On Tue, Feb 7, 2017 at 1:48 PM, Mark Andrews writes:
> >
In message <>, Ted Lemon writes:
> > writes:
> Hm.   When I look for foo.alt, what I get is NXDOMAIN, not SERVFAIL.
> When I validate, I get a secure denial of existence.   This is the
> correct behavior.   Why do you think we would get a SERVFAIL?
> >
> Because your testing is incomplete.
> >
> Go add a empty zone (SOA and NS records only) for alt to your
> recursive server.  This is what needs to be done to prevent
> privacy leaks.
> >
> >
> Here are some possible alternatives (to having the empty zone be named
> "alt.").
> First: make the locally served empty zone be "".
> Or, second method: have the DNAME RDATA be "", and the
> locally served zone be the same name.

Which does not work.  If you are serving up a local

        ALT. SOA ...
        ALT. NS ...
        ALT. DNAME

then it will not have RRSIG records so it will not validate unless there
is a INSECURE delegation for .ALT.

I really don't see the point in having the DNAME there other than you
seem to want a DNAME there.

The public version of the insecure .ALT zone could have a DNAME but
we are not talking about those contents at the moment.  We are
talking about what goes into the root zone to make this work.

> Or, third, have some other name for the zone (anything other than alt, or
> really anything that doesn't collide with a global name),

Nothing doesn't collide with a global name.  This is all about carving
a namespace out of the global namespace.

> and then use a
> local DNAME from "" (or "alt.empty,") to that
> zone's name (e.g. "homenet" or "homenet.local" or whatever  you wish).

Homenet is still part of the global namespace.  Once there is a delegation
and a RFC which states that it is not part of the global namespace then
you have other issues or should we start squatting on the homenet space?
> Since all of the above occur at or below the transition to unsigned, they
> should validate. (I need to test these, but I don't see why they wouldn't
> work, and all of the above avoid leaking queries to the root or to AS112
> servers.)
> Brian
> Configure another recursive server to forward its queries to this
> server and enable validation.
> >
> Now ask for foo.alt from this second server.
> >
> Mark
> > --
> > Mark Andrews, ISC
> > 1 Seymour St., Dundas Valley, NSW 2117, Australia
> > PHONE: +61 2 9871 4742                 INTERNET:
> >
