[DNSOP] Re: Fwd: New Version Notification for draft-pels-d nsop-axfr-notify-00.txt

Shane Kerr <[email protected]> Fri, 17 Jul 2026 20:43:18 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Martin,

I just noticed this from the recent replies!

On 2026-05-18 11:58, Martin Pels wrote:Hello,
>
> While working on draft-ietf-dnsop-dnssec-keyrestore[0] we found that 
> we needed to force secondary servers to perform an AXFR our zone 
> without checking the serial number in the SOA record. While DNS 
> implementations have knobs to force a transfer from the secondary 
> (e.g. "rndc retransfer" in BIND, "nsd-control force_transfer" in NSD), 
> there is currently no mechanism to make a primary server force its 
> secondaries to perform an AXFR without checking the serial. The below 
> draft introduces such a mechanism.
>
> We think this feature could be more widely beneficial for cases where 
> there is an inconsistency between the view of a zone on a primary and 
> a secondary server not under control of the same operator. We'd love 
> to hear what others think. 

Surely the draft should specify that TSIG MUST be used to secure the 
force-AXFR NOTIFY rather than require that the secondary MUST rate limit 
use of this? Using TSIG eliminates the need for additional state on the 
secondary.

Cheers,

--
Shane

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]