Re: Potentially Predatory Pre-Announcement of Possible Vaporware (zinq-djbdns-0.01)
Bernd Plagge <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | First Choice Internet Ltd. |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Heated arguments flying forward and backward. I've been using tinydns for over 8 years. In the past I also used qmail but it became too painful to compare the various patches and to combine them. I'm now using Courier which is a very complete package and there are Debian packages available for it (in the past I built Debian packages myself). You're on the right track whatever the purists are saying. All major Linux installations are using package managers (no insult intended, I'm talking about installation figures) and for this reason all commonly used software is provided as RPM and DEB package. I don't know much about rpm's but here are some facts about deb packages: - - you can build several deb packages from one source package - - to build a deb package it is best to use autoconf etc with proper support for various system paths ($prefix etc) (that means if a package comes with autoconf, automake it is easy to built deb package) Personally I don't think that DNSSEC will come - at least not worldwide - - because countries will just not accept that the US is controlling the DNS system. This, however, is a personel opinion and as the US has decided that .mil and .gov domains have to use DNSSEC there is little argument about the fact that it would be beneficial for tinydns to be able to support this. This does not mean that everybody has to use it. The inclusion of DNSSEC could be handled by a configuration variable. That way you compile without DNSSEC support if you don't need it. Also, I checked DNSCurve but it seems that there is no implementation for tinydns yet. I may be worth to contact the DNSCurve guys to obtain some more information. A working DNSCurve implementation for tinydns as well as the availability of suitable library routines to be used for other DNS resolvers is an absolute necessity to promote an alternative to DNSSEC. One of the main arguments for DNSSEC brought forward by ISC is that lot's of time (and money) was spent on DNSSEC development AND that there is no alternative. Nobody cares about the money because spent is spent and you won't get any cent back regardless whether you use it or not. But it is important to have an alternative. If implementation costs of the (DNSCurve) alternative are much lower and it is at least as secure as DNSSEC then you also got a practical argument against DNSSEC. I'm quite willing to test a DNSCurve implementation as soon as it becomes available. BTW, djbdns tinydns does not support IPV6 but there are patches to add IPV6 support to tindyns and to uscpi-tcp. Did you include this? Regards, Bernd On Thu, 13 Nov 2008 13:37:33 -0600 "Mark Johnson" <[email protected]> wrote: > On Thu, Nov 13, 2008 at 12:54 PM, Laurent Bercot <[email protected]> wrote: > > What was it motivated by? > > Look at the obvious coding style differences between autoconf and > > djbdns. Since you're working on djbware, I think it's safe to assume > > you like DJB's coding style. Why then succumb to the bloated side and > > create some unholy hybrid? > > Bloated? The autotooled version has *less* code. I don't see > what the build system has to do with coding style. The generated > Makefile produces the same executables as Dan's Makefile would. > > > As for DNSSEC: for heaven's sake, please, no. > > DNSSEC does not work. DNSSEC will not work. With all the resources > > that the ISC, and AFAIK the US government, have invested into DNSSEC, > > it would be working *now* if it was meant to work. > > But it's not. It's flawed by design. > > When a signed root zone has actually been publicaly deployed, it > will be time to talk DNSSEC. > > > DJB's policy is: do not implement or use things that are flawed by > > design. > > This policy has kept the code clean, secure and small. Please do not > > go against it, no matter how much political pressure you're submitted > > to. > > I'm not DJB. > > > It's okay to not implement something that can only work in the mind > > of a few people, no matter how influential those people may be. > > If something will make the Internet a better place, I may support > it. I am not convinced this will be the case for DNSSEC. I am also > not convinced that this will *not* be the case. With adequate thrust > and sufficient directional control, pigs can be made to fly. > You seem to have mistaken me for somebody important enough to > pressure politically. This is not the case. - -- プラゲ ベェアント - Bernd Plagge ファースト・チョイス・インターネット(有) First Choice Internet Ltd., Tokyo Tel. 03-4500-7799 Fax. 03-4400-3723 mail: [email protected] url: http://www.choicenet.ne.jp -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkkcwDAACgkQpYU8M8PbPV7SzwCfYwXa7n8cTwrAF8NNpDjByewg 9AUAoJN2RcEo4k8LuW6pttw3bKgenKS5 =aBcs -----END PGP SIGNATURE-----