Network Working Group D. Lawrence
Request for Comments: 3425 Nominum
Updates: 1035 November 2002
Category: Standards Track
Obsoleting IQUERY
1 - Introduction
As specified in RFC 1035 (section 6.4), the IQUERY operation for DNS queries is used to look up the name(s) which are associated with the given value. The value being sought is provided in the query's answer section and the response fills in the question section with one or more 3-tuples of type, name and class.
Lawrence Standards Track [Page 1]
RFC 3425 Obsoleting IQUERY November 2002
Operators of servers that do support IQUERY in some form (such as very old BIND 4 servers) generally opt to disable it. This is largely due to bugs in insufficiently-exercised code, or concerns about exposure of large blocks of names in their zones by probes such as inverse MX queries.
2 - Requirements
The key word "SHOULD" in this document is to be interpreted as described in BCP 14, RFC 2119, namely that there may exist valid reasons to ignore a particular item, but the full implications must be understood and carefully weighed before choosing a different course.
3 - Effect on RFC 1035
The effect of this document is to change the definition of opcode 1 from that originally defined in section 4.1.1 of RFC 1035, and to entirely supersede section 6.4 (including subsections) of RFC 1035.
Lawrence Standards Track [Page 2]
RFC 3425 Obsoleting IQUERY November 2002
The text in section 6.4 of RFC 1035 is now considered obsolete. The following is an applicability statement regarding the IQUERY opcode:
4 - Security Considerations
Since this document obsoletes an operation that was once available, it is conceivable that someone was using it as the basis of a security policy. However, since the most logical course for such a policy to take in the face of a lack of positive response from a server is to deny authentication/authorization, it is highly unlikely that removing support for IQUERY will open any new security holes.
5 - IANA Considerations
The IQUERY opcode of 1 should be permanently retired, not to be assigned to any future opcode.
6 - Acknowledgments
Olafur Gudmundsson instigated this action. Matt Crawford, John Klensin, Erik Nordmark and Keith Moore contributed some improved wording in how to handle obsoleting functionality described by an Internet Standard.
7 - References
[RFC1035] Mockapetris, P., "Domain Names - Implementation and
Lawrence Standards Track [Page 3]
RFC 3425 Obsoleting IQUERY November 2002 8 - Author's AddressDavid C Lawrence Nominum, Inc. 2385 Bay Rd Redwood City CA 94063 USA
Lawrence Standards Track [Page 4]
RFC 3425 Obsoleting IQUERY November 2002 9 - Full Copyright StatementCopyright (C) The Internet Society (2002). All Rights Reserved.