Re: Finer control over REFUSED, e.g. root referrals

2025-09-08 Thread Fred Morris
"Our society has ordered itself to be responsible, but also so that no one person is responsible." Ondřej you're not going to like my reply, but I'd like it to be adequately reasoned. It will be debatable. I'm not even sure this is the best venue, maybe dns-operati...@dns-oarc.net would be a bette

Re: Finer control over REFUSED, e.g. root referrals

2025-09-08 Thread Fred Morris
Hello, I appreciated your earlier comment regarding some shared utopian internet citizen responsibility to have a port 53 listener on every address... or not. On 9/8/25 7:42 AM, Michael Richardson wrote: > Fred Morris wrote: > > It needs to recurse to gather the data which it is intended to d

Re: Finer control over REFUSED, e.g. root referrals

2025-09-08 Thread Michael Richardson
Ondřej Surý wrote: > I can definitely say this is not going to be implemented and nobody should. > Not returning answer is a protocol violation that can lead to DNS > spoofing window being much larger. Surely I'm allowed to *not* run a DNS server on an IP address, and dropping repl

Re: Finer control over REFUSED, e.g. root referrals

2025-09-08 Thread Ondřej Surý
> On 8. 9. 2025, at 16:27, Michael Richardson wrote: > > Surely I'm allowed You are absolutely free to do whatever you want. I am just saying, this is not going to be implemented in BIND 9 and should not be implemented in any other DNS software. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My