OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Bennett Todd (bet_at_rahul.net)
Date: Mon Feb 03 2003 - 13:33:17 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    2003-02-03T14:26:48 Greg Hackney:
    > >....if someone has DNS sufficiently
    > > ...poorly configured that many or most initial queries timeout....
    > > ...why should you worry on their behalf?
    > > -Bennett
    >
    > Because the most problematic case is skytel.com (Skytel emergency
    > paging via email)

    Ahh, thanks for the additional info.

    If I owned your problem myself, here's what _I_ would do about it.

    I'd identify this domain that's critical to my operations, and whose
    DNS is marginal, and would set up a script that (a) automatically
    checks say once/hour to make sure the data hasn't changed, and if so
    kicks off a rebuild of the (b) private mirror I kept, served by a
    little localhost-bound tinydns instance, that's offering
    authoritative MX and corresponding A data for skytel.com, which is
    in turn (c) used by the dnscache instance local to the mail server
    for its lookups. djbdns (like recent versions of bind) allows a
    caching nameserver to be configured to divert queries for certain
    domains to specific servers, overriding the normal
    delegation-from-root path.

    -Bennett

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.7 (GNU/Linux)

    iD8DBQE+PsP8HZWg9mCTffwRAu9TAJ4kiJR8V6WE5SCWJAx5xXwC4hQuRwCgqRpi
    VfwmVKfidOxYwh2OrvBP2cQ=
    =IjFu
    -----END PGP SIGNATURE-----