ietf-wg-dnsop / draft-ietf-dnsop-avoid-fragmentation

0 stars 1 forks source link

Robert Wilton DISCUSS (3) #7

Open vixie opened 8 months ago

vixie commented 8 months ago

(3) p 3, sec 3.2. Recommendations for UDP requestors

R7. UDP requestors MAY drop fragmented DNS/UDP responses without IP reassembly to avoid cache poisoning attacks.

As written, I don't think that this is really a recommendation. Either it is a just a statement or fact (in which case it is not a recommendation), or it should be upgraded to a SHOULD.

paulwouters commented 6 months ago

duplicate with #8