ray, i know you mean well, and it's not your fault, but ...
could i convince you to put up a web page with the recipes for the half dozen prominent resolvers with this hack and one or two others?
The BIND instructions are in RFC 8806, as are those for some other resolvers that support this.
There are caveats:
- allowing AXFR of the root is something that some root operators do, but it is not a formal service offering. Any (or all) of them could withdraw it at any point.
- you'll want to have really good monitoring in place to make sure your transfers are succeeding
- without NOTIFY you might miss urgent root zone updates, e.g. in the case of an urgent TLD key roll
- you might also want to use ZONEMD to check that the zone is correct.
in case you did not notice, you left *simple* a few turns back. oh right, this is the dns (see my 2000 rant that dns anti-simplicity [0]).
would you care to put up a web page with the recipe(s) for doing all this? oh, you say there are 42 platforms and at least three ways to do each on any given platform?
and then we wonder why there is such a mess?
randy
[0] The DNS Today Are we Overloading the Saddlebags on an Old Horse? https:/
/ archive. psg. com/ 001213. ietf-dns.
it even predates magenta comic sans :)
-----
To unsubscribe from this mailing list or change your subscription options, please visit: https:// As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https:/mailman. ripe. net/ mailman3/ lists/ dns-wg. ripe. net/ / www. ripe. net/ membership/ mail/ mailman-3-migration/