Re: default dns config change causing major poolpah

From: Peter Losher <Peter_Losher_at_isc.org>
Date: Wed, 01 Aug 2007 18:06:14 -0700
Doug Barton wrote:

> Here is where the problem lies. What you're saying here is simply not
> true. I know several of the root operators personally, and in my
> previous position as GM of IANA I worked with them directly both
> individually and collectively. Everything involving a change to a root
> server is done at a near-glacial pace. There no more danger that we
> will wake up tomorrow unable to AXFR the root from any server than
> there is that we'll wake up tomorrow not able to send resolver queries
> to any root server. To say that this IS possible is FUD.

Doug - that is a *BIG* assumption you just made there.  As far as I know
you didn't discuss this change with any of the root server operators
(you certainly didn't with ISC) and we could have told you then how bad
of a idea this was.  It seems you made this change on instinct, and in
addition nowhere does it state in RFC2870 that the root-servers have to
accept AXFR's as part of their service.

You just made with this change what was before a diagnostic service into
a production service and you didn't even ask the folks most affected by
it.  This change should be yanked and yanked now until at least there
has been some discussion with the root server operators.  (and
discussing it on the dns-operations_at_ list does not cut it)

-Peter (with his root-ops hat on his desk)
-- 
Peter_Losher_at_isc.org | ISC | OpenPGP 0xE8048D08 | "The bits must flow"


Received on Wed Aug 01 2007 - 23:06:16 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:39:15 UTC