[DNSOP] Re: DNSOPFwd: New Version Notification for draft-s ury-dnsop-rrsig-refused-00.txt
Wes Hardaker <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Shumon Huque <[email protected]> writes: > Maybe that behavior should be generalized to include other types that should not > be allowed in queries too like RRSIG. I think coming up with a standard semantic for handling "you're clearly a broken client by making a request that makes no sense" is an excellent thing, and making the (future) RFC state "these are the RRTYPEs today that this covers" would be a good thing as well. I have an auth server for a popular-ish zone that receives a *lot* of ANY queries for the signed zone, which technically I should support (but I filter them). Lately I've noticed that likely the same behavior seems to be happening with queries for CNAME. Say what now? As to whether REFUSED or FORMERR I'll leave to the better minds that me (specifically resolver implementation folk), but I do think suggesting an EDE is critical. [TL;DR: I agree with what everyone else has said -- let's not try to figure out how to answer broken queries, but rather return a "your broken" response of some kind]. -- Wes Hardaker Google _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]