raybellis / draft-bellis-dnsop-xpf

DNS X-Proxied-For
0 stars 1 forks source link

spend a few words on why XPF is not an EDNS option #13

Open Habbie opened 6 years ago

Habbie commented 6 years ago

suggested by @fanf2

raybellis commented 6 years ago

It was an EDNS option originally.

It was changed to an RR because of complications over adding and removing EDNS options if an OPT RR isn't already present.

rgacogne commented 6 years ago

And also because ignoring an EDNS option while computing TSIG signatures was harder, IIRC

raybellis commented 6 years ago

@rgacogne Right - it would have required full TSIG wrapping and unwrapping in the middlebox.

fanf2 commented 6 years ago

I didn't think of all of those reasons myself :-) This kind of rationale can be really helpful for explaining the context and use-cases of a spec

Habbie commented 6 years ago

I didn't think of all of those reasons myself :-) This kind of rationale can be really helpful for explaining the context and use-cases of a spec

Now I wonder which ones you DID think of!

fanf2 commented 6 years ago

Basically what @raybellis outlined, but I missed @rgacogne’s TSIG point.