ah, we're out of phase 180 degrees.

the particular problem i happened to catch the other day found
nserver*.apple.com unreachable starting from the root.  i tried with
dig on linux, too.  that didn't work either.  but perhaps trying harder
would make sense.

i noticed that you aren't seeing negative responses to cname queries
from the code. is that something particular to your
environment or is that something we are likely to see, too.?

unfortunately akadns uses cnames in their scheme.  this really stinks.
it seems that the timeout in such a case should depend on the name.
(awful, no?)

i wonder if it might be safe to replace small tts with the expire time in the
soa.  being on the other end of that a decade ago, i remember to maintaining a
server at an old ip address for 2*expiretime to ensure that everybody had
updated.  it was suprising how long the old ip address was cached.

- erik

Reply via email to