Greetings,

The NXDOMAIN redirection features in BIND 9 - "type redirect" zones,
and the "nxdomain-redirect" option - were introduced in BIND 9.8 and
9.11 respectively.  They each trigger an extra lookup from an alternate
namespace allowing an NXDOMAIN response to be replaced with a positive
answer, unless the NXDOMAIN originates from a DNSSEC-signed domain.  In
that case, the rewritten answer would fail to validate, so the NXDOMAIN
is passed through unchanged.

At the time these features were first implemented, DNSSEC-signed domains
and validating resolvers were still quite rare.  As they have become more
and more common, NXDOMAIN redirection has become less and less effective.
We believe it is now only used infrequently in production environments.
(Please let us know if this is incorrect.)

Aside from its limited utility, NXDOMAIN redirection introduces complexity
into the query processing logic that has led to security bugs in the past,
and may lead to more in the future.

Consequently, per ISC's deprecation policy, I am notifying the mailing
list that we intend to end support for "type redirect" zones and for the
"nxdomain-redirect" option in named.  Our plan is to mark them as
deprecated in BIND 9.20, and remove them completely as of BIND 9.22.

Comments, questions and feedback are welcome.

-- 
Evan Hunt -- [email protected]
Internet Systems Consortium, Inc.
-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from 
this list.

Reply via email to