Reviewer: Linda Dunbar Review result: Ready with questions I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. The Abstract of This document claims that this document shows how to start and maintain a copy of the root zone in the Recursive Resolvers so that the Resolvers don't need to send query to another node. Two questions: - What if the node is not authorized to have the entire records? It would desirable for the Resolvers to have all the records of the root zone. Is there any scenario that the Resolvers simply cannot get all the records of the root zone? - How to detect if any records stored in the Resolver are STALE? Page 3, last sentence of the 3rd paragraph: is it a typo? or miss a verb? "... it would all responses from a remote root server" Cheers, Linda Dunbar