Questions about RFC 9859 generalized NOTIFY(CDS) support in BIND
Matthijs Mekking
matthijs at isc.org
Tue Sep 15 15:09:15 UTC 2026
Hi Oli,
Thank your for your interest in Generalized DNS Notifications.
On 9/13/26 18:14, Oli Schacher via bind-users wrote:
> Hi,
>
> I'm currently playing around with generalized NOTIFY, as we are
> deploying an agent for .ch/.li. I have a few questions about the current
> implementation in BIND 9.21. From reading the documentation and code, my
> understanding is that some parts are currently not configurable or not
> implemented, but I'd like to confirm this before pestering anyone with
> feature requests.
You are right that these points are not implemented in BIND 9 currently.
I actually have made work items for the four feature requests. See
below. We will work on them on a best effort basis. Feel free to respond
on them.
> Is it possible to manually configure a notification endpoint for a zone,
> to test the implementation while the parent does not yet publish DSYNC
> records?
https://gitlab.isc.org/isc-projects/bind9/-/work_items/6419
> As far as I understand, BIND sends the notification immediately after
> the CDS/CDNSKEY RRset changes and ignores `notify-defer`. This seems
> potentially problematic if the notification recipient immediately
> retrieves CDS/CDNSKEY from the authoritative servers: the updated RRset
> may not yet have propagated to all secondaries. Is there currently any
> way to configure such a delay for NOTIFY(CDS), e.g. by using `zone-
> propagation-delay` or another setting?
https://gitlab.isc.org/isc-projects/bind9/-/work_items/6420
> Does BIND send only one notification after the CDS/CDNSKEY RRset
> changes, or does/could it generate another notification at a later
> point, e.g. when checking the parent DS RRset? I'm asking because
> receiving a notification does not necessarily mean that the parent can
> immediately process the requested change. For example, the parental
> agent may temporarily be unable to act because of rate limiting, or
> because it has cached state for the domain which currently prevents
> another modification and may need another nudge later on.
https://gitlab.isc.org/isc-projects/bind9/-/work_items/6421
> RFC 9859 allows the NOTIFY sender to include the EDNS Report-Channel
> option so that the notification agent can report processing problems
> asynchronously. Is there a way to configure the Report-Channel for these
> CDS NOTIFY packets? From the documentation I gather that `send-report-
> channel` only applies to authoritative DNS responses.
https://gitlab.isc.org/isc-projects/bind9/-/work_items/6422
Best regards,
Matthijs
More information about the bind-users
mailing list