Re: Problems with spf testsuite and dns specification

Julian Mehnle <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Stefano Bagnara wrote:
> Julian Mehnle ha scritto:
> > (For what it's worth, I somehow doubt that client-side unification of
> > multiple identical RRs is widely implemented in DNS _resolvers_.)
>
> A big problem are DNS caches: as far as I understood BIND does compact
> identical RRs, so any user using an SPF client against a BIND cache (90%
> of users around the world?) will have big probability to never see
> identical duplicate RRs.

Good point.  But this is still besides the main point.  This shouldn't be 
an issue of SPF just like SMTP doesn't define what to do about multiple 
identical MX records.  This PoV is even strengthened by RFC 2181 pointing 
out that it is up to servers to suppress any multiple identical RRs.

We'll see if the council agrees to not have the test suite unnecessarily 
check for a specific resolution of this ambiguity.  I hope it will.

> I think that the "mockable" DNS Server we created might also be useful
> to spf team to better test implementations without mocking the
> resolution mechanism in the library.

This is an interesting approach.  Can you package up this "mockable DNS 
server" and document its use?  I could see linking to it from the official 
test suite webpage then.

> > Until the issue is resolved officially, you can instruct your jSPF
> > test suite driver to skip the problematic tests, explicitly declare in
> > your documentation that you cannot comply with those tests, and
> > explain why.
>
> This would weak the test suite. I think that at least adding "cloned"
> tests for multispf tests replacing multiple identical records with
> multiple different records would help differentiating the problem and
> this seems to be a task that you can approach without council
> requirements... WDYT?

Well, you can do that as long as you don't claim compliance to the official 
RFC 4408 test suite.  But it may be "good enough" for now, as long as you 
document exactly what the jSPF test suite is doing.

I'd advise against modifying rfc4408-tests.yml, though.  You could create a 
separate rfc4408-tests-jspf.yml (or so) with additional tests.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGc+uPwL7PKlBZWjsRAqm/AKCLQzXsTdNwyRS1qhVmIS9DOMBkXACguDH3
s5EDwac8UPD2GoqBCgasbd0=
=eNXz
-----END PGP SIGNATURE-----

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.