In message <[email protected]>, Ted Lemon writes:
>
> On Aug 29, 2017, at 10:03 PM, Ted Lemon <[email protected]> wrote:
> > Yes.   As far as I know the text gives IANA the information they need
> > to do; I do not know how they operate their black hole servers, so I am
> > trusting that these instructions are sufficient.   They have been
> > reviewed by people who understand this problem better than I do, like
> > Andrew Sullivan, Paul Hoffman and Mark Andrews.   I was specifically
> > advised not to overspecify this.   I would rather take their word on this
> > than yours, if you will forgive my saying so. :)
>
> Argh.   Warren made me look more closely, and you were right.   Sorry for
> doubting.   :]   Here is the new text for the IANA considerations section:
>
>       IANA is further requested to create a new subregistry within the
>       "Locally-Served DNS Zones" registry <xref target="LSDZ"/>, titled
>       "Transport-Independent Locally-Served DNS Zones", with the same
>       format as the other subregistries.  IANA is requested to add an
>       entry in this new registry for 'home.arpa.' with the description
>       "Homenet Special-Use Domain", listing this document as the reference.

It is up to IANA as to how they implement the delegation.  We just
specify the requirements (insecure delegation to a empty zone).  We
don't need to prescribe *where* leaked traffic is sunk.  IANA has
decades of experience with moving traffic flows if needed.

The simplest delegation is back to the servers for .arpa.  The
servers can be updated by IANA if/when they need to sink the traffic
somewhere else.  The AS112 server however not the set of servers
to sink the traffic too as they are not under IANA's control and
there is no way to get them all to serve home.arpa.

If there is another round I would remove

                        , and MUST point to one or more black hole
   servers, for example 'blackhole-1.iana.org.' and 'blackhole-
   2.iana.org.'

as it is a over specification.  Just let IANA manage it.

B.T.W. blackhole-1.iana.org and blackhole-2.iana.org aren't really
blackholes as they respond to queries.  Operators if blackhole-1.iana.org
and blackhole-2.iana.org are required to ensure that they do answer
and to withdraw routing anouncements for them when they fail to do
so.

Mark

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [email protected]

_______________________________________________
homenet mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/homenet

Reply via email to