Re: TTL on DS records
Andrew Sullivan <[email protected]> Sat, 21 Feb 2015 22:13:57 -0500
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Feb 21, 2015 at 08:42:38PM -0500, Olafur Gudmundsson wrote: > > No Andrew it effectively is the MAX( DS TTL, DNSKEY TTL) I suppose it's true that, having validated the DNSKEY once, you're not going to check it again. It does still entail that the parent zone gets to make TTL decisions that affect the lookups necessary for use of child-side data. > Long TTL are artifacts of decisions taken long time ago > and they need to be reexamined. I don't have any trouble with the idea that most caches aren't going to keep anything for a week, and I know lots of zones that have very short TTLs. But as I said, it's almost completely novel in the DNS that the parent-side decisions affect things for the child in this way, and I think we shouldn't be cavalier about that change. A -- Andrew Sullivan [email protected] _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext