[dns-operations] Verisign won't delete obsolete glue records?

Doug Barton dougb at dougbarton.email
Tue Mar 2 20:10:44 UTC 2021


On 3/2/21 11:49 AM, Andrew Sullivan wrote:
> On Mon, Mar 01, 2021 at 04:35:47PM -0800, Doug Barton wrote:
>>
>>
>> Perhaps I didn't ask my question clearly enough. Let's take a 
>> delegation for example.com to ns1.example.info and ns2.example.info. 
>> There will be no host records at Verisign for those two names, right? 
> 
> If the registry uses both domain objects and host objects ...

I think you missed my followup where I indicated that from what I can 
see, Verisign is creating host objects for every host mentioned in a 
delegation regardless of bailiwick, but not putting glue records into 
the zone where they are not needed.

For peace of mind I would much rather see the IP addresses in those host 
objects removed when they are not needed as glue, rather than being 
ignored, since that reduces the chance of a spurious glue record being 
published accidentally.

Doug


More information about the dns-operations mailing list