Re: [DNSOP] New Version Notification for draft-ietf-dnsop-as112-dname-00.txt

2013-11-18 Thread John R Levine
* Anyone can point a DNAME to empty.as112.arpa, not just subtrees of rDNS. Is that a security issue? I thought of it as a feature. AS112 is for everyone, not just IANA! :-) Well, yes, but I'm trying to think of a bad guy who wants to hide part of his malware factory with split horizon or som

Re: [DNSOP] New Version Notification for draft-ietf-dnsop-as112-dname-00.txt

2013-11-18 Thread Joe Abley
Hi John, On 2013-11-18, at 17:53, John Levine wrote: >> So, we got some good review and feedback on this from Tony Finch, anyone >> else? > > I read the draft, and as a spec it looks fine to me. Once there are a > few empty.as112.arpa servers, you can send any branch of the DNS to > oblivion

Re: [DNSOP] New Version Notification for draft-ietf-dnsop-as112-dname-00.txt

2013-11-18 Thread John Levine
>So, we got some good review and feedback on this from Tony Finch, anyone else? I read the draft, and as a spec it looks fine to me. Once there are a few empty.as112.arpa servers, you can send any branch of the DNS to oblivion by pointing a DNAME at them. I have 2 1/2 questions: * Anyone can po

Re: [DNSOP] prefetch (HAMMER_TIME) draft

2013-11-18 Thread Brian Somers
I would agree, perhaps wording it that the upstream lookup reduction is only realized if there is a single cache shared among entities capable of doing upstream lookups independently of each other. On Nov 15, 2013, at 9:33 AM, JINMEI Tatuya / 神明達哉 wrote: > At Thu, 7 Nov 2013 06:53:28 +0100, >