ebersman> If what you're arguing for is something that's actually mixed
ebersman> into the zone data, how do you handle non-compatible/legacy
ebersman> and avoid leakage?

wpk> non-compatible/legacy servers won't know the RRTypes that are
wpk> covert - and therefore won't be able to load them from disk.

In a polite/sane implementation, sure. But I have scars from my years at
ISC tech support dealing with very broken implementations not done by
the usual FOSS DNS folks. They might fail to load the zone at all, might
stop loading and serve what they have, only serve what they recognize,
crash, etc.

DNSOP mailing list

Reply via email to