[DNSOP] Re: DNSOPDELEXT: Proposed Delegation Type Ranges

Philip Homburg <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
> But I thought the original intent, when this discussion stared a
> while ago, was really: when should an engine know that a new RRTYPE
> is critical and you should abandon hope in some way because you
> don't understand it.  Or maybe I misunderstood the original goal
> (very entirely possible), but if not: then how does a new set of
> ranges change this semantic?  Are we confident that now there are
> 3 slices of different code that these new types can be treated
> generically in some way?  I have doubts...  And shouldn't there be
> another range for "abandon all hope because it turns out there is
> a category we failed to predict back then and need to assign it
> now"?

A problem with DELEG is that if a nameserver that is not DELEG-aware serves
a DNSSEC signed zone with DELEG records then this will cause failures.

So DELEXT is supposed to provide a solution to this problem for future
types (after DELEG), we cannot fix the current situation.

The obvious bit we want to encode is whether the NS RRset should be included
in the delegation or not. 

The third range seems obvious, parent side types that should not be included
as part of a delegation.

If the question is whether a new type should be or should not be included
in a delegation then these three seem to provide good coverage.

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.