Re: DNSSEC architecture vs reality

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Apr 13, 2021 at 09:55:34AM +0200, Petite Abeille wrote:
> > On Apr 13, 2021, at 02:48, Michael Thomas <mike@xxxxxxxx> wrote:
> > Oh, don't get me wrong: using TXT records is a colossal hack.
> 
> Perhaps. But a practical one. Perfect is the enemy of good.

The TXT RR thing is a distraction.  I'm all for pragmatism, but the
problem with using TXT RRs for anything other than commentary is that
the form of the name of the RRset is the only TXT RDATA payload type
identification available, which increases the number of distinct
domainnames one has to query, which complicates any concepts like
combining related answers or profiling queries.  Not a fatal problem,
but a very annoying one.

Since TLSA shipped (and SSHFP, and URI, and soon HTTPS and SVCB, and...)
I suspect this sub-thread can only be unproductive.  (Except in so far
as we might end up with something like J. Levine's I-D on RDATA schemas
published.

Nico
-- 




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux