On 21/02/2013, at 6:46 AM, Mark Andrews <ma...@isc.org> wrote:

> 
> While I think we should adopt the document I have grave concerns
> about it.
> 
> * there is no demonstrated need for it.

thats opinion, not fact Mark. 'demonstrated need' stems from other people's 
desires.

you might as well come out and say you think AS112 has no demonstrated need, as 
say this draft has no role in administration of AS112.

I tend to another opinion. I think this draft identifies a sensible path to 
making AS112 servers respond the way we want.

> * it is likely to interact badly with validating resolvers especially
>  when there are lots of labels in the qname below the delegation to
>  these servers.

AS112 is designed to offer a quick termination of query hunting to a non-value. 
Can you explain how this fails to be satisfied by a wildcard response, when we 
are seeking to divert a query WHICH CANNOT BE ANSWERED IN THE WIDER NET to a 
'not' answer? 

the internal side of anyone who has valid delegation of a domain which has hit 
an AS112 can have as much DNSSEC as they want. its everyone else, who sees the 
sideblow queries who needs this.

I am probably being thick. can you do an illustrative instance of what you mean 
here?


> * it changes the response from NXDOMAIN to NOERROR NODATA.

And why is that "wrong" ? I dont understand what you see as the outcomes. more 
query? bad DNS? load?

> 
> If we have to build special servers can't they periodically transfer
> a list of zones they need to serve rather than return what is
> essentially the wrong answer?

the back-end administration has proved fraught.

btw, I continue to collect data on the volume of ULA, link-local, teredo 
traffic in reverse, and it continues to grow..

-George

> 
> Mark
> -- 
> Mark Andrews, ISC
> 1 Seymour St., Dundas Valley, NSW 2117, Australia
> PHONE: +61 2 9871 4742                 INTERNET: ma...@isc.org
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to