OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
OT Re: *.com and *.net? Yay Postfix!

From: John Peach (postfixjohnpeach.com)
Date: Wed Sep 17 2003 - 13:22:47 CDT


> # postfixjohnpeach.com / 2003-09-17 08:33:08 -0400:
> > > I'll probably keep running my filter for the next week or so until I have
> > > time to evaluate the patches for djbdns.
> > >
> > It's working fine for me :)
> >
> > the only problem is I don't have dnscache setup at home :( Historically
> > I have myself as authoritative for advertising sites such as
> > doubleclick and djb doesn't believe you should have an authoritative
> > server and a caching server on the same address.....
>
> what stops you from running tinydns somewhere in 127/8? or do you
> run an operating system that can't assign more than one IP to an
> interface?
>
I'm very wary of tinydns anyway. By "design" it doesn't answer TCP queries, which, of course, breaks recent billyshit impementations which only speak TCP. It does not appear to be well documented how tinydns for an *internal* only nameserver can interact with dnscache for the rest of it. Obviously I cannot tell the root nameservers that I am authoritative for doubleclick.net et al and I use this nameserver for my home network.

BIND has been doing a perfectly acceptable job for me and with the patched version(s) released this morning, I prefer the way that the ISC have solved the problem to the patch for dnscache which relies on hardwiring the IP addresses returned.