On Sun, 4 May 2025 14:14:37 +0200
Ondřej Surý <[email protected]> wrote:

> Hi Stefan,

Hello Ondřej,

Thank you for taking the time to read my draft.

> I've read your draft and I am not really thrilled that this would
> introduce additional processing during the zone loading, during the
> AXFR, during the IXFR, and during the NSUPDATE

I'm not familiar with the inner workings of a name server, so I had not
yet thought about how this would impact the software.

> The draft is definitely underspecified in this area. Especially, the
> IXFR and NSUPDATE cases feel very hairy to me as this is practically
> makes SOA+(_version TXT) to be practically bound together during the
> updates.

Would getting the _version TXT from the zone data only when a query
with the ZONEVERSION option enabled make sense?

> Is this a practical problem that it adds yet another requirement for
> the authoritative nameserver implementations?

I would like to have a uniform way to know what the source of the DNS
data is in a way that it is visible to the public.


> > On 2. 5. 2025, at 14:26, Stefan Ubbink
> > <[email protected]> wrote:
> > 
> > Signed PGP part
> > Hello,
> > 
> > Last year [1] I had an idea to extend ZONEVERSION (RFC9660) with a
> > version of the database.
> > This is my first submission of the Internet Draft.
> > 
> > Please let me know what you think.
> > 
> > [1]
> > https://mailarchive.ietf.org/arch/msg/dnsop/eVJYb-PDKQUPE8Z6VNLTDG_1rbI/
> > 
> > 
> > Begin forwarded message:
> > 
> > Date: Fri, 2 May 2025 01:06:56 -0700
> > From: [email protected]
> > To: Stefan Ubbink <[email protected]>
> > Subject: New Version Notification for
> > draft-ubbink-zoneversion-extended-00.txt
> > 
> > 
> > A new version of Internet-Draft
> > draft-ubbink-zoneversion-extended-00.txt has been successfully
> > submitted by Stefan Ubbink and posted to the IETF repository.
> > 
> > Name:     draft-ubbink-zoneversion-extended
> > Revision: 00
> > Title:    DNS Zone Version (ZONEVERSION) Extended
> > Date:     2025-05-02
> > Group:    Individual Submission
> > Pages:    4
> > URL:
> > https://www.ietf.org/archive/id/draft-ubbink-zoneversion-extended-00.txt
> > Status:
> > https://datatracker.ietf.org/doc/draft-ubbink-zoneversion-extended/
> > HTML:
> > https://www.ietf.org/archive/id/draft-ubbink-zoneversion-extended-00.html
> > HTMLized:
> > https://datatracker.ietf.org/doc/html/draft-ubbink-zoneversion-extended
> > 
> > 
> > Abstract:
> > 
> >   The DNS Zone Version (ZONEVERSION) extended is a way to get
> >   information about the version of a DNS in the backend.  For
> > example when a DNSSEC signer for a zone generates a new SOA serial,
> > because it has created new RRSIG records, the original data has not
> > changed, but this is not visible to anyone looking at the zone.
> > This document will make it possible show the zone information which
> > is the base of the presented data.
> > 
> > 
> > 
> > The IETF Secretariat
> > 
> > 
> > 
> > 
> > -- 
> > Stefan Ubbink
> > DNS & Systems Engineer
> > Present: Mon, Tue, Wed, Fri
> > SIDN | Meander 501 | 6825 MD | ARNHEM | The Netherlands
> > T +31 (0)26 352 55 00
> > https://www.sidn.nl  
> > 詭>f)鄸+-v{(�'瓇娻N嫥叉靣笡z千u┺櫒ザ噂矈ey夒_  
> 
> 



-- 
Stefan Ubbink
DNS & Systems Engineer
Present: Mon, Tue, Wed, Fri
SIDN | Meander 501 | 6825 MD | ARNHEM | The Netherlands
T +31 (0)26 352 55 00
https://www.sidn.nl

Attachment: pgpfxK55Dn9aJ.pgp
Description: OpenPGP digital signature

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to