Internet Engineering Task Force (IETF) R. Bellis
Request for Comments: 5966 Nominet UK
Updates: 1035, 1123 August 2010
Category: Standards Track
ISSN: 2070-1721
DNS Transport over TCP - Implementation Requirements
Bellis Standards Track [Page 1]
RFC 5966 DNS over TCP August 2010
Table of Contents
1. Introduction
Most DNS [RFC1034] transactions take place over UDP [RFC0768]. TCP [RFC0793] is always used for zone transfers and is often used for messages whose sizes exceed the DNS protocol's original 512-byte limit.
Bellis Standards Track [Page 2]
RFC 5966 DNS over TCP August 2010 2. Terminology Used in This DocumentThe key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Discussion
In the absence of EDNS0 (Extension Mechanisms for DNS 0) (see below), the normal behaviour of any DNS server needing to send a UDP response that would exceed the 512-byte limit is for the server to truncate the response so that it fits within that limit and then set the TC flag in the response header. When the client receives such a response, it takes the TC flag as an indication that it should retry over TCP instead.
Bellis Standards Track [Page 3]
RFC 5966 DNS over TCP August 2010
The future that was anticipated in RFC 1123 has arrived, and the only standardised UDP-based mechanism that may have resolved the packet size issue has been found inadequate.
4. Transport Protocol Selection
All general-purpose DNS implementations MUST support both UDP and TCP transport.
Bellis Standards Track [Page 4]
RFC 5966 DNS over TCP August 2010 5. Connection HandlingSection 4.2.2 of [RFC1035] says:
6. Response Reordering
RFC 1035 is ambiguous on the question of whether TCP queries may be reordered -- the only relevant text is in Section 4.2.1, which relates to UDP:
Bellis Standards Track [Page 5]
RFC 5966 DNS over TCP August 2010 7. Security ConsiderationsSome DNS server operators have expressed concern that wider use of DNS over TCP will expose them to a higher risk of denial-of-service (DoS) attacks.
8. Acknowledgements
The author would like to thank the document reviewers from the DNSEXT Working Group, and in particular, George Barwood, Alex Bligh, Alfred Hoenes, Fernando Gont, Olafur Gudmondsson, Jim Reid, Paul Vixie, and Nicholas Weaver.9. References 9.1. Normative References[RFC0768] Postel, J., "User Datagram Protocol", STD 6, RFC 768,
Bellis Standards Track [Page 6]
RFC 5966 DNS over TCP August 2010
[RFC1123] Braden, R., "Requirements for Internet Hosts -
9.2. Informative References
[CPNI-TCP] CPNI, "Security Assessment of the Transmission Control