On Jul 9, 2013, at 3:46, Antoin Verschuren wrote:

> I know you all wish the world was simpler, but it isn't, We've tried.


I'd voiced support for CDS before and have even gone as far as visiting with 
Olafur and Warren to work on the mechanism.

But since the last conversation, I'm not as optimistic.  In part because of 
what Antoin wrote above.

I wish that we could have something done only in-band but I also think it will 
be impossible to achieve this.

The CDS proposal is fine for answering the question of how data is marshalled, 
but it doesn't answer other factors.  I haven't been able to draw a circle 
around the other factors - is what we are trying to achieve a "transaction" or 
a version of a "remote procedure call" or something else.

That the child has no information about the parent - in the sense that some 
parents have cutpoints deeper than 1 and that the child zone has no information 
about the parent name servers, knowing where how to locate the service is 
difficult.  (I'm leaving out the possibility of using a recursive server to 
discover the parent because that's a function that you really don't want in a 
key management system or an authoritative server.

There is also no "semaphore" system in place that will inform the parent and 
child what state of the DS transfer is in.  The draft assumes a poll cycle on 
the parent and detection by the client - but what if there's a race condition?  
Or one side gets stuck in a state (of the protocol state machine) and leaves 
the other side spinning?

These are concerns that are not well defined and I've off and on tried to find 
a more rigorous framework from which to hang them.  But Antoin sums up the 
"operator" view that - the world is more complicated than a simple solution 
away from completeness.

I said "I'm not as optimistic."  This doesn't mean I'm pessimistic nor 
withdrawing support for working on this in the working group.  There's a need 
to make DS management easier but a simple solution is no longer what I envision.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis             
NeuStar                    You can leave a voice message at +1-571-434-5468

There are no answers - just tradeoffs, decisions, and responses.

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to