re:

Begin forwarded message:

From: "D. J. Bernstein" <djb@cr.yp.to>
Date: January 21, 2019 at 10:24:12 PM EST
To: dns@list.cr.yp.to
Subject: Re: djbdns and EDNS?

My understanding is that this "flag day" is an issue for some firewalls
but not for any version of tinydns. https://dnsflagday.net/ says "This
domain is going to work after the 2019 DNS flag day" for various tinydns
servers that I've tested.

The bigger picture appears to be the following: There's a backlash
against the insane level of complexity that ISC has added to DNS over
many years, most importantly as part of DNSSEC. ISC is exploiting this
as an excuse to get rid of very small chunks of code that handle
interoperability with, e.g., firewalls that time out on EDNS queries.

ISC has a much longer history of threatening to damage interoperability,
and in some cases actually damaging interoperability, usually without
bothering to first obtain agreement on RFCs that specify a date after
which the old behavior is prohibited. This doesn't mean that ISC is
stupid enough to try to damage interoperability with something as widely
deployed as tinydns.

---Dan