> Mark Andrews wrote: > > > It's been done. IT DOES NOT WORK. named has code to prevent > > the records being added because IT DOES NOT WORK and we got > > sick and tired of telling people who ran up against sites > > that did it that IT DOES NOT WORK. It's better to prevent than > > to spend repeated amounts of time dealing with the repercussions. > > > Can't we make it work? I appreciate your honesty. But there are other > dns packages that do allow it. I'm looking for the flexibility to > extra-zone so i can manage root traffic in bind. Its obvious root get > bugus traffic - i advocate a traffic can to send those bogus tlds too. > I would love an AS112 stop sign. That also eliinate the legal liability > to me as a commercial operator of root. > > > > It's easy to remove the checks but then you need to make sure > > all clients will work with the resultant mess. > > > > > It already is a mess. has been for years. What we are doing is fixing > the mess using AS112. I know alot of root operators who would welcome > that friendly terminator for wayward traffic. But I need bind to > terminate *. NS. I feel sorry it does not.
"*." NS will result in lookups for non-existant labels return NODATA rather than NXDOMAIN. This is a BAD change. Lots of sites depend upon NXDOMAIN being returned. The AS112 delegations return NXDOMAIN for almost all queries directed to them as they are the result of gethostbyname(). The times when they don't but those are when the client is searching for the containing zone and expect to get the other types of response. The queries to the root at a mixture of single and multi-label queries. All the single lable queries (unqualified hostname for example) will get a DIFFERENT rcode as a result of this change. This does not if the AS112 usage model. > > Wildcard is defined for intra-zone use. It is not defined > > for extra-zone use. > > > Lets define it. Just call it experimental. or something convenient. i > think its needed for root services. I am told it works under Dr. > Bernstein's named daemon. I still have not tested that myself. But > will eventually. I pray it is the case. Any root operator would > welcome a trash can for bogus traffic. > > and its christmas time. what a wonderful gift. > > regards > joe baptista > > -- > Joe Baptista www.publicroot.org > PublicRoot Consortium > ---------------------------------------------------------------- > The future of the Internet is Open, Transparent, Inclusive, > Representative & Accountable to the Internet community @large. > ---------------------------------------------------------------- > Office: +1 (202) 517-1593 > Fax: +1 (509) 479-0084 > > > --------------000503020107010809040908 > Content-Type: text/x-vcard; charset=utf-8; > name="baptista.vcf" > Content-Transfer-Encoding: 7bit > Content-Disposition: attachment; > filename="baptista.vcf" > > begin:vcard > fn:Joe Baptista > n:Baptista;Joe > org:PublicRoot Consortium > adr:;;963 Ford Street;Peterborough;Ontario;K9J 5V5 ;Canada > email;internet:[EMAIL PROTECTED] > title:PublicRoot Representative > tel;fax:+1 (509) 479-0084 > tel;cell:+1 (416) 912-6551 > x-mozilla-html:FALSE > url:http://www.publicroot.org > version:2.1 > end:vcard > > > --------------000503020107010809040908 > Content-Type: text/plain; charset="us-ascii" > MIME-Version: 1.0 > Content-Transfer-Encoding: 7bit > Content-Disposition: inline > > _______________________________________________ > DNSOP mailing list > DNSOP@ietf.org > https://www1.ietf.org/mailman/listinfo/dnsop > > --------------000503020107010809040908-- > -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED] _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www1.ietf.org/mailman/listinfo/dnsop