Re: New RRtype "KREALM" in draft-vanrein-dnstxt-krb1-02.txt

"Niall O'Reilly" <[email protected]> Sun, 13 Sep 2015 14:55:11 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On Sun, 13 Sep 2015 13:55:45 +0100,
Rick van Rein wrote:
 [...]
> Here, $ORIGIN as you call it would be the hostname for the service, so
> "www.example.com" for a service like HTTP/www.example.com

  I'm just borrowing a notation from the zone-file '$ORIGIN'
  directive, which (some?) zone parsers use to adjust the current
  value to be substituted for '@'.
  
 [...]
>
> And this too would fall under that hostname "www.example.com" and add
> details.

  Or perhaps just under "example.com", depending on the use case.

 [...]
> 
> Note my assumption -- you meant to lookup realm names under _realm
> rather than the hostname of a server.
 
  Like the service tags in the owner name of the SRV record.
> 
> The cost of this is one more DNS query, but targeted at the precise
> thing we're looking for, so no search pattern.

  And (IIUC) no scanning of the RDATA to discard the parts of the blob
  that are irrelevant to the instant context.

 [...]
> 
> > If the realm isn't really "at" $ORIGIN, a CNAME reference might be
> > appropriate.
> >
> Hmm, that sounds like a nest of hornets to me, but it might work.  I'm
> not sure it is the best way though; references should contain their
> KREALM explicitly and point at the realm name, and KREALM records
> defining a home location for kerberos are always going to be local to
> the DNS-name that they sort-of claim to hold.

  I wasn't sure that such administrative proximity (propinquity?)
  was to be counted on.

  Heel veel succes verder!

  Niall
  

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext