DNS Root Name Servers Frequently Asked Questions ISOC MEMBER BRIEFING #20
Total Page:16
File Type:pdf, Size:1020Kb
DNS Root Name Servers Frequently Asked Questions ISOC MEMBER BRIEFING #20 http://www.isoc.org/briefings/020/ January, 2005 by Daniel Karrenberg DNS Root Name Server FAQ Version 1 - January 27th This is Daniel Karrenberg's personal FAQ about the root name 2005 server system. It is based on questions he had to answer over the past few years of "Internet Governance" debate. Expanded Coverage from ISOC Daniel brought the second DNS root name server, k.root- servers.net, to Europe in 1997 and he has been responsible for its A concise summary of the operation in the first years. Today he advises the operations team. material covered in this Daniel has also helped to build significant parts of the European FAQ is available in ISOC Internet in the 1980s; this included helping with the establishment member briefing #19. of many ccTLDs in the area. In the 1990s Daniel led the In-depth articles, papers, establishment of the RIPE NCC, the first of the regional Internet links and other resources registries. During this time Daniel helped to create the policy on a variety of topics are development process for Internet number resources in the RIPE available from the ISOC region and as CEO of the RIPE NCC he has been responsible for the site at: implementation of those policies. Through this effort he has become www.isoc.org/internet/ a practitioner at what others often refer to as "Internet issues governance". He prefers to be an engineer and pragmatist rather Acknowledgments than fully engaging in the process of public policy making. However, he strongly believes that policy making should be based on as much I thank all root name relevant information as humanly possible. Hence this FAQ. server operators for providing the quantitative Q: What is it that root name servers do exactly? information contained this FAQ. The following A: They are part of the Domain Name System (DNS), a worldwide individuals have provided distributed database that is used to translate worldwide unique substantive and useful domain names such as www.isoc.org to other identifiers. The DNS comments which have is an important part of the Internet because it is used by almost all improved the answers I Internet applications. give: Brian Carpenter, Steve Crocker, James The root name servers publish the root zone file to other DNS Galvin, Patrik Faltstrom, servers and clients on the Internet. The root zone file describes Thomas de Haan, Johan where the authoritative servers for the DNS top-level domains Ihren and Mirjam Kuehne. (TLD) are located; in other words: which server one has to ask for However these answers names ending in one of 258 (December 2004) TLDs, such as ORG, as well as any errors and NET, NL or AU. For a detailed description of how the DNS works omissions remain my and the role of the root name servers see: personal responsibility. I http://www.isoc.org/briefings/016/index.shtml also thank the RIPE NCC for providing the resources for the work on documents like this. Q: So the root name server operators determine who gets to About the Author operate TLDs? Daniel Karrenberg A: No, absolutely and positively not! The root zone file is just currently serves the RIPE published by the root name server operators. The file is edited by NCC as Chief Scientist. the IANA according to a process described on the IANA web site. His interests include The root name server operators publish the file as received from Internet measurements, the IANA. See: http://www.iana.org/root-management.htm the development of the DNS and the evolution of what others often call Q: Does all Internet traffic pass through the root name "Internet Governance". servers? A: No Internet traffic passes through the root name servers at all. They have nothing to do with routing, note the difference in Daniel is spelling. Name servers just answer queries from other parts of the one of DNS. the founders Q: Do the root name servers store all information in the of RIPE DNS? In the 1990s Daniel led the A: No, DNS is a distributed database. Storing all the information in establishment of the RIPE one place would be totally infeasible today. This is exactly why the NCC, the first of the DNS was developed as a distributed database. For a detailed Regional Internet description of how the DNS works and the role of the root name Registries. He has helped servers see: http://www.isoc.org/briefings/016/index.shtml to shape Internet address space distribution policy, Q: Are the root name servers queried every time I browse transferring both policy the web or send mail? development and implementation to the A: No, information is cached in the DNS. Your computer will query a region. caching DNS server to resolve domain names. A well behaved DNS server needs to query the root name servers only once every 48 Daniel helped to design hours for each particular TLD. In the meantime it can resolve NSD, designed and names for that TLD without involvement of the root name servers. implemented dnsmon and Because of this caching almost all DNS queries are answered deployed the initial K-root without involvement of the root name servers. server. In the 1980s Daniel For a detailed description of how the DNS works and the role of the helped to build EUnet and root name servers see: led the effort to transition http://www.isoc.org/briefings/016/index.shtml it to Internet protocols, making EUnet the first Q: Who are the root name server operators? pan-European ISP and bringing Internet A: There currently are 12 organisations providing root name service connections to many at 13 unique IPv4 addresses. They are: places in and around Europe. A - VeriSign Global Registry Services B - University of Southern California - Information Sciences Acknowledgments Institute C - Cogent Communications The ISOC Member D - University of Maryland Briefing series is made E - NASA Ames Research Center possible through the F - Internet Systems Consortium, Inc. generous assistance of G - U.S. DOD Network Information Center ISOC’s H - U.S. Army Research Lab I - Autonomica/NORDUnet Platinum Program J - VeriSign Global Registry Services Sponsors: Afilias, APNIC, K - RIPE NCC ARIN, Microsoft, and Ripe L - ICANN NCC, Sida. More M - WIDE Project information on the Platinum Sponsorship Information about most operators can be found via Program: http://www.root-servers.org/, or specifically via http://X.root- http://www.isoc.org/isoc/ servers.org/ where X stands for one of the letters listed above. membership/platinum.sht ml Q: What is the meaning of the letters A-M? About the Background A: In the past each letter identified a particular server machine. Paper Series Currently each letter identifies a single IPv4 address at which the service is provided under the responsibility of a single root name Published by: server operator. Some operators still provide the service from one The Internet Society location with one or more physical machines. Other operators 1775 Wiehle Avenue, provide the service from multiple locations using a method called Suite 102 "anycast". See below for an explanation. Reston, Virginia 20190 USA Q: So where are those root name servers anyway? Tel: +1 703 326 9880 Fax: +1 703 326 9881 A: Where in what sense? In the geographical sense there are root name servers in more than 80 locations within 34 countries 4, rue des Falaises (ISO3166 definition of country) worldwide (December 2004). Before CH-1205 Geneva you ask: the majority of them are outside the United States of Switzerland America. In terms of Internet topology the servers tend to be either Tel: +41 22 807 1444 in very well connected places so that they can serve a maximum Fax: +41 22 807 1445 number of clients; others are in relatively isolated places to provide reliable service to the local community while reducing non-local Email: [email protected] DNS traffic. The exact locations of many servers are often not Web: published for fear of physical attacks. http://www.isoc.org/ Series Editor: Martin Q: So you mean that no one knows where all of them exactly Kupres are? Copyright © Internet A: Yes, does any one person need to know that? I certainly do not Society 2005. All rights want to know! reserved. Q: So do you speak for all letters? A: No! No one can do that. See further down for an explanation why this is. I speak here on personal title. I would not say things that would cause the other root name server operators to stop talking to me; I actually like the folks I work with. ;-) I try my best to keep the answers restricted to factual information; but of course they reflect who I am and where I come from. I am always open to suggestions on how to better answer these questions and for new questions, of course. Q: So the root name server operators are all volunteers? A: In the distant past, more than 10 years ago, root name server operators could be described like that. Today no root name server operator is a volunteer in any sense of the word. None of them is an individual anymore. All of them are organisations that acknowledge the obligation to provide this service. Root name server operation has not depended on single individuals for a long time. See below for answers regarding the motivation of root name server operators to provide good service. Q: Who selects the root name server operators? A: All root name server operators have been selected by the IANA.