OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: dnscache
From: Bennett Todd (betrahul.net)
Date: Wed Jun 14 2000 - 11:45:47 CDT


2000-06-14-11:54:06 Brad Knowles:
> At 2:35 PM -0400 2000/6/13, Bennett Todd wrote:
> > Tinydns only serves UDP, since that's all that's needed
> > to return authoritative data to currently-used recursive
> > resolvers.
>
> Not true. Take any of the previously mentioned examples of
> exceeding the 512 byte limit of UDP, and note that all UDP queries
> that result in truncation must be retried with TCP.

Yup. So if you're absolutely and totally committed to serving up
authoritative answers exceeding 512 bytes, and don't give a damn
about who all that breaks (lots of people filter tcp/53 since it's
never needed to reach well-run sites, only sites administered by
people who like to play stupid games with their DNS) then by all
means run an axfrdns daemon off your tinydns-data file to serve the
data via TCP. It's supported, it works, that does not make it a good
idea.

> If it doesn't serve both TCP and UDP, then it doesn't serve
> the DNS properly -- period.

It can be configured to serve both TCP and UDP, if you're determined
to make it necessary. Most folks aren't; for them, tinydns works
just fine UDP-only.

-Bennett


  • application/pgp-signature attachment: stored