Re: Problems with spf testsuite and dns specification

Julian Mehnle <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Stefano Bagnara wrote:
> Maybe a better errata could be to specify "In case of multiple identical
> records an implementation can either return PermError or parse the
> record (see rfc2181 par 5):

Well, that would just make the inconclusive interpretation of the current 
spec explicit.  No harm done, but not much use either.

The problem lies with the test suite.

> publishers SHOULD NOT publish multiple records at all if they want
> predictable result".

But isn't that what RFC 2181 says already?  I could see adding a warning 
for domain owners (not implementors!) as an erratum, but it's probably of 
little use to most: I haven't ever heard of someone having unexpected 
problems due to multiple identical records published.  The only case where 
it seems to have happened is in the official test suite (you discovered 
it).  As for SPF implementors, it's not something they should be concerned 
with.

> I'm also curious to see how many of the current compliant
> implementations do compact the results in the "live" environment: we
> already know that there is a high probability that a dns cache/server in
> the chain will compact them (bind based servers do that) and we also
> know that some client library do the same. Dnsjava does this for sure,
> and if I understood it also the standard C libresolve, based on bind
> code, does the same: it would be interesting to check what libspf,
> libspf2, pyspf, Mail-SPF do "for real".

Agreed.  We could test it using your fake DNS server (as soon as you have 
packaged it), for example.

> > Demanding that a DNS _application_ such as SPF combine multiple
> > identical RRs into a single RR would be highly unusual.  Show me any
> > other DNS application that specifies this.
>
> IMHO the problem is not "to compact or not to compact". The problem is
> requiring a PermError (a specific different action) on something that
> the DNS spec tell us is not different from a single record.
> To use your "question": show me any other DNS application that specifies
> a different behaviour on multiple identical RRs ;-)

SMTP, MX records.  Multiple identical RRs make a typical SMTP client 
perform multiple lookups, not one.  At least, RFC 2821 section 5 doesn't 
specify any MX RR compaction.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGdkhgwL7PKlBZWjsRAiVDAKCDa9Cp3lqYih0l2NxQ6EAnxhiF3gCgoxtv
MryjI2l/vf2MxXJv79JFDO0=
=6GKq
-----END PGP SIGNATURE-----

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.