Re: Extending UPDATE to add/remove zones

Derek Atkins <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Hi,

Jay Daley <[email protected]> writes:

>>From my previous post on my draft for a new DNS opcode - servezones -
> I think there is reasonable interest in an in-band mechanism that
> instructs a nameserver to etiher start or stop serving one or more
> zones.  The area with less certainty is what that mechanism should be,
> a new Opcode (but it's only a 4 bit space!) or extending UPDATE.
>
> I'm planing to write a draft that shows how UPDATE could be extended
> to do this and then we can compare that with my servezones draft and
> see which is preferred.  To do that I'd like some help in determining
> the algorithm for how the extended UPDATE is processed.
[snip]

I admit I haven't read the whole draft, but my question is how do you
authenticate and, more importantly, authorize the addition or (worse)
deletion of zones?  Imagine an attack vector where someone could get
your domain's DNS servers to stop serving your domain(s)!

I think the security of adding and (more importantly) removing zones
should be carefully documented and discussed.

> Jay

-derek

-- 
       Derek Atkins                 617-623-3745
       [email protected]             www.ihtfp.com
       Computer and Internet Security Consultant
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.