Re: Extending UPDATE to add/remove zones
Alex Bligh <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 16 Oct 2013, at 18:23, Derek Atkins wrote: > I admit I haven't read the whole draft, but my question is how do you > authenticate and, more importantly, authorize the addition or (worse) > deletion of zones? Imagine an attack vector where someone could get > your domain's DNS servers to stop serving your domain(s)! > > I think the security of adding and (more importantly) removing zones > should be carefully documented and discussed. I'm not sure why this would be different from someone doing an update to remove the entire content of the zone served. Thus I don't really see why it should need security any different from the existing provisions for security. -- Alex Bligh _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext