Hi, In a recent run of my gonemaster analysis of all the TLDs, I just discovered that four ccTLDs has stale glue in the root for the RIPE nameservers, https://gonemaster.evilbit.de/analysis/tags/OUT_OF_BAILIWICK_ADDR_MISMATCH?s... It's for the ccTLDs ne, ps, sd, and tj, which as the nameservers [ne|ps|sd|tj].cctld.authdns.ripe.net that all have old glue. I have not seen this before, but also I have just updated the testcase specification for this specifically, as the root does not always give all the glue from the root. Just a heads up to whoever manages this glue. / Patrik
Dear Patrik, Thanks for this report. We are aware of this issue. At the start of 2025, we began renumbering the IPv6 prefix containing these name servers. We presented our reasons and plan in our updates to the DNS WG during RIPE 90 and RIPE 91. The renumbering required coordination with various parties, including all the ccTLDs to whom RIPE NCC provides secondary DNS service. Most parties managed to update the address records. However, these 4 ccTLDs did not manage to update the glue records, despite all our frequent and vigorous efforts to reach them by email, phone and regional contacts. We also opened requests with IANA to update the glue records, but without approval from the ccTLD contacts, the requests cannot be processed. Ultimately the ccTLDs are responsible for maintaining the correct glue records in the root zone. Each one of these ccTLDs has at least one other working IPv6 glue record, as well as several working IPv4 glue records, so DNS resolvers are able to follow the delegation and resolve names. Regards, Anand Buddhdev RIPE NCC On 15/08/2026 17:10, Patrik Wallstrom via dns-wg wrote:
Hi,
In a recent run of my gonemaster analysis of all the TLDs, I just discovered that four ccTLDs has stale glue in the root for the RIPE nameservers,
https://gonemaster.evilbit.de/analysis/tags/ OUT_OF_BAILIWICK_ADDR_MISMATCH?search=OUT_OF_BAILIWICK_ADDR_MISMATCH
It's for the ccTLDs ne, ps, sd, and tj, which as the nameservers [ne|ps| sd|tj].cctld.authdns.ripe.net that all have old glue. I have not seen this before, but also I have just updated the testcase specification for this specifically, as the root does not always give all the glue from the root.
Just a heads up to whoever manages this glue.
/ Patrik
Hi, On Thu, Aug 20, 2026 at 10:06:32AM +0200, Anand Buddhdev wrote:
Most parties managed to update the address records. However, these 4 ccTLDs did not manage to update the glue records, despite all our frequent and vigorous efforts to reach them by email, phone and regional contacts. We also opened requests with IANA to update the glue records, but without approval from the ccTLD contacts, the requests cannot be processed. Ultimately the ccTLDs are responsible for maintaining the correct glue records in the root zone.
I'm not really a DNS person, I just sometimes pretend to be one. Here, I am very confused. Why would glue be required for a nameserver that sits in a different DNS hierarchy? As in, why is the question of "correct or incorrect glue" relevant at all here? I do understand the ".net IN NS a.gtld-servers.net. which can only be resolved with glue" case, but ".ne IN NS ne.cctld.authdns.ripe.net" should be fine without any glue? Curious, Gert Doering -- NetMaster -- have you enabled IPv6 on something today...? SpaceNet AG Vorstand: Sebastian v. Bomhard, Karin Schuler, Sebastian Cler Joseph-Dollinger-Bogen 14 Aufsichtsratsvors.: Dr. Frank Thiäner D-80807 Muenchen HRB: 136055 (AG Muenchen) Tel: +49 (0)89/32356-444 USt-IdNr.: DE813185279
On 21. 08. 26 12:44, Gert Doering wrote:
Hi,
On Thu, Aug 20, 2026 at 10:06:32AM +0200, Anand Buddhdev wrote:
Most parties managed to update the address records. However, these 4 ccTLDs did not manage to update the glue records, despite all our frequent and vigorous efforts to reach them by email, phone and regional contacts. We also opened requests with IANA to update the glue records, but without approval from the ccTLD contacts, the requests cannot be processed. Ultimately the ccTLDs are responsible for maintaining the correct glue records in the root zone.
I'm not really a DNS person, I just sometimes pretend to be one.
Here, I am very confused. Why would glue be required for a nameserver that sits in a different DNS hierarchy? As in, why is the question of "correct or incorrect glue" relevant at all here?
I do understand the ".net IN NS a.gtld-servers.net. which can only be resolved with glue" case, but ".ne IN NS ne.cctld.authdns.ripe.net" should be fine without any glue?
Emphasis on "should". In theory it is not needed. In practice for some TLDs resolving their out-of-domain name servers involved delegation cycles and these are not resolvable without glue. (E.g. cd TLD in 2025.) Side note: Traditionally permissibility of glue was determined by the owner zone which contains the delegation - for TLDs the root. I.e. for TLD any glue goes. Side note 2: I'm not saying it is a good idea, but it is like that for last ~ 40 years. -- Petr Špaček
I Anand, I should be able to assist on .ne and .sd. I will reach out to you separately once I receive feedback. Cheers, -- Yazid A. On 8/20/26, 11:07, "Anand Buddhdev" <anandb@ripe.net <mailto:anandb@ripe.net>> wrote: Dear Patrik, Thanks for this report. We are aware of this issue. At the start of 2025, we began renumbering the IPv6 prefix containing these name servers. We presented our reasons and plan in our updates to the DNS WG during RIPE 90 and RIPE 91. The renumbering required coordination with various parties, including all the ccTLDs to whom RIPE NCC provides secondary DNS service. Most parties managed to update the address records. However, these 4 ccTLDs did not manage to update the glue records, despite all our frequent and vigorous efforts to reach them by email, phone and regional contacts. We also opened requests with IANA to update the glue records, but without approval from the ccTLD contacts, the requests cannot be processed. Ultimately the ccTLDs are responsible for maintaining the correct glue records in the root zone. Each one of these ccTLDs has at least one other working IPv6 glue record, as well as several working IPv4 glue records, so DNS resolvers are able to follow the delegation and resolve names. Regards, Anand Buddhdev RIPE NCC On 15/08/2026 17:10, Patrik Wallstrom via dns-wg wrote:
Hi,
In a recent run of my gonemaster analysis of all the TLDs, I just discovered that four ccTLDs has stale glue in the root for the RIPE nameservers,
https://urldefense.com/v3/__https://gonemaster.evilbit.de/analysis/tags/__;!... <https://urldefense.com/v3/__https://gonemaster.evilbit.de/analysis/tags/__;!!PtGJab4!9D6rOy6HYHToE9_6lLi6L5AXND1vDh_ZjcMtSl2FFGSn1E8nzMWqlyIEUcUrELwlDyZdm5lzBFGUMB1avFep-ec$> [gonemaster[.]evilbit[.]de] OUT_OF_BAILIWICK_ADDR_MISMATCH?search=OUT_OF_BAILIWICK_ADDR_MISMATCH
It's for the ccTLDs ne, ps, sd, and tj, which as the nameservers [ne|ps| sd|tj].cctld.authdns.ripe.net that all have old glue. I have not seen this before, but also I have just updated the testcase specification for this specifically, as the root does not always give all the glue from the root.
Just a heads up to whoever manages this glue.
/ Patrik
To unsubscribe from this mailing list or change your subscription options, please visit: https://urldefense.com/v3/__https://mailman.ripe.net/mailman3/lists/dns-wg.r... <https://urldefense.com/v3/__https://mailman.ripe.net/mailman3/lists/dns-wg.ripe.net/__;!!PtGJab4!9D6rOy6HYHToE9_6lLi6L5AXND1vDh_ZjcMtSl2FFGSn1E8nzMWqlyIEUcUrELwlDyZdm5lzBFGUMB1aru6copE$> [mailman[.]ripe[.]net] As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://urldefense.com/v3/__https://www.ripe.net/membership/mail/mailman-3-m... <https://urldefense.com/v3/__https://www.ripe.net/membership/mail/mailman-3-migration/__;!!PtGJab4!9D6rOy6HYHToE9_6lLi6L5AXND1vDh_ZjcMtSl2FFGSn1E8nzMWqlyIEUcUrELwlDyZdm5lzBFGUMB1aizGqtrI$> [ripe[.]net]
participants (5)
-
Anand Buddhdev -
Gert Doering -
Patrik Wallstrom -
Petr Špaček -
Yazid Akanho