Re: [DNSOP] Dname and its synthesized cname

2016-11-19 Thread Mark Andrews

In message , yao jk writes:
> Hello,
> 
>   Assume the resolver cache has 3 records:
>   A.com IN dname b.com 100
>   A.com IN rrsig dname 100
>  A.a.com IN cname a.b.com 2000
> 
> 
> When TTL expires after 100s but not after 2000s, what will resolver do when t
> he query for a.a.com with dnssec DO bit enabled?

DNAME aware clients cache the DNAME, not the CNAME.  The CNAME is
only there for clients that don't understand DNAME.

 
> Thanks
> 
> Jiankang
> 
> >From my phone
> ___
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org

___
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop


Re: [DNSOP] Dname and its synthesized cname

2016-11-20 Thread Jiankang Yao

Dear Mark,

 thanks for your kind reply.

in RFC 2672,
  "The synthesized CNAME RR, if provided, MUST have
  The same CLASS as the QCLASS of the query,
  TTL equal to zero,"

In RFC6672

"A CNAME RR with Time to Live (TTL) equal to the corresponding DNAME
   RR is synthesized and included in the answer section when the DNAME
   is employed as a substitution instruction."

 " Resolvers MUST be able to handle a synthesized CNAME TTL of zero or a
   value equal to the TTL of the corresponding DNAME record (as some
   older, authoritative server implementations set the TTL of
   synthesized CNAMEs to zero).  A TTL of zero means that the CNAME can
   be discarded immediately after processing the answer.
"
   

So in RFC 6672, DNAME resolver seem to have been updated to cache the 
synthesized cname.


thanks. 




Jiankang Yao

From: Mark Andrews
Date: 2016-11-20 10:30
To: yao jk
CC: dnsop@ietf.org
Subject: Re: [DNSOP] Dname and its synthesized cname

In message , yao jk writes:
> Hello,
> 
>   Assume the resolver cache has 3 records:
>   A.com IN dname b.com 100
>   A.com IN rrsig dname 100
>  A.a.com IN cname a.b.com 2000
> 
> 
> When TTL expires after 100s but not after 2000s, what will resolver do when t
> he query for a.a.com with dnssec DO bit enabled?

DNAME aware clients cache the DNAME, not the CNAME.  The CNAME is
only there for clients that don't understand DNAME.


> Thanks
> 
> Jiankang
> 
> >From my phone
> ___
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org

___
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop___
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop