[dns-operations] DNS trust dependencies for TLDs
Antoin Verschuren
Antoin.Verschuren at sidn.nl
Mon Jun 15 07:44:56 UTC 2009
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
I don't get it, sorry.
The .nl zone is a delegation only zone. (if not, then please provide me with a clear definition).
I think having some NS'es for .nl in a different zone or even under a different TLD is a good practice when glue failures arise due to operational errors.
Having all your eggs in the same basket does not appear redundant to me.
And I don't understand why such a situation should be different for a TLD as compared to any other zone.
As said, our dependency on such other zones is well considered.
Antoin Verschuren
Technical Policy Advisor
SIDN
Utrechtseweg 310
PO Box 5022
6802 EA Arnhem
The Netherlands
T +31 26 3525500
F +31 26 3525505
M +31 6 23368970
E antoin.verschuren at sidn.nl
W http://www.sidn.nl/
> -----Original Message-----
> From: Matthew Dempsky [mailto:matthew at dempsky.org]
> Sent: Monday, June 15, 2009 5:57 AM
> To: Mark Andrews
> Cc: Florian Weimer; dns-operations at mail.dns-oarc.net; Antoin Verschuren
> Subject: Re: [dns-operations] DNS trust dependencies for TLDs
>
> On Sun, Jun 14, 2009 at 8:42 PM, Mark Andrews<marka at isc.org> wrote:
> > delegation-only comes with warnings saying not to apply it
> > to non-delegation-only zones. SO is not a delegation-only
> > zone so you shouldn't turn it on for SO.
>
> Right. Florian's point was that if a TLD like .nl were to restructure
> to use only in-zone name server names, they might want to group those
> names into a distinct sub-zone to avoid issues with BIND servers that
> still have .nl configured as a delegation-only zone.
-----BEGIN PGP SIGNATURE-----
Version: 9.6.3 (Build 3017)
wsBVAwUBSjX7+DqHrM883AgnAQhQgAf/XZyQ8GHKfUPhTF8UImTw1myo2caqYmHZ
DqZYCNiyNfNFvA3VnlGf+w4JhZPfxGIz8qFFkLlWLTunPnluKQbBBk6M0tX7W7vo
ngVSYj94VTPMDtW8SwoNU3v/TgwFcr5+DpTSLTCpf4MPQ9i/a0mWbeS/NaTnOzbU
w6Gv1L4JSdI9KaV6EOZ1AI8rTKmjTxhFRMSxl8/vmMAH8WndvWxMLdZ+WUTjSwd5
ig6Qdw7eP6dSNsEx9RT8hJhNRKA8p+TGCuFAykApPN5BqXitEz4Dnvgmb3L/F5fa
aSW8zfhsndbJPeoWc6okErBG4Fl6LQ76GKtGUlDRhKF52FHAtA6oqQ==
=FH+H
-----END PGP SIGNATURE-----
More information about the dns-operations
mailing list