On Tue, Mar 04, 2014 at 05:32:09PM +1100,
Mark Andrews <[email protected]> wrote
a message of 24 lines which said:
> *Glue records are not optional in a referral.*
Why? A resolver can always reissue A and AAAA requests after receiving
NS RRsets without glue. This increase latency but it will work.
But there is more: in a referral, sending *all* the glue records *is*
optional.
% dig +bufsize=512 @f.root-servers.net A www.internautique.fr
; <<>> DiG 9.9.3-rpz2+rl.13214.22-P2-Ubuntu-1:9.9.3.dfsg.P2-4ubuntu1.1 <<>>
+bufsize=512 @f.root-servers.net A www.internautique.fr
; (2 servers found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29492
;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 8, ADDITIONAL: 7
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;www.internautique.fr. IN A
;; AUTHORITY SECTION:
fr. 172800 IN NS f.ext.nic.fr.
fr. 172800 IN NS d.nic.fr.
fr. 172800 IN NS d.ext.nic.fr.
fr. 172800 IN NS e.ext.nic.fr.
fr. 172800 IN NS g.ext.nic.fr.
fr. 86400 IN DS 20122 8 2 (
A4208B55FFB352EDC816D9329283DD8BBDDE44C58539
5AF9AA7275ABE3CF6795 )
fr. 86400 IN DS 35095 8 2 (
23C6CAADC9927EE98061F2B52C9B8DA6B53F3F648F81
4A4A86A0FAF9843E2C4E )
fr. 86400 IN RRSIG DS 8 1 86400 (
20140312000000 20140304230000 33655 .
PG6KEeoGIzsI1KnwWLFCjbmfy9Gvc8EyOlHaAR/vBMD9
kGKZW68OczNt95JwpA0xTRBBH+4wdxNZhrIiScJ4vT/A
mjrwt2sV1SPFl1+gdX0yynYVwFd+5aVhOsZO7Djo/KzZ
3HmHxttWjZGnQDbok5sUNuPwcKu2zENiwDsIS9M= )
;; ADDITIONAL SECTION:
d.ext.nic.fr. 172800 IN A 192.5.4.2
d.nic.fr. 172800 IN A 194.0.9.1
e.ext.nic.fr. 172800 IN A 193.176.144.22
f.ext.nic.fr. 172800 IN A 194.146.106.46
g.ext.nic.fr. 172800 IN A 194.0.36.1
d.ext.nic.fr. 172800 IN AAAA 2001:500:2e::2
;; Query time: 180 msec
;; SERVER: 2001:500:2f::f#53(2001:500:2f::f)
;; WHEN: Wed Mar 05 14:46:51 GMT 2014
;; MSG SIZE rcvd: 500
Note all the glue records were sent and, yet, BIND did not set TC=1.
_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop