[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: Operational issues



>      Zone files should remain easily editable.
> This is not a requirement: zone files are UI for administration. Some
> DNS systems don't rely on zone files. We should not start getting into
> admin UI here.

I agree that this is getting too much into implementation.  Someone else
(sorry can't remember who) suggested something along the lines of:

"It should be as easy to add IDNs to the DNS as ASCII-only names."

I think this would be an acceptable alternative.

>      Character set of a signed zone file should be capable of being the
>      same as the character set of the unsigned zone file.
> Ditto.

This is perhaps not phrased very well.  What I really want from this
requirement (or a similar one) is that offline DNSSEC signing should be
possible, and that it should be possible to look at the signed file and see
that it is the same as the unsigned one.  I have seen scripts go wrong, and
the wrong file be installed by mistake.  If we end up mandating something
which changes my favourite

banos.com. IN A 1.2.3.4

into

?whdofk?sldfasd;k763jk?. IN A 1.2.3.4

then it's very hard for me to check what is going on.  I would like a weak
requirement which prevents this from happening.

  Andy