John C Klensin klensin at
Thu Jan 17 15:54:30 CET 2008

--On Wednesday, 16 January, 2008 18:15 -0800 Mark Davis
<mark.davis at> wrote:

> These steps look reasonable.  One additional possibility is
> that we could place a restriction on the entire host name;
> that is, if there are any BIDI characters in the host name,
> then certain restrictions could apply to even all ASCII
> labels. I mention that as a possibility; Harald can say if
> that is realistic or not.

This rapidly gets tied up with an issue we describe as the
"distributed administrative hierarchy" of the DNS.  There is
also a potential nightmare based on the way that DNAME records
work and the observation that the zone that contains a DNAME
record does not need the permission of the zone to which it
points.  The short answer is that it is not realistic, in the
general case, to impose restrictions on one label based on the
contents of another.


