Re: DNS-AS RRTYPE PARAMETER ALLOCATION

Ray Bellis <[email protected]> Wed, 10 Feb 2016 12:26:38 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Wolfgang,

I've been appointed as the designated expert to review your RRTYPE
application per RFC 6895.

In principle the application is OK, and it's highly desirable that you
avoid use of TXT.

Within my remit however I do have some concerns over the name of the RRTYPE:

- the term "authoritative" has a particular meaning in the DNS
  protocol, and "authoritative source" is a commonly used term
  too.  Typing "dns authoritative source" into Google already
  produces 75,000 results, none that I could see relating to
  your project.

- using "DNS" within the RRTYPE name seems redundant - we're
  already in the DNS.

- the letters "AS" are also commonly used to refer to a BGP
  "Autonomous System".

[FWIW, when I first saw your requested mnemonic in the subject of your
application I was expecting to see an application for an RRTYPE to
represent a BGP AS number!]

Also missing is any explicit statement that the intended wire and
presentation format are identical to that of a TXT record.
Consideration should also be given to what happens if the data does not
fit within a single 255 octet "character-string" sub-field.

Incidentally, the "CISCO-CLS=" prefix in the RDATA would appear to be
redundant when you get your own RRTYPE, and if it's expected that other
vendors would use this then I suggest that you either omit it or use
something more neutral.

At a higher level I have concerns about the overall use case  that
should be addressed if you plan to document "DNS Authoritative Source"
in an Internet Draft (although I don't expect these to be a factor in my
decision as they're probably outside the scope of RFC 6895):

-  why DNS?  How does the client know what domain names are
   supposed to be looked up?

-  if the "Application Name" is the primary key, why not incorporate
   that into the domain name?

  - (corollary) is it expected that a client would want to (or even
    be allowed to) obtain information about all known applications at
    a domain with a single DNS query?

-  what about DNS Security?  What happens in your SDN if someone
   manages to poison a record?

The decision will be reached within two weeks of today, and before
approval the explicit linking to the TXT record format must be resolved.

I urge you to reconsider your project name of "DNS Authoritative Source"
as being a clash with existing terminology. I'm not currently inclined
to reject the application on that basis of the requested DNSAS mnemonic,
but welcome community feedback on that issue.

kind regards,

Ray Bellis

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext