[DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RF C6147) to Internet Standard
Michael Richardson <[email protected]> Mon, 13 Apr 2026 10:53:45 -0400
| Newsgroups | gmane.ietf.dnsop,gmane.ietf.v6ops |
|---|---|
| Message-ID | <[email protected]> |
Philip Homburg <[email protected]> wrote: > You never installed a DNSSEC validating proxy on a laptop without CLAT? Yes, I've done it. Any bog-standard Ubuntu laptop with systemd-resolve usually has DNSSEC enabled, and has no CLAT. (Of course, systemd-resolver screws up so badly for other reasons, one usually has to disable it) I agree, it's a fail. >> I think the point is to understand that DNSSEC with DNS64 is broken >> only in a very very very small % of situation, which can also be >> resolved. > The problem with DNS64 is that it seems to work (to some extent at least) > without CLAT. But as soon as you install a DNSSEC validating proxy, > or some other DNSSEC validation, access to IPv4 is lost. From what I understand, Smartphones, Windows and OSX all have CLATs, but do not come with DNSSEC enabled by default. I think that those systems are all moving (perhaps slowly) to PREF64 and local synthesis. That's good, right? > That means that devices that rely on DNS64 make it is a lot harder to > deploy those technologies. Only if they are mobile/nomadic. If they stay in one place, one does whatever the correct thing is. Remember that people deploying IPv6-{mostly,only} **today** know what the correct thing is. If DNS64 goes away, then many servers will have to go back to dual-stack. That's who loses. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide ** My working hours and your working hours may be different. ** ** Please do not feel obligated to reply outside your normal working hours ** _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmndA3gACgkQgItw+93Q 3WWyAgf/XBT4vjNAiVM7HlF8Cf96zduYPep4KrgGL2gPQAxy3awGppmh1A8DDD7H nOcBqBmw/WlJwLs96HmLIcFagnqGMZLzDIA6HbzGmsEVQ28KGB1F+66bsLSJ+opx 0S7VcFbu+zvyS1AOHRZzczZfy0kX+gngNzZt+vHFRhEnt2NL8xhdF7kd6rrIUmTA yhroyi2wdR+t0pg9FG6GmbRb9n2wdli3mQlsgg5qxP3hefRF1nwZOkbBQc7h4ndc 8RZ0xsSh41wBA6ENaCaC2z4B0+ZA9OYYclXXuavzrQ6hCT+JQanbt0T6r4J4UsxP SJrIdBrk/VpFcw92bVkZwrnKPr/5/A== =2Y8F -----END PGP SIGNATURE-----