[63382] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Will reverting DNS wildcard have any adverse affects?

daemon@ATHENA.MIT.EDU (bmanning@karoshi.com)
Fri Oct 3 20:35:15 2003

From: bmanning@karoshi.com
To: gcoon@inch.com (Gerald)
Date: Fri, 3 Oct 2003 17:34:07 -0700 (PDT)
Cc: web@typo.org (Wayne E. Bouchard), nanog@nanog.org
In-Reply-To: <20031003193015.B54929@kod.inch.com> from "Gerald" at Oct 03, 2003 07:36:44 PM
Errors-To: owner-nanog-outgoing@merit.edu


> I have confidence in the bind patch not breaking bind when Verisign
> reverts back, but there were some pretty rash suggestions when the
> sitefinder service first came online. (Paul, bind won't break when this
> goes back to normal will it?)

	ask yourself how many DNS admins are going to go pull out
	the "-delegation" stanzas from their configs?  Or that
	will use them to lie about other delegations that use wildcards
	as long as that code is still available?  ...  

	someone should write up a FAQ now, describing how to troubleshoot
	DNS anomolies that will arise as a result of this code being in
	the wild. IMHO, its going to be a -long- time before this "feature"
	is eradicated from the deployed base.  :(

> Gerald Coon

--bill

home help back first fref pref prev next nref lref last post