Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. A pretty significant change in resolver behavior is proceeding:

A pretty significant change in resolver behavior is proceeding:

Scheduled Pinned Locked Moved Uncategorized
dns
3 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jtk@infosec.exchangeJ This user is from outside of this forum
    jtk@infosec.exchangeJ This user is from outside of this forum
    jtk@infosec.exchange
    wrote last edited by
    #1

    A pretty significant change in resolver behavior is proceeding:

    "[...] BIND 9 is switching to a parent-centric model of delegations. [...] The NS records in the child domain will be treated as normal DNS records and returned as authoritative data, but they will no longer overwrite the delegation data for the domain."

    BIND 9.21+/9.22: parent-centric delegations and no TTL-based cleaning

    favicon

    (lists.isc.org)

    So much of what you may have learned about how #DNS works around the turn of the century is now out of date.

    paul_ipv6@infosec.exchangeP 1 Reply Last reply
    0
    • jtk@infosec.exchangeJ jtk@infosec.exchange

      A pretty significant change in resolver behavior is proceeding:

      "[...] BIND 9 is switching to a parent-centric model of delegations. [...] The NS records in the child domain will be treated as normal DNS records and returned as authoritative data, but they will no longer overwrite the delegation data for the domain."

      BIND 9.21+/9.22: parent-centric delegations and no TTL-based cleaning

      favicon

      (lists.isc.org)

      So much of what you may have learned about how #DNS works around the turn of the century is now out of date.

      paul_ipv6@infosec.exchangeP This user is from outside of this forum
      paul_ipv6@infosec.exchangeP This user is from outside of this forum
      paul_ipv6@infosec.exchange
      wrote last edited by
      #2

      @jtk

      having parent/child mismatches in NS for delegation has always been non-deterministic, but this will definitely surprise folks who've been counting on one broken way of doing things.

      reviewing operational procedures for how to change NS when moving registrars is definitely one place to check for this.

      i'm still not totally sold on DELEG but this will definitely be one step towards making that happen.

      jtk@infosec.exchangeJ 1 Reply Last reply
      0
      • paul_ipv6@infosec.exchangeP paul_ipv6@infosec.exchange

        @jtk

        having parent/child mismatches in NS for delegation has always been non-deterministic, but this will definitely surprise folks who've been counting on one broken way of doing things.

        reviewing operational procedures for how to change NS when moving registrars is definitely one place to check for this.

        i'm still not totally sold on DELEG but this will definitely be one step towards making that happen.

        jtk@infosec.exchangeJ This user is from outside of this forum
        jtk@infosec.exchangeJ This user is from outside of this forum
        jtk@infosec.exchange
        wrote last edited by
        #3

        @paul_ipv6 I'm in favor ofthe parent-centric approach. When I was doing some research on DNS inconsistency, making the parent NS RRset the primary and eventually only authoritative source of that data seemed to be both practical and sensible, at least on paper. I'm not confident this would be problem-free (e.g., RRset update agility) however.

        I'm also not sure about DELEG-related stuff, but I think that can be treated as a separated issue.

        1 Reply Last reply
        1
        0
        • R relay@relay.infosec.exchange shared this topic
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • World
        • Users
        • Groups