Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-09 Thread Florian Weimer
On 08/09/2015 01:29 AM, Joe Abley wrote: > At a guess I would imagine that the widespread interest in the most > recent BIND9 assertion failures with TKEY queries have caused code to > be upgraded everywhere. That seems unlikely to me. Many operators only deploy minimal changes, *especially* duri

Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread Mark Andrews
In message <-4512598740891104712@unknownmsgid>, Joe Abley writes: > At a guess I would imagine that the widespread interest in the most > recent BIND9 assertion failures with TKEY queries have caused code to > be upgraded everywhere. Some older versions of BIND9 followed the > pre-6891 specificati

Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread Joe Abley
At a guess I would imagine that the widespread interest in the most recent BIND9 assertion failures with TKEY queries have caused code to be upgraded everywhere. Some older versions of BIND9 followed the pre-6891 specification for unknown EDNS types; perhaps that has had a positive impact on Mark's

Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread manning
You may be correct. The subject suggests TLD servers and their upstreams block EDNS(1) (was this a considered choice or an implementation artifact) and there has been a reduction in blocking at the server level. Unclear if this is a deliberate choice or an upgrade artifact that the server admi

Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread Joe Abley
Hi Bill, Not sure what you mean. Wasn't the point of Mark's email roughly the opposite of what you said? Compliance with EDNS(0) presumably means compliance with RFC 6891. That specification includes handling of unknown EDNS options. Joe Aue Te Ariki! He toki ki roto taku mahuna! > On Aug 8,

Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread manning
Of course this means that EDNS, for all its promise as an extension to allow for more flags/signaling is effectively dead, since anything other than EDNS(0) will now be blocked. Not sure I agree that EDNS compliance is identical to EDNS(0) compliance. manning bmann...@karoshi.com PO Box 6151

Re: [DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread Paul Wouters
On Sun, 9 Aug 2015, Mark Andrews wrote: As of the 8th of August there was a big reduction in the number of TLD zones which filtered queries with unknown EDNS version or unknown EDNS flags. While there is still work to do to improve EDNS compliance this is

[DNSOP] Big reduction in the number of TLD zones blocking EDNS(1) queries

2015-08-08 Thread Mark Andrews
As of the 8th of August there was a big reduction in the number of TLD zones which filtered queries with unknown EDNS version or unknown EDNS flags. While there is still work to do to improve EDNS compliance this is a big step forward. Thank you.