nanog mailing list archives

Re: Re: Advisory — D-root is changing its IPv4 address


From: Christopher Morrow <morrowc.lists () gmail com>
Date: Fri, 14 Dec 2012 13:23:41 -0500

<hand wavey>dnssec</hand wavey>
On Dec 14, 2012 1:06 PM, "Joe Greco" <jgreco () ns sol net> wrote:

So really stupid question, and hopefully it's just me, do I need to do
something
on my servers?

your crontab that updates your root-hints may already have caught the
chang=
e...

That seems like a spectacularly bad idea.  How do you validate the new
root-hints automatically?  What if someone manages to send you something
malicious in place of the correct one?

... JG
--
Joe Greco - sol.net Network Services - Milwaukee, WI - http://www.sol.net
"We call it the 'one bite at the apple' rule. Give me one chance [and]
then I
won't contact you again." - Direct Marketing Ass'n position on e-mail
spam(CNN)
With 24 million small businesses in the US alone, that's way too many
apples.



Current thread: