<?xml version="1.0"?>
<?rfc compact="yes" ?>
<?rfc symrefs="yes" ?>
<?rfc sortrefs="yes" ?>
<?rfc toc="yes" ?>
<!DOCTYPE rfc SYSTEM "rfc2629.dtd" [
<!ENTITY rfc1918 PUBLIC '' 'http://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.1918.xml'>
<!ENTITY rfc6303 PUBLIC '' 'http://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6303.xml'>
<!ENTITY rfc6598 PUBLIC '' 'http://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6598.xml'>
]>
<rfc ipr="trust200902" docName="draft-ietf-dnsop-rfc6598-rfc6303-03">
  <front>
    <title abbrev="IPv4 Locally-Served DNS Zones Additions">Add 100.64.0.0/10 prefixes to IPv4 Locally-Served DNS Zones Registry.</title>
    <author initials="M." surname="Andrews" fullname="M. Andrews">
      <organization abbrev="ISC">Internet Systems Consortium</organization>
      <address>
        <postal>
          <street>950 Charter Street</street>
          <city>Redwood City</city>
          <region>CA</region>
          <code>94063</code>
          <country>US</country>
        </postal>
        <email>marka@isc.org</email>
      </address>
    </author>
    <date month="April" year="2015"/>
    <abstract>
      <t>
	RFC6598 specified that: "Reverse DNS queries for Shared Address
	Space addresses [100.64.0.0/10] MUST NOT be forwarded to the
	global DNS infrastructure."
      </t>
      <t>
	This document formally directs IANA to add the associated zones
	to the "IPv4 Locally-Served DNS Zones Registry" to prevent such
	queries accidently leaking to the global DNS infrastructure.
      </t>
    </abstract>
  </front>
  <middle>
    <section toc="yes" anchor="intro" title="Introduction">
      <t>
	<xref target="RFC6598"/> specified that: "Reverse DNS queries
	for Shared Address Space addresses [100.64.0.0/10] MUST NOT
	be forwarded to the global DNS infrastructure." <xref
	target="RFC6303"/> provides guidance on handling such
	queries.
      </t>
      <t>
	This document directs the IANA to add the IPv4 reverse zones
	corresponding to 100.64.0.0/10, a netblock reserved in <xref
	target="RFC6598"/>, to the IPv4 Locally-Served DNS Zone
	Registry established in <xref target="RFC6303"/>.
      </t>
      <t>
	Unlike <xref target="RFC1918"/> address, which are not
	expected to be seen by other parties, the addresses from
	<xref target="RFC6598"/> are expected to be seen by parties
	other than those deploying the addresses, so it is more
	crucial that recursive nameservers default to serving these
	zones locally.
      </t>
    </section>
    <section toc="yes" anchor="changes" title="Changes to IPv4 Locally-Served DNS Zones Registry">
      <t>
	To add the following zone listed in
	<xref target="rfc6598zones">RFC6598 Zones</xref> to the
	"IPv4 Locally-Served DNS Zone Registry".
      </t>
      <section toc="yes" anchor="rfc6598zones" title="RFC6598 Zones">
        <t>
	  <list>
	    <t>64.100.IN-ADDR.ARPA</t>
	    <t>65.100.IN-ADDR.ARPA</t>
	    <t>66.100.IN-ADDR.ARPA</t>
	    <t>67.100.IN-ADDR.ARPA</t>
	    <t>68.100.IN-ADDR.ARPA</t>
	    <t>69.100.IN-ADDR.ARPA</t>
	    <t>70.100.IN-ADDR.ARPA</t>
	    <t>71.100.IN-ADDR.ARPA</t>
	    <t>72.100.IN-ADDR.ARPA</t>
	    <t>73.100.IN-ADDR.ARPA</t>
	    <t>74.100.IN-ADDR.ARPA</t>
	    <t>75.100.IN-ADDR.ARPA</t>
	    <t>76.100.IN-ADDR.ARPA</t>
	    <t>77.100.IN-ADDR.ARPA</t>
	    <t>78.100.IN-ADDR.ARPA</t>
	    <t>79.100.IN-ADDR.ARPA</t>
	    <t>80.100.IN-ADDR.ARPA</t>
	    <t>81.100.IN-ADDR.ARPA</t>
	    <t>82.100.IN-ADDR.ARPA</t>
	    <t>83.100.IN-ADDR.ARPA</t>
	    <t>84.100.IN-ADDR.ARPA</t>
	    <t>85.100.IN-ADDR.ARPA</t>
	    <t>86.100.IN-ADDR.ARPA</t>
	    <t>87.100.IN-ADDR.ARPA</t>
	    <t>88.100.IN-ADDR.ARPA</t>
	    <t>89.100.IN-ADDR.ARPA</t>
	    <t>90.100.IN-ADDR.ARPA</t>
	    <t>91.100.IN-ADDR.ARPA</t>
	    <t>92.100.IN-ADDR.ARPA</t>
	    <t>93.100.IN-ADDR.ARPA</t>
	    <t>94.100.IN-ADDR.ARPA</t>
	    <t>95.100.IN-ADDR.ARPA</t>
	    <t>96.100.IN-ADDR.ARPA</t>
	    <t>97.100.IN-ADDR.ARPA</t>
	    <t>98.100.IN-ADDR.ARPA</t>
	    <t>99.100.IN-ADDR.ARPA</t>
	    <t>100.100.IN-ADDR.ARPA</t>
	    <t>101.100.IN-ADDR.ARPA</t>
	    <t>102.100.IN-ADDR.ARPA</t>
	    <t>103.100.IN-ADDR.ARPA</t>
	    <t>104.100.IN-ADDR.ARPA</t>
	    <t>105.100.IN-ADDR.ARPA</t>
	    <t>106.100.IN-ADDR.ARPA</t>
	    <t>107.100.IN-ADDR.ARPA</t>
	    <t>108.100.IN-ADDR.ARPA</t>
	    <t>109.100.IN-ADDR.ARPA</t>
	    <t>110.100.IN-ADDR.ARPA</t>
	    <t>111.100.IN-ADDR.ARPA</t>
	    <t>112.100.IN-ADDR.ARPA</t>
	    <t>113.100.IN-ADDR.ARPA</t>
	    <t>114.100.IN-ADDR.ARPA</t>
	    <t>115.100.IN-ADDR.ARPA</t>
	    <t>116.100.IN-ADDR.ARPA</t>
	    <t>117.100.IN-ADDR.ARPA</t>
	    <t>118.100.IN-ADDR.ARPA</t>
	    <t>119.100.IN-ADDR.ARPA</t>
	    <t>120.100.IN-ADDR.ARPA</t>
	    <t>121.100.IN-ADDR.ARPA</t>
	    <t>122.100.IN-ADDR.ARPA</t>
	    <t>123.100.IN-ADDR.ARPA</t>
	    <t>124.100.IN-ADDR.ARPA</t>
	    <t>125.100.IN-ADDR.ARPA</t>
	    <t>126.100.IN-ADDR.ARPA</t>
	    <t>127.100.IN-ADDR.ARPA</t>
          </list>
        </t>
      </section>
    </section>
    <section toc="yes" anchor="iana" title="IANA Considerations">
      <t>
	This document directs IANA to add the zones listed in <xref
	target="rfc6598zones">RFC6598 Zones</xref> to the
	"IPv4 Locally-Served DNS Zone Registry".
      </t>
      <t>
	IANA is reminded that an insecure delegation for these zones
	is required for compliance with <xref target="RFC6598"/> to
	break the DNSSEC chain of trust.
      </t>
    </section>
    <section toc="yes" anchor="security" title="Security Considerations">
      <t>
	This document is thought to present no additional security
	risks to the Internet.
      </t>
    </section>
    <section toc="yes" anchor="acknowledgements" title="Acknowledgements">
      <t>
	I would like to thank Joe Abley for his review comments.
      </t>
    </section>
  </middle>
  <back>
    <references title="Normative References">
      &rfc1918;
      &rfc6303;
      &rfc6598;
    </references>
  </back>
</rfc>
