[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-dnsext-forgery-resilience-01.txt





--On 16 November 2007 12:52:37 -0200 Stephane Bortzmeyer <bortzmeyer@nic.fr> wrote:

On Mon, Nov 12, 2007 at 08:35:43PM -0200,
 Stephane Bortzmeyer <bortzmeyer@nic.fr> wrote
 a message of 25 lines which said:

More detailed, with the help of Alex Bligh:

New version that I propose,

This works for me. I am presuming the "Rationale" section is not
for the RFC but for the list, or we might change "bad guys" to
"attacker" etc.

[ I Had drafted a response saying it may be that duplicating query IDs where
 the rest of the query n-tuple is different is desirable on high volume
 query originators, with some stats to indicate when it might be necessary,
 and rephrased in terms of the necessity of disambiguating responses
 rather than merely saying "dangerous". However, given the difficulties
 with SERVFAIL etc., I concluded that if you stick all this in, you
 are left more with the definition of a problem for an implementers rather
 than implementation advice. On the basis these extra words were thus
 unhelpful, I suggest sticking with what you wrote ]

Alex

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>