Moin!

On Fri, Mar 06, 2015 at 11:14:21AM -0800, Paul Vixie wrote:
> > Also why have
> > you limited the this to authoritative servers?
> 
> this raises the point: ANY deserves its own access control list, or
> other non-BIND equivilent. because ANY is useful for diagnostics, local
> sysadmins ought to be able to make such queries.
That depends. If you have other mechanisms than dig to get data out
of your cache you don't need it. I would like to see it deprecated to
the level that no one relies on the query being answered with a record.
So even the resolver can answer with NOTIMP. 

> this way lies madness. you can't know that a validator has no reasonable
> intent behind an RRSIG query.
I can not see how there is a reason for a validator to issue an RRSIG
query, and I do not know of an validator that does this (there might
be). RRSIG is as complex as the ANY query as you have to look for all
resource record types and not just one. We don't need to include that
in this draft, but the complexity of the query is higher than a normal
query and the use of it is way lower (IMHO it is not needed).

Just two quick datapoints I got. On a recursive server farm that of a
medium ISP (that doesn't do validation, but has it server DNSSEC enabled)
out of a total of 15 billion queries a day there were 6 RRSIG queries 
and on an authoritative server for a DNSSEC secured domain that has 
around 2 million queries a day there were 7 RRSIG quries. So maybe we 
deprecate it before people use it more ;-).

So long
-Ralf

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to