In message <8d78b784-34d3-421e-b82c-52dd32e22...@fl1ger.de>, "Ralf Weber" write s: > Moin! > > This may be totally in appropriate > > On 6 Nov 2015, at 0:54, Mark Andrews wrote: > > I keep getting told the IETF can't tell people what to do > > but that is *exactly* what we do do when we issue a BCP. > > We tell people what best current practice is and ask them > > to follow it. > > > > Today we have TLDs that do perform all sorts of checks on > > servers they delegate zones to and some do inform the > > operators of those zones that they have errors. Those > > checks cover in part tests described in > > draft-andrews-dns-no-response-issue. > Really TLDs doing repeated checks? I know some do when you > register domains, but repeatedly? Examples?
Yes. Daily checks of all delegated server. I don't believe they are currently reporting the discovered faults. http://bamus.switch.ch/edns/summary.html Others do as well. ICANN runs regular checks of TLD servers and they do report when they fail those checks for atleast some of the TLDs. > > So do we adopt this or do we continue to lie to ourselves > > about what BCP actually do? > They recommend something. The problems is when your > recommendations are interfering with business or policy aspects > which this draft clearly does: > > "If repeated attempts to inform and get the customer to correct / > replace the faulty server are unsuccessful the TLD operator shall > remove all delegations to said server from the zone." Lots of BCP's have costs associated with them. Checking delegations and getting them corrected has always been part of their responsabilities as has been removing delegations that cause operational problems They really are not being ask to do anything that they should not already be doing. I would hope that they never have to remove a delegation. That sending a number of emails over several months would be enough. It will be for many sites. They just need to be informed that they have a issue and they will update to fixed release. Some will complain that the TLD's are being busybodies, but having a document that says these checks should be being performed will backup the TLD's. Those that perform these checks today need this backup. TLD's will decide in the end whether they remove the delegation or not. Backing up that action with consensus that they should be doing it helps the TLD should they do so. > <cynic mode=on> > So you are telling TLD to spend money for checks that will decrease > there revenue. TLDs make money by registering domains. The don't make > money by running DNS, that is cost. > </cynic mode> If they don't run the DNS they don't get to take in the money. > I know that a lot of TLDs go to great lengths running a good DNS > service and have sensible policies for there registrars to run a good > DNS service also, and the above comments are not for them, but some > people only look at the money. Part of running a good service is ensuring that the delegations work. This has always been part of there operational responsabilities even if some of them would like to forget that. TLD have also been required to remove delegations that cause operational problems. They do this today for sites that emit spam, host malware etc. Sites that use nameserver that are not rfc compliant do cause operational problems. Removing a delegation for that after repeated attempts to get the issue addressed is no different than removing a delegation for spaming. Running nameservers that do not answer well formed queries causes when a option is set or a flags is not zero cause operational problems. Running nameservers that return the wrong error code when option is set or a flags is not zero cause operational problems. Lookup are failing (present tense) due to these issues. More will fail as clients make more use features that should work for all site and do work for the majority of sites. We don't yet have clients sending EDNS(1) queries but EDNS flags, EDNS options, DNS flags, and unknown types are all regular occurances. Yes, there are sites today that don't repond to DO=1 queries. Yes, there are sites today that don't repond to AD=1 queries. Yes, there are sites today that don't repond to EDNS queries. Yes, there are sites today that don't repond to EDNS queries with a EDNS option. Yes, there are sites today that don't repond to various query types. There are sites that respond with NXDOMAIN rather than NOERROR when you do one of the above. The operational problems that result from these behaviours should be obvious to everyone on this list. There are lots of other incorrect responses that cause operational problems. > So long > -Ralf -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop