Re: Problems with spf testsuite and dns specification

Julian Mehnle <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Stefano Bagnara wrote:
> http://www.dns.net/dnsrd/rfc/rfc2181.html#5.%20Resource%20Record%20Sets
>
> It says "Servers should suppress such duplicates if encountered". Most
> servers will return 1 single IN TXT "foobar".

You bring up an interesting point.  I wasn't aware of this before, although 
I'm quite sure I do have read this part of RFC 2181 before.

> > Nevertheless, the SPF spec says that when there are multiple TXT
> > records beginning with "v=spf1", then the correct result is PermError.
>
> That's what I'm trying to fix.  IMHO it is correct when the records are
> different, but when they are identical it is a matter of what DNS server
> (servers) and what dns clients are in the resolution chain to know if
> you will receive one or multiple identical records. The SPF spec should
> not rely on this: the DNS spec does not allow such distinction to be
> made and SPF is a DNS based protocol.

I agree.  This is optional behavior in the DNS specs, and SPF must tolerate 
all legal DNS behavior.

In particular, this means that the test suite must not inherently require 
DNS implementations to choose one option over the other(s).  If a DNS 
implementation and its RFC 4408 test suite driver choose to collapse 
multiple identical records, then that must not make the test suite data 
invalid as a result.

This is NOT an issue with RFC 4408 itself, and making any errata to it with 
regard to this issue would be wrong.  Neither should this ever be seen as 
an issue with SPF implementations themselves (as opposed to, for example, 
with their DNS bindings).  [I.e., if an SPF implementation gets two 
_identical_ SPF records for the same DNS name from their DNS binding, then 
it must consider them as redundant and throw a PermError.  If some part of 
the DNS implementation chain (from the domain's name server to the SPF 
implementation's DNS client) consolidates them, then the SPF implemen- 
tation must handle that as a single SPF record.]

Instead, the zonedata used by the test cases "multispf1" and "multispf2" 
should be changed to feature slightly differing records in order to 
respect valid DNS behavior while still being able to prove the test cases' 
points.

Stuart, do you see any reason why having such tests with multiple 
_identical_ -- as opposed to merely multiple, but differing -- SPF records 
is important?

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGbytGwL7PKlBZWjsRAqSQAJ4/twgEMgVEwE3b6/rzAfZuJ9j69ACeOy55
FEoGwgdOLQ5otRWLy8v+EpI=
=wuvC
-----END PGP SIGNATURE-----

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.