This is a long standing issue. While rare it needs to be addressed by all vendors. BIND sets TC=1 when it can’t fit any glue records in and if a glue record matches the qname it chooses that. Before anyone complains that I’ve listed a response from .GOV servers they where informed years ago about the issue.
Mark > Begin forwarded message: > > From: internet-dra...@ietf.org > Subject: New Version Notification for > draft-andrews-dnsop-glue-is-not-optional-00.txt > Date: 15 April 2020 at 16:03:46 AEST > To: "Mark Andrews" <ma...@isc.org>, "M. Andrews" <ma...@isc.org> > > > A new version of I-D, draft-andrews-dnsop-glue-is-not-optional-00.txt > has been successfully submitted by M. Andrews and posted to the > IETF repository. > > Name: draft-andrews-dnsop-glue-is-not-optional > Revision: 00 > Title: Glue In DNS Referral Responses Is Not Optional > Document date: 2020-04-14 > Group: Individual Submission > Pages: 5 > URL: > https://www.ietf.org/internet-drafts/draft-andrews-dnsop-glue-is-not-optional-00.txt > Status: > https://datatracker.ietf.org/doc/draft-andrews-dnsop-glue-is-not-optional/ > Htmlized: > https://tools.ietf.org/html/draft-andrews-dnsop-glue-is-not-optional-00 > Htmlized: > https://datatracker.ietf.org/doc/html/draft-andrews-dnsop-glue-is-not-optional > > > Abstract: > The DNS uses glue records to allow iterative clients to find the > addresses of nameservers that live within the delegated zone. Glue > records are expected to be returned as part of a referral and if they > cannot be fitted into the UDP response, TC=1 MUST be set to inform > the client that the response is incomplete and that TCP SHOULD be > used to retrieve the full response. > > > > > Please note that it may take a couple of minutes from the time of submission > until the htmlized version and diff are available at tools.ietf.org. > > The IETF Secretariat > > -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org
_______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop