Re: TCP connections to DJBDNS

Faried Nawaz <[email protected]>
Newsgroups gmane.network.djbdns
Organization Integral Domains
Message-ID <[email protected]>
Dean Anderson wrote:
  On Tue, 20 Jan 2009, Faried Nawaz wrote:
  
  > Your dnscache does't reply to authoritative queries.  
  
  I meant that since dnscache supports TCP, it seems odd that tinydns
  doesn't; I don't use tinydns, so I can say for sure.

dnscache handles recursive queries only.  tinydns and axfrdns handle
authoritative queries only.


  TCP is just about necessary to have reasonably secure DNS lookups in
  some cases, and I think EDNSO and TCP should be (ought to be) supported
  in both dnscache and tinydns.

DNSCurve, which doesn't really exist yet, shows that you can do secure
DNS lookups using UDP.  Given the size of the response packet, it'll
use TCP if necessary, just like normal DNS lookups.  DNSCurve uses larger
UDP packets, too: 

DNSCurve clients are required to set aside a 4096-byte buffer for receiving
a UDP response packet.  -- http://dnscurve.org/impl.html


  If tinydns really doesn't support TCP, then we should think about fixing
  that. It can't be very hard...

It doesn't need to -- there's axfrdns.  http://cr.yp.to/djbdns/tcp.html

  
  I am also thinking about changes to dnscache to enable one to configure
  it to accept UDP queries, but prefer TCP for recursion.  Thoughts?

Since it only handles recursive queries, that's not necessary.  


Faried.
-- 
The Great GNU has arrived, infidels, behold his wrath !
           (> (length "eclipse") (length "emacs")) => T
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.