Re: TTL on DS records

Andrew Sullivan <[email protected]> Sat, 21 Feb 2015 22:13:57 -0500
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On Sat, Feb 21, 2015 at 08:42:38PM -0500, Olafur Gudmundsson wrote:
> 
> No Andrew it effectively is the MAX( DS TTL, DNSKEY TTL) 

I suppose it's true that, having validated the DNSKEY once, you're not
going to check it again.  It does still entail that the parent zone
gets to make TTL decisions that affect the lookups necessary for use
of child-side data.

> Long TTL are artifacts of decisions taken long time ago
> and they need to be reexamined. 

I don't have any trouble with the idea that most caches aren't going
to keep anything for a week, and I know lots of zones that have very
short TTLs.  But as I said, it's almost completely novel in the DNS
that the parent-side decisions affect things for the child in this
way, and I think we shouldn't be cavalier about that change.

A

-- 
Andrew Sullivan
[email protected]

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext