[DNSOP] reviewing draft-wkumari-dnsop-root-loopback-00

2014-10-29 Thread Runxia Wan
Hi all,I am reviewing draft-wkumari-dnsop-root-loopback-00 and draft-wkumari-dnsop-dist-root-01. I have some questions about some details of the draft:First, when a resolver falls back to legacy operation, I guess there should be a retry interval for it to retry to work in the loopback operatio

Re: [DNSOP] New Version Notification for draft-livingood-dnsop-negative-trust-anchors-01.txt

2014-10-29 Thread Mark Andrews
In message <10d9f4dd-1be6-41ff-954d-fd223547d...@virtualized.org>, David Conrad writes: > Tim, > > On Oct 29, 2014, at 2:55 PM, Morizot Timothy S > wrote: > > If an authoritative domain (e.g. irs.gov) screwed up its delegation NS > records so it effectively went dark or made some similar sort of

Re: [DNSOP] Fwd: New Version Notification for draft-livingood-dnsop-negative-trust-anchors-01.txt

2014-10-29 Thread Mark Andrews
In message , Warren Kumari writes: > Over on the BIND-Users list there is currently a discussion of > fema.net (one the "Federal Emergency Management Agency" domains) > being DNSSEC borked > (https://lists.isc.org/pipermail/bind-users/2014-October/094142.html) > > This is an example of the sort

Re: [DNSOP] New Version Notification for draft-livingood-dnsop-negative-trust-anchors-01.txt

2014-10-29 Thread David Conrad
Tim, On Oct 29, 2014, at 2:55 PM, Morizot Timothy S wrote: > If an authoritative domain (e.g. irs.gov) screwed up its delegation NS > records so it effectively went dark or made some similar sort of > authoritative DNS or nameserver error, we wouldn't expect the recursive, > caching side to r

Re: [DNSOP] Fwd: New Version Notification for draft-livingood-dnsop-negative-trust-anchors-01.txt

2014-10-29 Thread Morizot Timothy S
Warren Kumari wrote: > Over on the BIND-Users list there is currently a discussion of > fema.net (one the "Federal Emergency Management Agency" domains) > being DNSSEC borked > (https://lists.isc.org/pipermail/bind-users/2014-October/094142.html) > > This is an example of the sort of issues that a

Re: [DNSOP] Fwd: New Version Notification for draft-livingood-dnsop-negative-trust-anchors-01.txt

2014-10-29 Thread Warren Kumari
Over on the BIND-Users list there is currently a discussion of fema.net (one the "Federal Emergency Management Agency" domains) being DNSSEC borked (https://lists.isc.org/pipermail/bind-users/2014-October/094142.html) This is an example of the sort of issues that an NTA could address -- I'd like t

Re: [DNSOP] Workshop on DNS Future Root Service Architecture, Hong Kong, December 8-9, 2014 (SAVE THE DATE)

2014-10-29 Thread John Kristoff
On Tue, 28 Oct 2014 01:07:40 -0700 Paul Vixie wrote: > This two day workshop will focus on the DNS root service architecture > issues raised by two current Internet Drafts: > > 1. http://tools.ietf.org/html/draft-wkumari-dnsop-root-loopback-00 >Decreasing Access Time to Root Servers by Runni

[DNSOP] Bi-weekly reminder of the documents for the WG

2014-10-29 Thread Paul Hoffman
Greetings again. This is a reminder that the documents that this WG is working on, and may or may not be working on in the future, is at https://svn.tools.ietf.org/svn/wg/dnsop/doclist.html It helps the WG chairs to know which documents have enough people willing to review them to move them forw

Re: [DNSOP] Possible slower response with minimization

2014-10-29 Thread David C Lawrence
Warren Kumari: > Stephane Bortzmeyer : >> Warren Kumari wrote >>> wkumari@vimes:~$ dig ns +noall +comments com.akadns.net >>> >> [Example of a nameservcer replying NXDOMAIN for an ENT.] > > Yes, I'm just surprised that Akamai suffers from it. It is definitely considered a bug and has had a CR ope

Re: [DNSOP] Possible slower response with minimization

2014-10-29 Thread Stephane Bortzmeyer
On Mon, Oct 27, 2014 at 03:44:12PM -0700, Doug Barton wrote a message of 86 lines which said: > We already have projects that have bravely gone into these details ... > https://wiki.mozilla.org/Public_Suffix_List comes to mind of > course. [See also the DBOUND effort

Re: [DNSOP] Possible slower response with minimization

2014-10-29 Thread Warren Kumari
On Wed, Oct 29, 2014 at 10:53 AM, Stephane Bortzmeyer wrote: > On Mon, Oct 27, 2014 at 06:09:49PM -0400, > Warren Kumari wrote > a message of 69 lines which said: > >> wkumari@vimes:~$ dig ns +noall +comments com.akadns.net > > [Example of a nameservcer replying NXDOMAIN for an ENT.] Yes, I'm

Re: [DNSOP] Possible slower response with minimization

2014-10-29 Thread Stephane Bortzmeyer
On Mon, Oct 27, 2014 at 06:09:49PM -0400, Warren Kumari wrote a message of 69 lines which said: > wkumari@vimes:~$ dig ns +noall +comments com.akadns.net [Example of a nameservcer replying NXDOMAIN for an ENT.] > Er... wouldn't this break with qnm? Depending on how it is implemented, yes, m