[DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RF C6147) to Internet Standard

Philip Homburg <[email protected]> Mon, 13 Apr 2026 15:45:20 +0200
Newsgroups gmane.ietf.dnsop,gmane.ietf.v6ops
Message-ID <[email protected]>
> > IPv6 and DNSSEC are independent technologies. We cannot assume that one
> > implies the other.
> 
> And do you have real experience of deployments breaking it? I will
> love to see those cases.

You never installed a DNSSEC validating proxy on a laptop without CLAT?

> I think the point is to understand that DNSSEC with DNS64 is broken
> only in a very very very small % of situation, which can also be
> resolved.

The problem with DNS64 is that it seems to work (to some extent at least)
without CLAT. But as soon as you install a DNSSEC validating proxy,
or some other DNSSEC validation, access to IPv4 is lost.

The same thing is of course true for a DNS proxy that connects to a 
public resolver over DoH or DoT.

That means that devices that rely on DNS64 make it is a lot harder to
deploy those technologies.

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]