Re: [DNSOP] Ben Campbell's No Objection on draft-ietf-dnsop-resolver-priming-09: (with COMMENT)

2016-12-08 Thread Ben Campbell
On 6 Dec 2016, at 13:08, Paul Hoffman wrote: In section 3.1, is there a reason the requirement in paragraph 2 does not get a 2119 keywords, when the requirement in the first paragraph does? They seem similar in impact. The paragraph is: If a priming query does not get a response, the rec

Re: [DNSOP] Working Group Last Call draft-ietf-dnsop-refuse-any

2016-12-08 Thread Tony Finch
Stephane Bortzmeyer wrote: > > Why not also when cookies are used? Like TCP, they protect against > reflection attacks. My reason for deploying minimal-any was not for direct reflection attacks, because RRL already deals with direct reflection attacks. I wanted to avoid sending truncated UDP res

Re: [DNSOP] Working Group Last Call draft-ietf-dnsop-refuse-any

2016-12-08 Thread Stephane Bortzmeyer
On Tue, Nov 29, 2016 at 09:10:02AM +0100, Matthijs Mekking wrote a message of 196 lines which said: > > This is operational choice, if we call that out do we also call > > out that answer may depend on address, TSIG etc ? > > No, just TCP :) Why not also when cookies are used? Like TCP, they