The following errata report has been submitted for RFC7686,
"The ".onion" Special-Use Domain Name".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid6761

--------------------------------------
Type: Technical
Reported by: Peter van Dijk <peter.van.d...@powerdns.com>

Section: 2

Original Text
-------------
   5.  Authoritative DNS Servers: Authoritative servers MUST respond to
       queries for .onion with NXDOMAIN.

   6.  DNS Server Operators: Operators MUST NOT configure an
       authoritative DNS server to answer queries for .onion.  If they
       do so, client software is likely to ignore any results (see
       above).

Corrected Text
--------------
   5.  Authoritative DNS Servers: Authoritative servers MUST respond 
non-authoritatively to
       queries for names in .onion.

   6.  DNS Server Operators: Operators MUST NOT configure an
       authoritative DNS server to answer authoritatively to queries for names 
in .onion.  If they
       do so, client software is likely to ignore any results (see
       above).

Notes
-----
The original text for 5 and 6 is conflicting. A name server cannot respond with 
NXDOMAIN (which is an authoritative answer) without having a zone configured to 
serve that NXDOMAIN from. Clearly the intent of the text is that clients will 
not find authoritative answers to .onion queries anywhere in the DNS.

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC7686 (draft-ietf-dnsop-onion-tld-01)
--------------------------------------
Title               : The ".onion" Special-Use Domain Name
Publication Date    : October 2015
Author(s)           : J. Appelbaum, A. Muffett
Category            : PROPOSED STANDARD
Source              : Domain Name System Operations
Area                : Operations and Management
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to