On 30.11.2018 11:59, nusenu wrote:
ѽ҉ᶬḳ℠ via Unbound-users:
With hyperlocal (RFC7706) requiring the root zone DNS server ip addresses listed 
please don't use the term "hyperlocal" (reasoning: Paul Hoffman - RFC7706bis author -
asked for not using it in the RFC7706 context at the last IETF103 DNSOP see the Q&A section of his
presentation https://www.youtube.com/watch?v=g0Sz7gziUW0&feature=youtu.be&t=5015 )

as master in auth-zone and since this information is already provided (and 
automatically updated) in root-hints would it not make sense to utilise it for 
RFC7706 in auth-zone, something like?:

auth-zone:
    name: .
    master: path/to/root-hints
not all root servers allow zone transfers so you don't 
want to list them all as masters.

To my understanding (http://www.dns.icann.org/services/axfr/) all servers do permit zone transfer except l.root-servers.net

I did send an example unbound config for review to the DNSOP mailing list:

https://mailarchive.ietf.org/arch/msg/dnsop/KLJFVjgALzvjZY0F0aZjFhE60LQ

To my understanding the quotes ("") in the syntax are not required. It works as well without and unbound-checkconf does claim any error for a syntax without the quotes.

Reply via email to