[DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 (RFC6147) to Internet Standard

Ted Lemon <[email protected]> Tue, 14 Apr 2026 20:31:55 +0200
Newsgroups gmane.ietf.dnsop,gmane.ietf.v6ops
Message-ID <[email protected]>
I think it's also worth asking whether the devices that care about DNSSEC or DOH are the devices that don't do local synthesis. E.g. I'm pretty sure Apple devices will do local synthesis. I get the sense that Google devices will as well. Not sure about Windows, maybe Jen Linkova knows? Also not sure about Linux, probably varies. Of course, if e.g. your browser is doing DoH, it may not bother with DNSSEC anyway, even if your local resolver does do DNSSEC. But it had better do local synthesis, or it's not going to work in a v6only NAT64 environment regardless of whether or not DNS64 is present.

But my point is, your printer that's downloading firmware probably isn't doing DNSSEC validation, although it should, and it's probably not using DoH to bypass the local resolver either.

> On 14 Apr 2026, at 19:57, Philip Homburg <[email protected]> wrote:
> 
>> I will like to see that long list of things that dont work with
>> DNS64 in the real world.
> 
> I don't have a complete list, but here is a start. Let's assume a host
> that relies on DNS64 to obtain IPv4 connectivity. What doesn't work in
> that case:
> 1) An IPv4 literal
> 2) Any kind of local DNSSEC validation, either in the stub resolver or in
>   a local DNS forwarder.
> 3) Any resolver configuration that by-passes the local (DNS64) resolver
>   such as an (optionally DoH, DoT) connection to a public resolver.
> 4) Any kind of code that implement STUN for IPv4 but not for
>   IPv6.
> 5) As far as I can tell, any kind of code that tries STUN on an IPv6 address
>   that was mapped by the DNS64 resolver.
> 
> A few corners cases:
> 6) A DNS recursive resolver
> 7) DNS code that tries to disable EDNS Client Subnet
> 
> I think there are more protocols that somehow encode whether IPv4 or IPv6
> is used, but this is just from the top of my head.
> 
> _______________________________________________
> v6ops mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]