神明達哉 <jin...@wide.ad.jp> wrote:
>
> I'm not sure how we can expect this model to deploy in practice.  With
> this model, the zone admin will need to develop an additional script
> or something integrated into whatever the provisioning framework they
> are using.  Is that the assumption?

I would like it to be integrated into the DNS server, like automatic
DNSSEC signing. But you can implement it as a bag on the side and lots of
places have already done that. (I have a half-arsed implementation which I
desperately want to replace with something better.)

> Perhaps primary server implementations may eventually have some level
> of support that makes this provisioning much less painful (in a way
> other than performing on-demand resolution).  If and when many popular
> implementations do it in a convenient way (at least as convenient as
> the proprietary alternatives), we may hope the new model with ANAME
> optimization will start to deploy, eventually with wider deployment of
> the optimization part as more resolvers support it.

It doesn't have to be sequential like that: the additional section
processing on auth and rec servers, and resolver ANAME optimization won't
cause any interop problems, so they can be deployed whenever the code is
ready and they'll have a useful effect when they encounter an ANAME
record.

Tony.
-- 
f.anthony.n.finch  <d...@dotat.at>  http://dotat.at/
Rockall, Malin, Hebrides, Bailey: Northwest 5 to 7, occasionally gale 8 except
in Rockall, decreasing 4 later. Rough or very rough, becoming moderate or
rough except in Bailey. Showers. Moderate or good.
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to