Obsoleting IQUERY
updates
- rfc-1035 — Domain names - implementation and specification
Extracted elements (8)
IQUERY was deprecated because it placed an arduous burden on servers (requiring exhaustive database searches or separate inverse indexes), could generate megabyte-sized responses enabling DoS attacks, was unable to refer requesters to other servers, and had no known clients providing meaningful service.
The widely-used alternative of PTR records in the in-addr.arpa tree for reverse mapping of addresses to names has served the community well and is preferable to IQUERY for inverse lookups.
Section 6.4 (including all subsections) of RFC 1035 is entirely superseded by this document and considered obsolete. Implementations previously conforming to RFC 1035's IQUERY behavior should now return NOTIMP.
Name servers SHOULD return a 'Not Implemented' error when an IQUERY request is received, as the IQUERY opcode is now obsolete.
DNS opcode 1 (IQUERY) is redefined as obsolete. Originally used to look up names associated with a given Resource Record value, its definition in RFC 1035 section 4.1.1 is superseded by this document.
IANA is directed to permanently retire IQUERY opcode value 1, which must not be reassigned to any future DNS opcode.
If IQUERY were not obsoleted, securing its responses with DNSSEC would be extremely difficult without on-the-fly digital signing. Removing IQUERY is unlikely to open new security holes since absence of a positive response would logically lead to denial of authentication.
Large IQUERY responses (potentially tens of thousands of 3-tuples) could easily be used to launch denial of service attacks against servers or the network. Obsoleting IQUERY removes this vector.