The following errata report has been held for document update 
for RFC8906, "A Common Operational Problem in DNS Servers: Failure to 
Communicate". 

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid7689

--------------------------------------
Status: Held for Document Update
Type: Technical

Reported by: Josh Soref <jso...@gmail.com>
Date Reported: 2023-10-26
Held by: Warren Kumari (Ops AD) (IESG)

Section: 8.2.8

Original Text
-------------
expect: DO=1 to be present if an RRSIG is in the response


Corrected Text
--------------
expect: flag: do to be present if an RRSIG is in the response

Notes
-----
The same section has `expect: flag: aa to be present`, and when running the 
suggested command, no `DO=1` is shown, which makes the advice unhelpful.

Sample command:
```
$ dig +nocookie +edns=0 +noad +norec +dnssec soa $zone @$server

; <<>> DiG 9.16.44-Debian <<>> +nocookie +edns +noad +norec +dnssec soa 
powerdns.com @2600:3c03::f03c:91ff:fe55:e54d
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 45268
;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 1232
;; QUESTION SECTION:
;powerdns.com.                  IN      SOA

;; Query time: 0 msec
;; SERVER: 2600:3c03::f03c:91ff:fe55:e54d#53(2600:3c03::f03c:91ff:fe55:e54d)
;; WHEN: Thu Oct 26 22:26:44 UTC 2023
;; MSG SIZE  rcvd: 41
```

[ WK: For more info, see thread: 
https://mailarchive.ietf.org/arch/msg/dnsop/gA71yLWLZ8-eylYgKjNy9emP9hU/ 

It was also suggested that reminding readers that "@$server"  in this case 
refers to an
authoritative server, and not a recursive server - See Sec 8 ]

--------------------------------------
RFC8906 (draft-ietf-dnsop-no-response-issue-23)
--------------------------------------
Title               : A Common Operational Problem in DNS Servers: Failure to 
Communicate
Publication Date    : September 2020
Author(s)           : M. Andrews, R. Bellis
Category            : BEST CURRENT PRACTICE
Source              : Domain Name System Operations
Area                : Operations and Management
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to