Re: New RRtype "KREALM" in draft-vanrein-dnstxt-krb1-02.txt
"Niall O'Reilly" <[email protected]> Sun, 13 Sep 2015 14:55:11 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 13 Sep 2015 13:55:45 +0100, Rick van Rein wrote: [...] > Here, $ORIGIN as you call it would be the hostname for the service, so > "www.example.com" for a service like HTTP/www.example.com I'm just borrowing a notation from the zone-file '$ORIGIN' directive, which (some?) zone parsers use to adjust the current value to be substituted for '@'. [...] > > And this too would fall under that hostname "www.example.com" and add > details. Or perhaps just under "example.com", depending on the use case. [...] > > Note my assumption -- you meant to lookup realm names under _realm > rather than the hostname of a server. Like the service tags in the owner name of the SRV record. > > The cost of this is one more DNS query, but targeted at the precise > thing we're looking for, so no search pattern. And (IIUC) no scanning of the RDATA to discard the parts of the blob that are irrelevant to the instant context. [...] > > > If the realm isn't really "at" $ORIGIN, a CNAME reference might be > > appropriate. > > > Hmm, that sounds like a nest of hornets to me, but it might work. I'm > not sure it is the best way though; references should contain their > KREALM explicitly and point at the realm name, and KREALM records > defining a home location for kerberos are always going to be local to > the DNS-name that they sort-of claim to hold. I wasn't sure that such administrative proximity (propinquity?) was to be counted on. Heel veel succes verder! Niall _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext