Internet DRAFT - draft-ietf-dnsop-rfc6598-rfc6303
draft-ietf-dnsop-rfc6598-rfc6303
Network Working Group M. Andrews
Internet-Draft ISC
Intended status: Best Current Practice October 11, 2015
Expires: April 13, 2016
Add 100.64.0.0/10 prefixes to IPv4 Locally-Served DNS Zones Registry.
draft-ietf-dnsop-rfc6598-rfc6303-05
Abstract
RFC6598 specified that: "Reverse DNS queries for Shared Address Space
addresses [100.64.0.0/10] MUST NOT be forwarded to the global DNS
infrastructure."
This document formally directs IANA to add the associated zones to
the "IPv4 Locally-Served DNS Zones Registry" to prevent such queries
accidently leaking to the global DNS infrastructure.
Status of This Memo
This Internet-Draft is submitted in full conformance with the
provisions of BCP 78 and BCP 79.
Internet-Drafts are working documents of the Internet Engineering
Task Force (IETF). Note that other groups may also distribute
working documents as Internet-Drafts. The list of current Internet-
Drafts is at http://datatracker.ietf.org/drafts/current/.
Internet-Drafts are draft documents valid for a maximum of six months
and may be updated, replaced, or obsoleted by other documents at any
time. It is inappropriate to use Internet-Drafts as reference
material or to cite them other than as "work in progress."
This Internet-Draft will expire on April 13, 2016.
Copyright Notice
Copyright (c) 2015 IETF Trust and the persons identified as the
document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal
Provisions Relating to IETF Documents
(http://trustee.ietf.org/license-info) in effect on the date of
publication of this document. Please review these documents
carefully, as they describe your rights and restrictions with respect
to this document. Code Components extracted from this document must
include Simplified BSD License text as described in Section 4.e of
Andrews Expires April 13, 2016 [Page 1]
Internet-Draft IPv4 Locally-Served DNS Zones Additions October 2015
the Trust Legal Provisions and are provided without warranty as
described in the Simplified BSD License.
Table of Contents
1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2
2. Changes to IPv4 Locally-Served DNS Zones Registry . . . . . . 2
2.1. RFC6598 Zones . . . . . . . . . . . . . . . . . . . . . . 2
3. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 5
4. Security Considerations . . . . . . . . . . . . . . . . . . . 5
5. Acknowledgements . . . . . . . . . . . . . . . . . . . . . . 5
6. Normative References . . . . . . . . . . . . . . . . . . . . 5
Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 6
1. Introduction
[RFC6598] specified that: "Reverse DNS queries for Shared Address
Space addresses [100.64.0.0/10] MUST NOT be forwarded to the global
DNS infrastructure." [RFC6303] provides guidance on handling such
queries.
This document directs the IANA to add the IPv4 reverse zones
corresponding to 100.64.0.0/10, a netblock reserved in [RFC6598], to
the IPv4 Locally-Served DNS Zone Registry established in [RFC6303].
Unlike [RFC1918] address, which are not expected to be seen by other
parties, the addresses from [RFC6598] are expected to be seen by
parties other than those deploying the addresses, so it is more
crucial that recursive nameservers default to serving these zones
locally.
2. Changes to IPv4 Locally-Served DNS Zones Registry
To add the following zone listed in RFC6598 Zones (Section 2.1) to
the "IPv4 Locally-Served DNS Zone Registry".
2.1. RFC6598 Zones
64.100.IN-ADDR.ARPA
65.100.IN-ADDR.ARPA
66.100.IN-ADDR.ARPA
67.100.IN-ADDR.ARPA
68.100.IN-ADDR.ARPA
Andrews Expires April 13, 2016 [Page 2]
Internet-Draft IPv4 Locally-Served DNS Zones Additions October 2015
69.100.IN-ADDR.ARPA
70.100.IN-ADDR.ARPA
71.100.IN-ADDR.ARPA
72.100.IN-ADDR.ARPA
73.100.IN-ADDR.ARPA
74.100.IN-ADDR.ARPA
75.100.IN-ADDR.ARPA
76.100.IN-ADDR.ARPA
77.100.IN-ADDR.ARPA
78.100.IN-ADDR.ARPA
79.100.IN-ADDR.ARPA
80.100.IN-ADDR.ARPA
81.100.IN-ADDR.ARPA
82.100.IN-ADDR.ARPA
83.100.IN-ADDR.ARPA
84.100.IN-ADDR.ARPA
85.100.IN-ADDR.ARPA
86.100.IN-ADDR.ARPA
87.100.IN-ADDR.ARPA
88.100.IN-ADDR.ARPA
89.100.IN-ADDR.ARPA
90.100.IN-ADDR.ARPA
91.100.IN-ADDR.ARPA
92.100.IN-ADDR.ARPA
Andrews Expires April 13, 2016 [Page 3]
Internet-Draft IPv4 Locally-Served DNS Zones Additions October 2015
93.100.IN-ADDR.ARPA
94.100.IN-ADDR.ARPA
95.100.IN-ADDR.ARPA
96.100.IN-ADDR.ARPA
97.100.IN-ADDR.ARPA
98.100.IN-ADDR.ARPA
99.100.IN-ADDR.ARPA
100.100.IN-ADDR.ARPA
101.100.IN-ADDR.ARPA
102.100.IN-ADDR.ARPA
103.100.IN-ADDR.ARPA
104.100.IN-ADDR.ARPA
105.100.IN-ADDR.ARPA
106.100.IN-ADDR.ARPA
107.100.IN-ADDR.ARPA
108.100.IN-ADDR.ARPA
109.100.IN-ADDR.ARPA
110.100.IN-ADDR.ARPA
111.100.IN-ADDR.ARPA
112.100.IN-ADDR.ARPA
113.100.IN-ADDR.ARPA
114.100.IN-ADDR.ARPA
115.100.IN-ADDR.ARPA
116.100.IN-ADDR.ARPA
Andrews Expires April 13, 2016 [Page 4]
Internet-Draft IPv4 Locally-Served DNS Zones Additions October 2015
117.100.IN-ADDR.ARPA
118.100.IN-ADDR.ARPA
119.100.IN-ADDR.ARPA
120.100.IN-ADDR.ARPA
121.100.IN-ADDR.ARPA
122.100.IN-ADDR.ARPA
123.100.IN-ADDR.ARPA
124.100.IN-ADDR.ARPA
125.100.IN-ADDR.ARPA
126.100.IN-ADDR.ARPA
127.100.IN-ADDR.ARPA
3. IANA Considerations
This document directs IANA to add the zones listed in RFC6598 Zones
(Section 2.1) to the "IPv4 Locally-Served DNS Zone Registry".
IANA is reminded that an insecure delegation for these zones is
required for compliance with [RFC6598] to break the DNSSEC chain of
trust.
4. Security Considerations
This document is thought to present no additional security risks to
the Internet.
5. Acknowledgements
I would like to thank Joe Abley for his review comments.
6. Normative References
[RFC1918] Rekhter, Y., Moskowitz, B., Karrenberg, D., de Groot, G.,
and E. Lear, "Address Allocation for Private Internets",
BCP 5, RFC 1918, DOI 10.17487/RFC1918, February 1996,
<http://www.rfc-editor.org/info/rfc1918>.
Andrews Expires April 13, 2016 [Page 5]
Internet-Draft IPv4 Locally-Served DNS Zones Additions October 2015
[RFC6303] Andrews, M., "Locally Served DNS Zones", BCP 163, RFC
6303, DOI 10.17487/RFC6303, July 2011,
<http://www.rfc-editor.org/info/rfc6303>.
[RFC6598] Weil, J., Kuarsingh, V., Donley, C., Liljenstolpe, C., and
M. Azinger, "IANA-Reserved IPv4 Prefix for Shared Address
Space", BCP 153, RFC 6598, DOI 10.17487/RFC6598, April
2012, <http://www.rfc-editor.org/info/rfc6598>.
Author's Address
M. Andrews
Internet Systems Consortium
950 Charter Street
Redwood City, CA 94063
US
Email: marka@isc.org
Andrews Expires April 13, 2016 [Page 6]