On 2023-08-08 18:41 UTC, Paul Hoffman <paul.hoff...@icann.org> wrote:
> On Aug 8, 2023, at 11:27 AM, Florian Obser <florian+i...@narrans.de> wrote:
>> 
>> This introduced at least a nit
>
> Yipes, very good points. 
>
>> 
>>   For example, consider an authoritative server named ns0.example.com
>>   that is served by two installations (with two A records), one at
>>   192.0.2.7 that follows this guidance, and one at 2001:db8::8 that is
>>   a legacy (cleartext port 53-only) deployment.
>> 
>> It doesn't have two A records. It has an A and AAAA record.
>
> Errr, yup!
>
>> I know
>> that Éric asked for a non-legacy IP example,
>
> ...and he's our AD...
>
>> but I don't think this makes
>> things better. I find it very confusing, usually the server would be
>> dual stacked so why would it do different things depending on the
>> address family? Maybe just go v6 only, thusly?
>> 
>>   For example, consider an authoritative server named ns0.example.com
>>   that is served by two installations (with two AAAA records), one at
>>   2001:db8::7 that follows this guidance, and one at 2001:db8::8 that is
>>   a legacy (cleartext port 53-only) deployment.  A recursive client who
>>   associates state with the NS name and reaches 2001:db8::7 first will
>
> It is that uncommon for a name server to have one A record and one
> AAAA record? I'd rather not go all-IPv6 because some readers might
> think that the discussion is for v6-only systems. If possible, I'd

yes, I think so, too.

> rather just say "(with one A record and one AAAA record)".

That's what I was thinking at first, too.

However, if you have a nameserver with one A record and one AAAA record
the nameserver is usually dualstacked, so why would it do DoE+Do53 on
IPv4 and only Do53 on IPv6? Other than it being misconfigured.

So I'm worried that a reader will focus on: Hey, that's just a dumb
configuration and not notice that there are subtleties when there are
multiple servers involved. If you only have one address family that's
more clear. (Your text kinda hints at there being two servers, but it's
very easy to overlook.)

>
> --Paul Hoffman
>
>

-- 
In my defence, I have been left unsupervised.

_______________________________________________
dns-privacy mailing list
dns-privacy@ietf.org
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to