Re: Problems with spf testsuite and dns specification
Julian Mehnle <[email protected]>
| Newsgroups | gmane.mail.spam.spf.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Stefano Bagnara wrote: > Julian Mehnle ha scritto: > > (For what it's worth, I somehow doubt that client-side unification of > > multiple identical RRs is widely implemented in DNS _resolvers_.) > > A big problem are DNS caches: as far as I understood BIND does compact > identical RRs, so any user using an SPF client against a BIND cache (90% > of users around the world?) will have big probability to never see > identical duplicate RRs. Good point. But this is still besides the main point. This shouldn't be an issue of SPF just like SMTP doesn't define what to do about multiple identical MX records. This PoV is even strengthened by RFC 2181 pointing out that it is up to servers to suppress any multiple identical RRs. We'll see if the council agrees to not have the test suite unnecessarily check for a specific resolution of this ambiguity. I hope it will. > I think that the "mockable" DNS Server we created might also be useful > to spf team to better test implementations without mocking the > resolution mechanism in the library. This is an interesting approach. Can you package up this "mockable DNS server" and document its use? I could see linking to it from the official test suite webpage then. > > Until the issue is resolved officially, you can instruct your jSPF > > test suite driver to skip the problematic tests, explicitly declare in > > your documentation that you cannot comply with those tests, and > > explain why. > > This would weak the test suite. I think that at least adding "cloned" > tests for multispf tests replacing multiple identical records with > multiple different records would help differentiating the problem and > this seems to be a task that you can approach without council > requirements... WDYT? Well, you can do that as long as you don't claim compliance to the official RFC 4408 test suite. But it may be "good enough" for now, as long as you document exactly what the jSPF test suite is doing. I'd advise against modifying rfc4408-tests.yml, though. You could create a separate rfc4408-tests-jspf.yml (or so) with additional tests. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGc+uPwL7PKlBZWjsRAqm/AKCLQzXsTdNwyRS1qhVmIS9DOMBkXACguDH3 s5EDwac8UPD2GoqBCgasbd0= =eNXz -----END PGP SIGNATURE----- ------------------------------------------- ----------------------------------------------------------------------- To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f Powered by Listbox: http://www.listbox.com