DNS root servers to support IPv6

Many TLDs already have IPv6 DNS servers, even Belgium has one (brussels.ns.dns.be). Several of the root servers already have IPv6 addresses as well but until now, the root hints file and priming responses served by the root servers only contained the IPv4 records. This will change on Februari 4th when AAAA records are added for 4 of the root servers.

For most people this change will go unnoticed. There is a report that lists the possible issues. The most likely problem is that with the addition of the IPv6 records, the DNS response will be larger than the 512 bytes originally allowed by DNS.

Problems are only to be expected for people running ancient software versions on their DNS resolvers or firewalls (eg old PIX versions). If in doubt, the ICANN website has a list of firewalls that have been tested. That page also has instructions on how to test your firewall. Note that they are testing the hk servers which no longer seem to return such long responses, so you'll need to find another server that does. I used one of the root servers from the Open Root Server Network for testing.

filed under