Internet-Draft catalog-zone-xfr-properties March 2025
Suhonen, et al. Expires 27 September 2025 [Page]
Workgroup:
DNSOP Working Group
Internet-Draft:
draft-axu-dnsop-catalog-zone-xfr-properties-00
Published:
Intended Status:
Standards Track
Expires:
Authors:
A. Suhonen
TREX
W. Toorop
NLnet Labs
A. Buddhdev
RIPE NCC

DNS Catalog Zone Properties for Zone Transfers

Abstract

This document specifies DNS Catalog Zones Properties that define the primary name servers from which specific or all member zones can transfer their associated zone, as well as properties for access control for those transfers.

About This Document

This note is to be removed before publishing as an RFC.

Status information for this document may be found at https://datatracker.ietf.org/doc/draft-axu-dnsop-catalog-zone-xfr-properties/.

Discussion of this document takes place on the dnsop Working Group mailing list (mailto:dnsop@iets.org), which is archived at https://mailarchive.ietf.org/arch/browse/dnsop/.

Source for this draft and an issue tracker can be found at https://github.com/https://github.com/DNS-Hackathon/catalog-extensions-draft.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 27 September 2025.

Table of Contents

1. Introduction

DNS Catalog Zones [RFC9432] described a method for automatic DNS zone provisioning among DNS name servers by the catalog of zones to be provisioned as one or more regular DNS zones. Configuration associated with the member zones, such as from which primary name servers and with which TSIG keys [RFC8945] to transfer the zones, and from which IP addresses and with which TSIG keys DNS notifies [RFC1996] are allowed, were assumed to be preprovisioned at the catalog consumer.

This document specifies DNS Catalog Zones Properties to specify primary name servers and TSIG keys to use to transfer the member zones in a catalog, as well as properties to specify which IP addresses, using which TSIG keys, are allowed to notify [RFC1996] the secondary name server serving the member zones, in order to remove the need to preprovision those at the catalog consumers.

1.1. Requirements language

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.

2. Description

Body text [REPLACE]

3. Catalog Zone Structure

These new properties can be at the top of the catalog zone, where they will affect all member zones, or under a member zone label, where they will affect just that member zone.

4. New Properties

Body text [REPLACE]

4.1. Primaries

Body text [REPLACE]

4.1.1. TSIG Key Name

Body text [REPLACE]

4.1.2. TLSA

Body text [REPLACE]

4.2. Allow Notify

Body text [REPLACE]

4.3. Allow Transfer

Body text [REPLACE]

4.4. Allow Query

Body text [REPLACE]

5. Name Server Behavior

Body text [REPLACE]

6. Implementation and Operational Notes

Body text [REPLACE]

7. IANA Considerations

IANA is requested to add the following entries to the "DNS Catalog Zones Properties" registry under the "Domain Name System (DNS) Parameters" page:

Table 1
Property Prefix Description Status Reference
primaries Primary name servers Standards Track [this document]
allow-notify Allow NOTIFY from Standards track [this document]
allow-transfer Allow zone transfer from Standards track [this document]
allow-query Allow queries from Standards track [this document]

8. Implementation Status

[NOTE to the RFC Editor: Please remove this section before publication]

This section records the status of known implementations of the protocol defined by this specification at the time of posting of this Internet-Draft [RFC7942].

9. Security and Privacy Considerations

Security and Privacy Considerations

10. References

10.1. Normative References

[RFC1996]
Vixie, P., "A Mechanism for Prompt Notification of Zone Changes (DNS NOTIFY)", RFC 1996, DOI 10.17487/RFC1996, , <https://www.rfc-editor.org/rfc/rfc1996>.
[RFC2119]
Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, DOI 10.17487/RFC2119, , <https://www.rfc-editor.org/rfc/rfc2119>.
[RFC8174]
Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, DOI 10.17487/RFC8174, , <https://www.rfc-editor.org/rfc/rfc8174>.
[RFC8945]
Dupont, F., Morris, S., Vixie, P., Eastlake 3rd, D., Gudmundsson, O., and B. Wellington, "Secret Key Transaction Authentication for DNS (TSIG)", STD 93, RFC 8945, DOI 10.17487/RFC8945, , <https://www.rfc-editor.org/rfc/rfc8945>.
[RFC9432]
van Dijk, P., Peltan, L., Surý, O., Toorop, W., Monshouwer, C.R., Thomassen, P., and A. Sargsyan, "DNS Catalog Zones", RFC 9432, DOI 10.17487/RFC9432, , <https://www.rfc-editor.org/rfc/rfc9432>.

10.2. Informative References

[RFC7942]
Sheffer, Y. and A. Farrel, "Improving Awareness of Running Code: The Implementation Status Section", BCP 205, RFC 7942, DOI 10.17487/RFC7942, , <https://www.rfc-editor.org/rfc/rfc7942>.

Appendix A. Example Catalog with One of Everything

Example Catalog with One of Everything

Acknowledgements

Thanks everybody who helped making this work possible.

Contributors

Thanks to all of the contributors.

Authors' Addresses

Aleksi Suhone
TREX Regional Exchanges Oy
Kuninkaankatu 30 A
FI-33720 Tampere
Finland
Willem Toorop
NLnet Labs
Science Park 400
1098 XH Amsterdam
Netherlands
Anand Buddhdev
RIPE NCC
Stationsplein 11
1012 AB Amsterdam
Netherlands