[dns-operations] Questions on DNS Flag day 2020 proposal

Davey Song songlinjian at gmail.com
Mon Jun 17 10:58:00 UTC 2019


>
> So, if DNS servers not response to TCP will be treat as DEAD
>

The authoritative server without support of TCP is not DEAD but become weak
due to large DNS response. A small portion of response which is larger than
1220 octets will be truncated after flag day and the authoritative server
can not response in TCP afterwards. In the contrast, before Flag day, there
are still a pretty chance (63% if the dropping rate is 37%)  for that
authoritative server to deliever large resonse to client by fragmenting it.
Unable to delievering large DNS response, that's the pain authoritative
server is going to have.

I withdraw the conclusion that the authoritative server is free from the
flag day of DNS TCP.  Sad.

Davey
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.dns-oarc.net/pipermail/dns-operations/attachments/20190617/dd0d83c5/attachment.html>


More information about the dns-operations mailing list