Re: RFC 6604 Clarification

"W.C.A. Wijngaards" <[email protected]> Tue, 31 Mar 2015 09:22:19 +0200
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi Kumar,

I cannot answer on the RFC part, but I want to answer on what will
make the resolver continue the lookup.

On 30/03/15 11:04, Kumar Ashutosh wrote:
> Hi
> 
> As per RFC 6604, section 3
> 
> When an xNAME chain is followed, all but the last query cycle
> 
> necessarily had no error.  The RCODE in the ultimate DNS response
> 
> MUST BE set based on the final query cycle leading to that
> 
> response.  If the xNAME chain was terminated by an error, it will
> 
> be that error code.  If the xNAME chain terminated without error,
> 
> it will be zero.
> 
> 
> 
> This is a little vague on two accounts:
> 
> 1.What would be the error code if the server decides to curtail
> the CNAME chain after a certain length (say 20). Is it still
> success or do we indicate in some other way.

The curtailed CNAME chain is best sent with RCODE NOERROR(0).

> 
> 2.If the CNAME chain points to a Qname for which the auth server
> is non-authoritative (and recursion is disabled on the auth
> server.) The server in this case cannot get the response. A direct
> query for this Qname will result in SERV_FAIL. Should the auth
> server return SERV_FAIL in this case? Will resolvers respect
> answers with SERV_FAIL in RCODE and cache the partial response?

You must send the partial response with RCODE NOERROR(0).  Then, the
resolver can retry after the CNAME.

Best regards,
   Wouter


> 
> 
> 
> Can we put a clarification?
> 
> 
> 
> Thanks
> 
> *Ashu*
> 
> Program Manager | Windows Networking| DNS
> 
> 
> 
> 
> 
> _______________________________________________ dnsext mailing
> list [email protected] https://www.ietf.org/mailman/listinfo/dnsext
> 

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJVGksrAAoJEJ9vHC1+BF+Nv0QP/RY/NRKvkVhUKqFQ+CuWU/06
RQWEktMu4XMLBX6RlUteOwsc7Ufux5Fz+/KN50M8wrRZ+7I0CMFQBI88ugOSZ5mB
iX2DYv6soBtZirX0gUsXtZ1PQRMOipx/7qi7YPIZS5Sm7WEWWdcuVMlIMiswVqLi
2gg3Ac4bOGYTMhR9cwlNGX4VYlDfQIjP7+HOcTZS5uBR6sc7hzmpH8xrSCHj49Je
MVv2h/IpjR+DdNQSDPBJHhOyPnfjhgfcGDPgn7lbuGspaSEQ6onEAu1R/G7RJkhz
QhbMXQmLlk22bxlZXhi33uHFjKLzWBttLe88+vFf1UgdpjQjrXnIRF4Y2UIDQGi5
CChfolUG2UIjyVzsd9yOX48T1rhe9L9MSD7SuqAc35/jN8eZG325kzF9h4iuNBhy
NM/5XS68dejl9fUmgERZB14GGPw4ZdvtFyuFlXGKaQj8CHeMCHXg5A8TbnUdLelf
XSKrSfQBslEzotJiNjdQWLomfcQPolkYwN/X9RaGvcPJbrGYWDtgqyVYbNTgWdOd
59GKt9xSvymYSlp91MTBmNNHPNdvf8l5RqGKiKrdB3kXenLNUx7mulYFonB4QvEy
irsbPO36vtZub4OppUADysd76WsMPC/7m6YjGX92C40Jv1VRrlqKvOZgKlO2q6Ms
alLuBIJh7/0fluO4vB4w
=ZlFv
-----END PGP SIGNATURE-----

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext