<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>

<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-iab-arpa-authoritative-servers-01" number="9120" updates="3172" obsoletes="" submissionType="IAB" category="info" consensus="true" xml:lang="en" tocInclude="true" tocDepth="4" sortRefs="true" symRefs="true" version="3">

  <front>
    <title abbrev="Nameservers for the .arpa Domain">Nameservers for the Address and Routing Parameter Area ("arpa") Domain</title>
    <seriesInfo name="RFC" value="9120"/>
    <author initials="K." surname="Davies" fullname="Kim Davies">
<organization showOnFrontPage="false">Internet Assigned Numbers Authority</organization>
      <address>
        <postal>
          <street>PTI/ICANN</street>
          <street>12025 Waterfront Drive</street>
          <city>Los Angeles</city>
	  <region>CA</region>
          <code>90094</code>
          <country>United States of America</country>
        </postal>
        <email>kim.davies@iana.org</email>
      </address>
    </author>
    <author initials="J." surname="Arkko" fullname="Jari Arkko">
<organization showOnFrontPage="false">Ericsson Research</organization>
      <address>
        <postal>
          <street>02700 Kauniainen</street>
          <country>Finland</country>
        </postal>
        <email>jari.arkko@ericsson.com</email>
      </address>
    </author>
<date year="2021" month="October"/>

<keyword>root zone</keyword>
<keyword>IANA</keyword>
<keyword>top-level domain</keyword>
<keyword>root nameservers</keyword>
<keyword>DNS</keyword>
<keyword>ARPA</keyword>

    <abstract>
      <t>This document describes revisions to operational practices to separate the function of the "arpa" top-level domain in the DNS from its historical
operation alongside the DNS root zone.</t>
    </abstract>
  </front>
  <middle>
    <section anchor="introduction" numbered="true" toc="default">
      <name>Introduction</name>
      <t>The "arpa" top-level domain <xref target="RFC3172" format="default"/> is designated as an
"infrastructure domain" to support techniques defined by Internet
standards. Zones under the "arpa" domain provide various mappings, such
as IP addresses to domain names and E.164 numbers to URIs. It also
contains special-use names such as "home", which is a nonunique name
      used in residential networks.</t>

      <t>Historically, the "arpa" zone has been hosted on almost all of the
root nameservers (NSs), and <xref target="RFC3172" format="default"/> envisages the "arpa" domain to be
"sufficiently critical that the operational requirements for the root
servers apply to the operational requirements of the "arpa" servers". To
date, this has been implemented by serving the "arpa" domain directly on
a subset of the root server infrastructure.</t>
      <t>This bundling of root nameserver and "arpa" nameserver operations has entwined
management of the zones' contents and their infrastructures. As a result,
some proposals under consideration by the IETF involving the "arpa" zone
have been discarded due to the risk of conflict with operations associated
with managing the content of the root zone or administering the root
nameservers.</t>
      <t>The separation described in this document resolves the operational impacts
of synchronizing edits to the root zone and the "arpa" zone by
eliminating the current dependency and allowing more tailored operations
based on the unique requirements of each zone.</t>
    </section>
    <section anchor="requirements-for-the-arpa-zone" numbered="true" toc="default">
      <name>Requirements for the "arpa" Zone</name>
      <t>The "arpa" domain continues to play a role in critical Internet
operations, and this change does not propose weakening operational
requirements described in <xref target="RFC3172" format="default"/> for the domain. Future operational
requirements for the "arpa" domain are encouraged to follow strong
baseline requirements such as those documented in <xref target="RFC7720" format="default"/>.</t>
      <t>Changes to the administration of the "arpa" zone do not alter the
management practices of other zones delegated within the "arpa"
namespace. For example, "ip6.arpa" would continue to be managed in
accordance with <xref target="RFC5855" format="default"/>.</t>
    </section>
    <section anchor="transition-process" numbered="true" toc="default">
      <name>Transition Process</name>
      <t>The process will dedicate new hostnames to the servers that are authoritative for
the "arpa" zone, but it will initially serve the "arpa" zone from the same
hosts.</t>
      <t>Once completed, subsequent transitional phases could include using
new hosts to replace or augment the existing root nameserver hosts and
separating the editing and distribution of the "arpa" zone from
necessarily being connected to the root zone. Any future management
considerations regarding how such changes may be performed are beyond
the scope of this document.</t>
      <section anchor="dedicated-nameserver-hostnames" numbered="true" toc="default">
        <name>Dedicated Nameserver Hostnames</name>
        <t>Consistent with the use of the "arpa" namespace itself to host nameservers for other delegations in the "arpa" zone <xref target="RFC5855" format="default"/>, this
document specifies a new namespace of "ns.arpa", with the
nameserver set for the "arpa" zone to be initially labeled as follows:</t>
        <artwork name="" type="" align="left" alt=""><![CDATA[
   a.ns.arpa
   b.ns.arpa
   c.ns.arpa
   ...
]]></artwork>
        <t>Dedicated hostnames eliminate a logical dependency that requires the
coordinated editing of the nameservers for the "arpa" zone and the root
zone. This component of this transition does not require that the underlying
hosts that provide "arpa" name service (that is, the root nameservers) be
altered. The "arpa" zone will initially map the new hostnames to the
same IP addresses that already provide service under the respective
hostnames within "root-servers.net".</t>
        <t>Because these nameservers are completely within the "arpa" zone, they
will require glue records in the root zone. This is consistent with
current practice and requires no operational changes to the root zone.</t>
      </section>
      <section anchor="separation-of-infrastructure" numbered="true" toc="default">
        <name>Separation of Infrastructure</name>
        <t>After initially migrating the "arpa" zone to use hostnames that are not shared
with the root zone, the underlying name service is expected to evolve such that
it no longer directly aligns with a subset of root nameserver instances. With no
shared infrastructure between the root nameservers and the "arpa" nameservers, future
novel applications for the "arpa" zone may be possible.</t>
        <t>Any subsequent change to the parties providing name service for the
zone is considered a normal management responsibility and would be
performed in accordance with <xref target="RFC3172" format="default"/>.</t>
      </section>
      <section anchor="zone-administration" numbered="true" toc="default">
        <name>Zone Administration</name>
        <t>Publication of the "arpa" zone file to the authoritative "arpa" nameservers is currently undertaken alongside the root zone maintenance functions.
Upon the separation of the "arpa" infrastructure from the root nameserver
infrastructure, publication of the "arpa" zone no longer necessarily needs
to be technically linked or interrelated to the root zone publication
mechanisms.</t>
      </section>
      <section anchor="conclusion-of-process" numbered="true" toc="default">
        <name>Conclusion of Process</name>
        <t>Full technical separation of operations of the "arpa" zone and root zone 
minimally requires the following to be satisfied:</t>
        <ul spacing="normal">
          <li>The "arpa" zone no longer shares any hostnames in its nameserver set with the root
zone.</li>
          <li>The hosts that provide authoritative name service are not the same hosts
as the root nameservers, do not share any IPv4 or IPv6 addresses with the
root servers, and are sufficiently provisioned separately such
that any unique "arpa" zone requirements can be deployed without affecting
how root zone service is provided.</li>
<li>The editorial and publication process for the "arpa" zone removes any common dependencies with the root zone process so that the "arpa" zone 
can be managed, edited, and provisioned wholly independently of the
root zone.</li>
        </ul>
        <t>Such separation is ultimately sought to allow for novel uses of
the "arpa" zone without the risk of inadvertently impacting root zone and root
server operations. It is recognized that achieving this state requires a
deliberative process involving significant coordination to ensure impacts
are minimized.</t>
      </section>
    </section>
    <section anchor="iana-considerations" numbered="true" toc="default">
      <name>IANA Considerations</name>
      
      <t>IANA shall coordinate the creation of the "ns.arpa" namespace and
populate it with address records that reflect the IP addresses of the
contemporary root servers documented within "root-servers.net" as its
initial state. The namespace may be provisioned either directly within
the "arpa" zone (as an empty nonterminal) or through establishing
a dedicated "ns.arpa" zone, according to operational requirements.</t>
      <t>IANA will initially migrate the 12 NS records for the "arpa" zone
      to point to their respective new entries in the "ns.arpa" domain.</t>
<t>When these actions are complete, the IAB and IANA will consult
and coordinate with all relevant parties on activity to reduce
or eliminate reliance upon the root zone and root server
 infrastructure serving the "arpa" zone. Such
changes will be performed in compliance with <xref target="RFC3172" format="default"/> and shall be
conducted with all due care and deliberation to mitigate potential
impacts on critical infrastructure.</t>
    </section>
    <section anchor="security-considerations" numbered="true" toc="default">
      <name>Security Considerations</name>
      <t>The security of the "arpa" zone is not necessarily impacted by any
aspects of these changes. Robust practices associated with administering
the content of the zone (including signing the zone with DNSSEC) as well
      as its distribution will continue to be necessary.</t>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>
        <xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.3172.xml"/>
      </references>
      <references>
        <name>Informative References</name>
        <xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.5855.xml"/>
        <xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7720.xml"/>
      </references>
    </references>
    <section numbered="false" anchor="members" toc="default">
      <name>IAB Members at the Time of Approval</name>
<t>Internet Architecture Board members at the time this document was
approved for publication were:</t>
<ul empty="true" indent="3" spacing="compact">
<li><t><contact fullname="Jari Arkko"/></t></li>
<li><t><contact fullname="Deborah Brungard"/></t></li>
<li><t><contact fullname="Ben Campbell"/></t></li>
<li><t><contact fullname="Lars Eggert"/></t></li>
<li><t><contact fullname="Wes Hardaker"/></t></li>
<li><t><contact fullname="Cullen Jennings"/></t></li>
<li><t><contact fullname="Mirja Kühlewind"/></t></li>
<li><t><contact fullname="Zhenbin Li"/></t></li>
<li><t><contact fullname="Jared Mauch"/></t></li>
<li><t><contact fullname="Tommy Pauly"/></t></li>
<li><t><contact fullname="David Schinazi"/></t></li>
<li><t><contact fullname="Russ White"/></t></li>
<li><t><contact fullname="Jiankang Yao"/></t></li>
</ul>
    </section>
<section numbered="false" anchor="acknowledgments" toc="default">
      
      <name>Acknowledgments</name>
      <t>Thank you <contact fullname="Alissa Cooper"/>, <contact fullname="Michelle Cotton"/>, <contact fullname="Lars-Johan Liman"/>, <contact fullname="Wes Hardaker"/>,
<contact fullname="Ted Hardie"/>, <contact fullname="Paul Hoffman"/>, <contact fullname="Russ Housley"/>, <contact fullname="Oscar Robles-Garay"/>, <contact fullname="Duane Wessels"/>, and <contact fullname="Suzanne Woolf"/> for providing review and feedback.</t>
    </section>
  </back>
</rfc>
