> While it is staight forward enough to do this technically it is still *not* a 
> good idea to deploy it.

> ISP's have leased the address to their customers and for the duration of that 
> lease the CUSTOMER not the ISP should be the one naming the machine.

[Philippe L.] Populating the reverse domain with "technical FQDNs' and let the 
customer name its machine are not incompatible. This is the way it already 
works in IPv4 for some major ISPs. It allows some security checks since the 
"technical" FQDN of the reverse domain is also provisioned in a forward zone 
with an A record matching the PTR record. The customer has still the 
possibility to define its own FQDNs.

It is also possible for the customer to delegate the reverse zone provisioning 
to a third party entity (like DynDNS) so that the PTR and A (or AAAA) records 
have the same customer's FQDN. Procedure is described at the following URL: 
http://dyn.com/support/reverse-dns/. 

Few customers will only need to delegate reverse DNS to this third party 
entity. On the ISP side, the software generating the PTR records "on the fly" 
should have the capacity to handle reverse zone delegation for a specific IP by 
use of CNAME record. If a customer requires reverse DNS delegation for a block 
of IPs or for a full IPv6 prefix, same principle is applicable using the DNAME 
records. 
By default the ISP keeps control on the provisioning of the reverse domain 
"ip6.arpa". On customers' request, ISP can manage exceptions to delegate this 
provisioning. In this case, the customer must assume the fact that some ISP's 
services may not be compatible any more.
  
> When ISPs started doing this with IN-ADDR.ARPA the protocols necessary to 
> have machines populate the zone themselves did not exist.  A lot has changed 
> in the intervening years.


_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations 
confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce 
message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages 
electroniques etant susceptibles d'alteration,
France Telecom - Orange decline toute responsabilite si ce message a ete 
altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged 
information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete 
this message and its attachments.
As emails may be altered, France Telecom - Orange is not liable for messages 
that have been modified, changed or falsified.
Thank you.

_______________________________________________
homenet mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/homenet

Reply via email to