Re: RFC 6604 Clarification

Kumar Ashutosh <[email protected]> Tue, 31 Mar 2015 10:53:51 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Thank You Wouter.

The first one seems to be a fair call.
The second case is a little confusing.

Also, I am a little skeptical about sending any partial response with SERV_FAIL as many resolvers may simply reject the data in Serv_fail responses and will cause resolution failures. 

Thanks
Ashu
Program Manager | Windows Networking| DNS & SDN

-----Original Message-----
From: dnsext [mailto:[email protected]] On Behalf Of W.C.A. Wijngaards
Sent: Tuesday, March 31, 2015 12:52
To: [email protected]
Subject: Re: [dnsext] RFC 6604 Clarification

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi Kumar,

I cannot answer on the RFC part, but I want to answer on what will make the resolver continue the lookup.

On 30/03/15 11:04, Kumar Ashutosh wrote:
> Hi
> 
> As per RFC 6604, section 3
> 
> When an xNAME chain is followed, all but the last query cycle
> 
> necessarily had no error.  The RCODE in the ultimate DNS response
> 
> MUST BE set based on the final query cycle leading to that
> 
> response.  If the xNAME chain was terminated by an error, it will
> 
> be that error code.  If the xNAME chain terminated without error,
> 
> it will be zero.
> 
> 
> 
> This is a little vague on two accounts:
> 
> 1.What would be the error code if the server decides to curtail the 
> CNAME chain after a certain length (say 20). Is it still success or do 
> we indicate in some other way.

The curtailed CNAME chain is best sent with RCODE NOERROR(0).

> 
> 2.If the CNAME chain points to a Qname for which the auth server is 
> non-authoritative (and recursion is disabled on the auth
> server.) The server in this case cannot get the response. A direct 
> query for this Qname will result in SERV_FAIL. Should the auth server 
> return SERV_FAIL in this case? Will resolvers respect answers with 
> SERV_FAIL in RCODE and cache the partial response?

You must send the partial response with RCODE NOERROR(0).  Then, the resolver can retry after the CNAME.

Best regards,
   Wouter


> 
> 
> 
> Can we put a clarification?
> 
> 
> 
> Thanks
> 
> *Ashu*
> 
> Program Manager | Windows Networking| DNS
> 
> 
> 
> 
> 
> _______________________________________________ dnsext mailing list 
> [email protected] https://www.ietf.org/mailman/listinfo/dnsext
> 

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJVGksrAAoJEJ9vHC1+BF+Nv0QP/RY/NRKvkVhUKqFQ+CuWU/06
RQWEktMu4XMLBX6RlUteOwsc7Ufux5Fz+/KN50M8wrRZ+7I0CMFQBI88ugOSZ5mB
iX2DYv6soBtZirX0gUsXtZ1PQRMOipx/7qi7YPIZS5Sm7WEWWdcuVMlIMiswVqLi
2gg3Ac4bOGYTMhR9cwlNGX4VYlDfQIjP7+HOcTZS5uBR6sc7hzmpH8xrSCHj49Je
MVv2h/IpjR+DdNQSDPBJHhOyPnfjhgfcGDPgn7lbuGspaSEQ6onEAu1R/G7RJkhz
QhbMXQmLlk22bxlZXhi33uHFjKLzWBttLe88+vFf1UgdpjQjrXnIRF4Y2UIDQGi5
CChfolUG2UIjyVzsd9yOX48T1rhe9L9MSD7SuqAc35/jN8eZG325kzF9h4iuNBhy
NM/5XS68dejl9fUmgERZB14GGPw4ZdvtFyuFlXGKaQj8CHeMCHXg5A8TbnUdLelf
XSKrSfQBslEzotJiNjdQWLomfcQPolkYwN/X9RaGvcPJbrGYWDtgqyVYbNTgWdOd
59GKt9xSvymYSlp91MTBmNNHPNdvf8l5RqGKiKrdB3kXenLNUx7mulYFonB4QvEy
irsbPO36vtZub4OppUADysd76WsMPC/7m6YjGX92C40Jv1VRrlqKvOZgKlO2q6Ms
alLuBIJh7/0fluO4vB4w
=ZlFv
-----END PGP SIGNATURE-----

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext