The following errata report has been held for document update 
for RFC7686, "The ".onion" Special-Use Domain Name". 

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid6761

--------------------------------------
Status: Held for Document Update
Type: Technical

Reported by: Peter van Dijk <[email protected]>
Date Reported: 2021-11-29
Held by: Mohamed Boucadair (IESG)

Section: 2

Original Text
-------------
   5.  Authoritative DNS Servers: Authoritative servers MUST respond to
       queries for .onion with NXDOMAIN.

   6.  DNS Server Operators: Operators MUST NOT configure an
       authoritative DNS server to answer queries for .onion.  If they
       do so, client software is likely to ignore any results (see
       above).

Corrected Text
--------------
   5.  Authoritative DNS Servers: Authoritative servers SHOULD NOT
       recognize .onion names as special and MUST NOT treat queries for
       .onion names differently from other queries.

   6.  DNS Server Operators: Operators MUST NOT configure an
       authoritative DNS server to answer authoritatively to queries for names 
in .onion.  If they
       do so, client software is likely to ignore any results (see
       above).

Notes
-----
The original text for 5 and 6 is conflicting. A name server cannot respond with 
NXDOMAIN (which is an authoritative answer) without having a zone configured to 
serve that NXDOMAIN from. Clearly the intent of the text is that clients will 
not find authoritative answers to .onion queries anywhere in the DNS.

===Verifier note

see https://mailarchive.ietf.org/arch/msg/dnsop/S2mQZ83THHjV0z8A2iXAtG8Vrpc/

--------------------------------------
RFC7686 (draft-ietf-dnsop-onion-tld-01)
--------------------------------------
Title               : The ".onion" Special-Use Domain Name
Publication Date    : October 2015
Author(s)           : J. Appelbaum, A. Muffett
Category            : PROPOSED STANDARD
Source              : Domain Name System Operations
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to