Re: Problems with spf testsuite and dns specification
Julian Mehnle <[email protected]>
| Newsgroups | gmane.mail.spam.spf.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Stefano Bagnara wrote: > http://www.dns.net/dnsrd/rfc/rfc2181.html#5.%20Resource%20Record%20Sets > > It says "Servers should suppress such duplicates if encountered". Most > servers will return 1 single IN TXT "foobar". You bring up an interesting point. I wasn't aware of this before, although I'm quite sure I do have read this part of RFC 2181 before. > > Nevertheless, the SPF spec says that when there are multiple TXT > > records beginning with "v=spf1", then the correct result is PermError. > > That's what I'm trying to fix. IMHO it is correct when the records are > different, but when they are identical it is a matter of what DNS server > (servers) and what dns clients are in the resolution chain to know if > you will receive one or multiple identical records. The SPF spec should > not rely on this: the DNS spec does not allow such distinction to be > made and SPF is a DNS based protocol. I agree. This is optional behavior in the DNS specs, and SPF must tolerate all legal DNS behavior. In particular, this means that the test suite must not inherently require DNS implementations to choose one option over the other(s). If a DNS implementation and its RFC 4408 test suite driver choose to collapse multiple identical records, then that must not make the test suite data invalid as a result. This is NOT an issue with RFC 4408 itself, and making any errata to it with regard to this issue would be wrong. Neither should this ever be seen as an issue with SPF implementations themselves (as opposed to, for example, with their DNS bindings). [I.e., if an SPF implementation gets two _identical_ SPF records for the same DNS name from their DNS binding, then it must consider them as redundant and throw a PermError. If some part of the DNS implementation chain (from the domain's name server to the SPF implementation's DNS client) consolidates them, then the SPF implemen- tation must handle that as a single SPF record.] Instead, the zonedata used by the test cases "multispf1" and "multispf2" should be changed to feature slightly differing records in order to respect valid DNS behavior while still being able to prove the test cases' points. Stuart, do you see any reason why having such tests with multiple _identical_ -- as opposed to merely multiple, but differing -- SPF records is important? -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGbytGwL7PKlBZWjsRAqSQAJ4/twgEMgVEwE3b6/rzAfZuJ9j69ACeOy55 FEoGwgdOLQ5otRWLy8v+EpI= =wuvC -----END PGP SIGNATURE----- ------------------------------------------- ----------------------------------------------------------------------- To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f Powered by Listbox: http://www.listbox.com