Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-11 Thread Brian Dickson
> > Paul wrote: > Evan Hunt wrote: > (I do like the idea of advertising a separate expiry value though.) > i think if we're going to put something into the 20-year deployment funnel > we should treat the fixed costs as high and demand more benefits. that's > where the proposal up-thread came from.

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-11 Thread Vladimír Čunát
On 09/09/2017 09:22 PM, Paul Vixie wrote: > [...] > the content owner may have good and specific reasons for the TTL they > chose, and using that data for longer than that period may be harmful, > and must be presumed to be harmful unless explicit signaling is added > to let the content owner speci

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-09 Thread Paul Vixie
Evan Hunt wrote: On Sat, Sep 09, 2017 at 08:29:28AM -0700, Paul Vixie wrote: rpz is a defense. it assumes that the content owner is trying to hurt me. it is therefore one step away from being an attack, and is in any case, not an attack. Sure. And TTL stretching assumes the content owner is

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-09 Thread Evan Hunt
On Sat, Sep 09, 2017 at 08:29:28AM -0700, Paul Vixie wrote: > rpz is a defense. it assumes that the content owner is trying to hurt > me. it is therefore one step away from being an attack, and is in any > case, not an attack. Sure. And TTL stretching assumes the content owner is a fellow victi

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-09 Thread Paul Vixie
Evan Hunt wrote: On Fri, Sep 08, 2017 at 06:43:52PM -0700, Paul Vixie wrote: not so fast. nxdomain redirection is an attack. censorship is an attack. i don't think you mean to group ttl stretching in with those attacks. because if you do, then we agree, it is an attack, and ought not be done,

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Evan Hunt
On Fri, Sep 08, 2017 at 06:43:52PM -0700, Paul Vixie wrote: > not so fast. nxdomain redirection is an attack. censorship is an attack. > i don't think you mean to group ttl stretching in with those attacks. > because if you do, then we agree, it is an attack, and ought not be > done, and certain

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Matthew Kerwin
On 9 September 2017 at 00:32, Tony Finch wrote: > Paul Vixie wrote: > > > > if they really need this, they should provide a method by which i can > specify > > both a TTL and an Expiry, and i will consider publishing both values, > and if i > > do, then they can use them the way i intend them. >

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Paul Vixie
Evan Hunt wrote: On Thu, Sep 07, 2017 at 10:28:30PM -0700, Paul Vixie wrote: if they really need this, they should provide a method by which i can specify both a TTL and an Expiry, and i will consider publishing both values, and if i do, then they can use them the way i intend them. because as

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Evan Hunt
On Thu, Sep 07, 2017 at 10:28:30PM -0700, Paul Vixie wrote: > if they really need this, they should provide a method by which i can specify > both a TTL and an Expiry, and i will consider publishing both values, and > if i do, then they can use them the way i intend them. because as i said, > auto

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Paul Vixie
Tony Finch wrote: Paul Vixie wrote: if they really need this, they should provide a method by which i can specify both a TTL and an Expiry, and i will consider publishing both values, and if i do, then they can use them the way i intend them. RRSIG sort-of does that? but it wasn't intende

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Tony Finch
Paul Vixie wrote: > > if they really need this, they should provide a method by which i can specify > both a TTL and an Expiry, and i will consider publishing both values, and if i > do, then they can use them the way i intend them. RRSIG sort-of does that? Tony. -- f.anthony.n.finchhttp://

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-08 Thread Joe Abley
> On Sep 8, 2017, at 01:28, Paul Vixie wrote: > > if they really need this, they should provide a method by which i can specify > both a TTL and an Expiry, and i will consider publishing both values, and if > i > do, then they can use them the way i intend them. because as i said, > autonomy

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-07 Thread Paul Vixie
On Thursday, September 07, 2017 11:08:43 PM Joe Abley wrote: > >> Would you see the querying application informing you of intent via > >> > >> option code saying "If I'm unable to talk to you once TTL expires, I may > >> serve your last known good answer"? > > > > i don't think so. if it was "m

Re: [DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-07 Thread Joe Abley
Apologies in advance for iPad MIME-crime. See below for crimes committed by workman rather than tools. > On Sep 7, 2017, at 21:37, Paul Vixie wrote: > > note, there's a proposal contained here. > > Jared Mauch wrote: >>> On Thu, Sep 07, 2017 at 01:29:47PM -0700, Paul Vixie wrote: >>> if the dr

[DNSOP] opportunistic semi-authoritative caching (Re: DNSOP Call for Adoption - draft-tale-dnsop-serve-stale)

2017-09-07 Thread Paul Vixie
note, there's a proposal contained here. Jared Mauch wrote: On Thu, Sep 07, 2017 at 01:29:47PM -0700, Paul Vixie wrote: if the draft being considered was clear on two points, i'd support adoption. ... Would you see the querying application informing you of intent via option code sayi