Re: [dns-wg] Draft of RIPE DNS Resolver Best Common Practices

2023-11-29 Thread Petr Špaček
On 27. 11. 23 13:16, Ralf Weber wrote: ### Aggressive NSEC caching **Aggressive NSEC caching should be enabled.** For: Public resolver operators. "Aggressive NSEC caching", meaning negative caching based on NSEC and NSEC3 values, can reduce traffic greatly. It is important to protect against r

Re: [dns-wg] Draft of RIPE DNS Resolver Best Common Practices

2023-11-29 Thread Petr Špaček
Hello everyone, thank your for hard work on this. I think it's well written document. More substantial feedback below relates to: - TTL recommendations - Selection of transport protocols - EDNS Client Subnet (ECS) - Missing mention of RFC 8906 More in-line below, including couple nits. On 26.