[DNSOP] Re: Fwd: New Version Notification for draft-pels-d nsop-axfr-notify-00.txt
Shane Kerr <[email protected]> Fri, 17 Jul 2026 20:43:18 +0200
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Martin, I just noticed this from the recent replies! On 2026-05-18 11:58, Martin Pels wrote:Hello, > > While working on draft-ietf-dnsop-dnssec-keyrestore[0] we found that > we needed to force secondary servers to perform an AXFR our zone > without checking the serial number in the SOA record. While DNS > implementations have knobs to force a transfer from the secondary > (e.g. "rndc retransfer" in BIND, "nsd-control force_transfer" in NSD), > there is currently no mechanism to make a primary server force its > secondaries to perform an AXFR without checking the serial. The below > draft introduces such a mechanism. > > We think this feature could be more widely beneficial for cases where > there is an inconsistency between the view of a zone on a primary and > a secondary server not under control of the same operator. We'd love > to hear what others think. Surely the draft should specify that TSIG MUST be used to secure the force-AXFR NOTIFY rather than require that the secondary MUST rate limit use of this? Using TSIG eliminates the need for additional state on the secondary. Cheers, -- Shane _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]