[dns-operations] DNS trust dependencies for TLDs

Antoin Verschuren Antoin.Verschuren at sidn.nl
Mon Jun 15 07:44:56 UTC 2009

Hash: SHA256

I don't get it, sorry.
The .nl zone is a delegation only zone. (if not, then please provide me with a clear definition).
I think having some NS'es for .nl in a different zone or even under a different TLD is a good practice when glue failures arise due to operational errors.
Having all your eggs in the same basket does not appear redundant to me.
And I don't understand why such a situation should be different for a TLD as compared to any other zone.
As said, our dependency on such other zones is well considered.

Antoin Verschuren

Technical Policy Advisor
Utrechtseweg 310
PO Box 5022
6802 EA Arnhem
The Netherlands

T +31 26 3525500
F +31 26 3525505
M +31 6 23368970
E antoin.verschuren at sidn.nl
W http://www.sidn.nl/

> -----Original Message-----
> From: Matthew Dempsky [mailto:matthew at dempsky.org]
> Sent: Monday, June 15, 2009 5:57 AM
> To: Mark Andrews
> Cc: Florian Weimer; dns-operations at mail.dns-oarc.net; Antoin Verschuren
> Subject: Re: [dns-operations] DNS trust dependencies for TLDs
> On Sun, Jun 14, 2009 at 8:42 PM, Mark Andrews<marka at isc.org> wrote:
> >        delegation-only comes with warnings saying not to apply it
> >        to non-delegation-only zones.  SO is not a delegation-only
> >        zone so you shouldn't turn it on for SO.
> Right.  Florian's point was that if a TLD like .nl were to restructure
> to use only in-zone name server names, they might want to group those
> names into a distinct sub-zone to avoid issues with BIND servers that
> still have .nl configured as a delegation-only zone.
Version: 9.6.3 (Build 3017)


More information about the dns-operations mailing list