Re: Extending UPDATE to add/remove zones
Derek Atkins <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Hi, Jay Daley <[email protected]> writes: >>From my previous post on my draft for a new DNS opcode - servezones - > I think there is reasonable interest in an in-band mechanism that > instructs a nameserver to etiher start or stop serving one or more > zones. The area with less certainty is what that mechanism should be, > a new Opcode (but it's only a 4 bit space!) or extending UPDATE. > > I'm planing to write a draft that shows how UPDATE could be extended > to do this and then we can compare that with my servezones draft and > see which is preferred. To do that I'd like some help in determining > the algorithm for how the extended UPDATE is processed. [snip] I admit I haven't read the whole draft, but my question is how do you authenticate and, more importantly, authorize the addition or (worse) deletion of zones? Imagine an attack vector where someone could get your domain's DNS servers to stop serving your domain(s)! I think the security of adding and (more importantly) removing zones should be carefully documented and discussed. > Jay -derek -- Derek Atkins 617-623-3745 [email protected] www.ihtfp.com Computer and Internet Security Consultant _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext