Negative Caching of DNS Resolution Failures
Listen now
Description
In this episode of PING, Verisign fellow Duane Wessels (https://blog.apnic.net/author/Duane-Wessels/) discusses a late state (version 08) Internet draft he’s working on with two colleagues from Verisign. The draft is on Negative Caching of DNS Resolution Failures (https://datatracker.ietf.org/doc/draft-ietf-dnsop-caching-resolution-failures/) and is co-authored by Duane, William Carroll (https://datatracker.ietf.org/person/[email protected]), and Matt Thomas (https://datatracker.ietf.org/person/[email protected])This episode discusses the behaviour of the DNS system overall in the face of failures to answer. There are already mechanisms to deny the existence of a queried name or a specific resource type. There are also mechanisms to define how long this negative answer should be cached, just as there are cache lifetimes defined for how long to hold valid answers, things that do exist, and have been supplied.This time, it’s a cache of not being able to answer. The thing asked about? It might exist, or it might not. This cached data isn’t saying if it does exist or not, it’s a caching failure to be able to answer. As the draft states: “… a non-response due to a resolution failure in which the resolver does not receive any useful information regarding the data’s existence.”Prior DNS specifications did provide guidance on caching in the context of positive responses and negative responses but the only guidance relating to failing to answer was to avoid aggressive re-querying of the nameservers that should be able to answer.Read more about the draft, and other DNS-related work by Duane on the APNIC Blog:* The draft Negative Caching of DNS Resolution Failures (https://datatracker.ietf.org/doc/draft-ietf-dnsop-caching-resolution-failures/) (2023, Version 08)* Adding ZONEMD protections to the root zone (https://blog.apnic.net/2023/07/18/adding-zonemd-protections-to-the-root-zone/) (2023, APNIC Blog post)* [Podcast] Adding ZONEMD protections to the root zone (https://blog.apnic.net/2023/07/20/podcast-adding-zonemd-protections-to-the-root-zone/) (2023, related podcast on PING)* [Podcast] A look back at notable root zone changes (https://blog.apnic.net/2023/05/24/podcast-a-look-back-at-notable-root-zone-changes/) (Duane discusses three significant root zone changes over the last decade)
More Episodes
This time on PING Doug Madory (https://blog.apnic.net/author/doug-madory/) from Kentik (https://www.kentik.com/company/) discusses his recent measurements of the RPKI system worldwide, and it's visible impact on the stability and security of BGP.Doug makes significant use of the Oregon RouteViews...
Published 05/15/24
Published 05/15/24
In this episode of PING, APNIC’s Chief Scientist Geoff Huston (https://blog.apnic.net/author/Geoff-Huston/) discusses Starlink again, and the ability of modern TCP flow control algorithms to cope with the highly variant loss and delay seen over this satellite network. Geoff has been doing more...
Published 05/01/24