On Nov 4, 2009, at 11:41 AM, Matthew Dempsky wrote:
On Wed, Nov 4, 2009 at 11:26 AM, <bmanning@vacation.karoshi.com> wrote:The current deployment plan is to stage things to push out large responses early - prior to having any actual DNSSEC usable data ... ostensibly toflush out DNSmtu problems.Is this plan to push out large responses indiscriminately, or only in response to queries with DO=1?
Also, has someone done a study what the major recursive resolvers do on response failures from a root? Do they go to another first or do they try a smaller EDNS MTU?