Dear all,In this updated version of the Delegation Revalidation by DNS Resolvers draft, we address the issues that came up during the dnsop working group session at the IETF 120, namely:
* We mention that the security benefits with DNSSEC validated infrastructure data only applies when re-validation of the referral and authoritative NS RRset responses is done strictly, without falling back to the non-authoritative data. * We address some more error cases, such as what should be done for NODATA responses for the validating NS query, and what to do if validated address records are unreachable. With that, we believe the draft is ready for working group last call. Op 08-01-2025 om 13:22 schreef internet-dra...@ietf.org:
Internet-Draft draft-ietf-dnsop-ns-revalidation-08.txt is now available. It is a work item of the Domain Name System Operations (DNSOP) WG of the IETF. Title: Delegation Revalidation by DNS Resolvers Authors: Shumon Huque Paul Vixie Willem Toorop Name: draft-ietf-dnsop-ns-revalidation-08.txt Pages: 13 Dates: 2025-01-08 Abstract: This document recommends improved DNS resolver behavior with respect to the processing of Name Server (NS) resource record (RR) sets (RRsets) during iterative resolution. When following a referral response from an authoritative server to a child zone, DNS resolvers should explicitly query the authoritative NS RRset at the apex of the child zone and cache this in preference to the NS RRset on the parent side of the zone cut. The (A and AAAA) address RRsets in the additional section from referral responses and authoritative NS answers for the names of the NS RRset, should similarly be re-queried and used to replace the entries with the lower trustworthiness ranking in cache. Resolvers should also periodically revalidate the child delegation by re-querying the parent zone at the expiration of the TTL of the parent side NS RRset. The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-dnsop-ns-revalidation/ There is also an HTMLized version available at: https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-ns-revalidation-08 A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-ietf-dnsop-ns-revalidation-08 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ DNSOP mailing list --dnsop@ietf.org To unsubscribe send an email todnsop-le...@ietf.org
OpenPGP_0xE5F8F8212F77A498_and_old_rev.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ DNSOP mailing list -- dnsop@ietf.org To unsubscribe send an email to dnsop-le...@ietf.org