Re: Problems with spf testsuite and dns specification

Julian Mehnle <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Stefano Bagnara wrote:
> As Julien already told, rfc2181 does IMO apply also to stup
> implementations of a DNS resolver.

Let me phrase it like this: from the DNS RFCs' PoV, there is no live DNS or 
emulated DNS -- there's just DNS.  Anyone who claims to implement DNS must 
adhere to the same set of DNS RFCs.

> Again, IMO the problem with the specification is that it requires a
> behaviour that is unknown when you publish the duplicated records.

Well, the _real_ solution is for domain owners to NOT publish multiple 
identical records.  Then the problem won't occur in the first place.

Consequently, this is exactly what the test suite should do, or rather, not 
do.  I.e., it should not "publish" multiple identical records in the test 
case that is actually supposed to test for RFC 4408 4.5/6.

> It does not make sense at all: if you are simply telling that what is
> wrote in the 4408 is like something said by God and cannot be wrong,
> then ok, we can skip this discussion at all, otherwise it should be
> considered that the rfc4408 may be inappropriate about this

RFC 4408 is not beyond criticism, however we cannot change it retroactively 
and expect all the existing "v=spf1" implementations to follow suit (in 
this case, they would have to newly implement recognition of multiple 
identical RRs).

"v=spf1" is carved in stone.  We have fought hard in the past to protect 
its integrity.  Of all the imaginable issues, this one certainly doesn't 
warrant an exception.

> The intent of rfc2181 is to have multiple identical records to behave as
> a single record. If you implement a specification on top of DNS you
> cannot change the intents of the underlying transport and so IMO
> considering multiple identical RRs as a single one is perfectly VALID
> for rfc4408 because it is built on top of rfc2181 and we simply SHOULD
> do that.

Demanding that a DNS _application_ such as SPF combine multiple identical 
RRs into a single RR would be highly unusual.  Show me any other DNS app- 
lication that specifies this.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGdbD0wL7PKlBZWjsRAhuEAKCK4dxlAd9ImyEjHvmydVXSa/yi3gCdHMjV
5UaqU91Lj2nMTfvBVVMRfcw=
=17VG
-----END PGP SIGNATURE-----

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.