Re: TCP connections to DJBDNS
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 20 Jan 2009, Faried Nawaz wrote: > Your dnscache does't reply to authoritative queries. I meant that since dnscache supports TCP, it seems odd that tinydns doesn't; I don't use tinydns, so I can say for sure. On Wed, 21 Jan 2009, Jakob Hirsch wrote: > Peter Dambier wrote: > > > It is a must. If you do not support EDNS or if your clients dont > > support EDNS then you must support TCP. > > That's not true. Though there is an implicit need for tcp (or EDNS0) > when your responses are going to be bigger than 512 bytes, and it's > probably good practice to offer tcp service, there is not general > "must". RFC 1123 says explicetely: This is right, BUT---I think the consensus on DNSEXT was that implementations must support TCP or ENDSO, and DNSSEC requires TCP or ENDSO. Then again, I've been silenced on DNSEXT for opposing the BIND Cartel, as has Dr. Bernstein previously. So maybe the IETF can be ignored as an honest standards body, since it no longer issues standards based on honest community consensus but only on what the BIND cartel wants to do. And who wants that? TCP is just about necessary to have reasonably secure DNS lookups in some cases, and I think EDNSO and TCP should be (ought to be) supported in both dnscache and tinydns. If tinydns really doesn't support TCP, then we should think about fixing that. It can't be very hard... I am also thinking about changes to dnscache to enable one to configure it to accept UDP queries, but prefer TCP for recursion. Thoughts? --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000