1 Mar 2008 08:00
Re: dns-0x20.txt
Mark Andrews <Mark_Andrews <at> isc.org>
2008-03-01 07:00:50 GMT
2008-03-01 07:00:50 GMT
> > On 29-Feb-2008, at 12:57, Paul Vixie wrote: > > >>> marka has made the revolutionary (to me at least) proposal that once > >>> you've heard EDNS0 from a responder, you should remember that you > >>> did, and > >>> you should not be willing to believe that they've lost this > >>> capability. > >> > >> I'm worried about how you would determine that the responder was > >> the same > >> across subsequent queries sent to the same address and port. > > > > NSID? > > If we're talking green fields, sure, but I don't think it's reasonable > to expect non-EDNS-capable servers to support NSID. > > >> Anycast servers provide meat for this concern. If the query > >> frequency is > >> very low, even routine server renumbering or system administration > >> might > >> provide some protein. > >> > >> On the face of it, this proposal does not seem very robust. > > > > i agree. however, we have in the past insisted that all authority > > servers for > > a zone support the same level of dnssec. could we not also insist(Continue reading)
RSS Feed