nanog mailing list archives
Re: IPv6 Pain Experiment
From: Mark Andrews <marka () isc org>
Date: Thu, 3 Oct 2019 13:37:57 +1000
Actually you can do exactly the same thing for glue. KEY records below bottom of zone cut exactly the same way as you have A and AAAA below bottom of zone cut. The only difference is the zone listed in the UPDATE message. zone example.com { ... update-policy { // allow a TSIG or SIG(0) update signed with administrator.example.com to change anything in the zone grant adminstrator.example.com. zonesub ANY; // allow a TSIG or SIG(0) update signed with name X to update anything at X grant * self * ANY; }; }; Now is that a “complicated” policy? Coming soon “grant * tcp-self . PTR(1);” allow a TCP UPDATE to install a single PTR record at the matching reverse name of the TCP source address. https://gitlab.isc.org/isc-projects/bind9/merge_requests/2124
On 3 Oct 2019, at 12:30 pm, Masataka Ohta <mohta () necom830 hpcl titech ac jp> wrote: Mark Andrews wrote:There is also nothing stopping machines updating their addresses in the DNS dynamically securely.Except that glue A/AAAA can not be updated so easily and security configuration is even more painful than address configuration. Masataka Ohta
-- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: marka () isc org
Current thread:
- Re: IPv6 Pain Experiment, (continued)
- Re: IPv6 Pain Experiment Denis Fondras (Oct 07)
- Re: IPv6 Pain Experiment Owen DeLong (Oct 07)
- Re: IPv6 Pain Experiment Karl Auer (Oct 07)
- RE: IPv6 Pain Experiment Michel Py (Oct 07)
- Re: IPv6 Pain Experiment Owen DeLong (Oct 07)
- RE: IPv6 Pain Experiment Michel Py (Oct 08)
- Re: IPv6 Pain Experiment Owen DeLong (Oct 08)
- RE: IPv6 Pain Experiment bzs (Oct 08)
- Re: IPv6 Pain Experiment Mark Andrews (Oct 02)
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 02)
- Re: IPv6 Pain Experiment Mark Andrews (Oct 02)
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 02)
- Message not available
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 03)
- Message not available
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 03)
- Re: IPv6 Pain Experiment Doug Barton (Oct 03)
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 03)
- Re: IPv6 Pain Experiment John Levine (Oct 03)
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 03)
- Re: IPv6 Pain Experiment Mark Andrews (Oct 03)
- Re: IPv6 Pain Experiment Masataka Ohta (Oct 03)
- Re: IPv6 Pain Experiment Doug Barton (Oct 03)