[DNSOP] Re: DNSOPFwd: New Version Notification for draft-s ury-dnsop-rrsig-refused-00.txt

Wes Hardaker <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Shumon Huque <[email protected]> writes:

> Maybe that behavior should be generalized to include other types that should not
> be allowed in queries too like RRSIG.

I think coming up with a standard semantic for handling "you're clearly
a broken client by making a request that makes no sense" is an excellent
thing, and making the (future) RFC state "these are the RRTYPEs today
that this covers" would be a good thing as well.  I have an auth server
for a popular-ish zone that receives a *lot* of ANY queries for the
signed zone, which technically I should support (but I filter them).
Lately I've noticed that likely the same behavior seems to be happening
with queries for CNAME.  Say what now?

As to whether REFUSED or FORMERR I'll leave to the better minds that me
(specifically resolver implementation folk), but I do think suggesting
an EDE is critical.

[TL;DR: I agree with what everyone else has said -- let's not try to
figure out how to answer broken queries, but rather return a "your
broken" response of some kind].
-- 
Wes Hardaker
Google

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.