Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-14 Thread Tony Finch
So I have adjusted the configuration on my workstation's name server to include the global root servers (for robustness) as well as a local stealth slave (for low latency). Here's a count of queries directed at the root zone and the servers chosen to handle them. I wonder how different it would be

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-12 Thread Tony Finch
Paul Vixie p...@redbarn.org wrote: I thought the idea of validating the zone transfer before putting the zone live was interesting. this is something deliberately left out of the dnssec design, because it doesn't obviate validation by query initiators of the underlying data. Right, but

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-12 Thread Paul Vixie
Tony Finch mailto:d...@dotat.at Wednesday, November 12, 2014 7:13 AM Paul Vixie p...@redbarn.org wrote: With normal DNSSEC validation, resolvers have a way to recover from data corruption. With this local root zone proposal they do not. i seem to have missed a step. why? If a validating

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-12 Thread Tony Finch
Paul Vixie p...@redbarn.org wrote: that's either an argument for listing multiple servers, the first being on the loopback, the other(s) being real global root name servers; That would probably work. or, instead of telling bind9 forward only, tell it forward first. That would not work: you

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-12 Thread Tony Finch
Paul Vixie p...@redbarn.org wrote: um. type forward is a possible zone type in bind9. we do it when we deliver DNS RBL policy zones. i was not talking about the kind of forwarding used for recursive service. Yes, I know that. type forward does not work if the server you are forwarding to is

[DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-11 Thread Paul Hoffman
Greetings again. Based on some great input from Evan Hunt, we have updated our draft. The algorithm is both simpler and easier to configure. In fact, we have examples of how to configure BIND and Unbound/NSD to match the new spec. We'll be talking about the new draft in today's meeting. --Paul

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-11 Thread Bob Harold
This sounded good until Note that using this configuration will cause the recursive resolver to fail if the local root zone server fails. Could I use forward first instead of static-stub so that it would fall back to the normal root servers if the local root server could not get zone transfers or

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-11 Thread Bob Harold
On Tue, Nov 11, 2014 at 2:15 PM, Evan Hunt e...@isc.org wrote: This sounded good until Note that using this configuration will cause the recursive resolver to fail if the local root zone server fails. Could I use forward first instead of static-stub so that it would fall back to the

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-11 Thread Tony Finch
Paul Hoffman paul.hoff...@vpnc.org wrote: Greetings again. Based on some great input from Evan Hunt, we have updated our draft. The algorithm is both simpler and easier to configure. In fact, we have examples of how to configure BIND and Unbound/NSD to match the new spec. I have been running

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-11 Thread Evan Hunt
On Tue, Nov 11, 2014 at 02:43:02PM -0500, Bob Harold wrote: Thanks, but what about the case where the zone transfers are refused and the root zone expires? My server is still running, but cannot answer for the root zone. That's a case where I want it to fail over to the real roots. If the

Re: [DNSOP] Fwd: New Version Notification for draft-wkumari-dnsop-root-loopback-01.txt

2014-11-11 Thread Paul Vixie
Tony Finch mailto:d...@dotat.at Tuesday, November 11, 2014 1:07 PM ... I thought the idea of validating the zone transfer before putting the zone live was interesting. this is something deliberately left out of the dnssec design, because it doesn't obviate validation by query initiators