[dns-operations] I want a pony^H^H^H^H^H^Hto change the TTL (Was: TLD glue sticks around too long

Robert Edmonds edmonds at mycre.ws
Mon Dec 5 18:20:35 UTC 2016


Stephane Bortzmeyer wrote:
> Also, since the resolver uses the TTL from the zone (which is
> authoritative), why worrying about the TTL from the parent? On my
> Unbound, I do get the authoritative ultra-short TTL:

I think this is due to Unbound's "harden-glue" feature:

    harden-glue: <yes or no>
           Will trust glue only if it is within the servers authority.
           Default is on.

Interestingly, other folks think their TLD's glue TTLs are too short:
e.g., the nameserver address records for google.com and
googledomains.com have 4 day TTLs.

-- 
Robert Edmonds



More information about the dns-operations mailing list