Re: TCP connections to DJBDNS
Faried Nawaz <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | Integral Domains |
| Message-ID | <[email protected]> |
Dean Anderson wrote:
On Tue, 20 Jan 2009, Faried Nawaz wrote:
> Your dnscache does't reply to authoritative queries.
I meant that since dnscache supports TCP, it seems odd that tinydns
doesn't; I don't use tinydns, so I can say for sure.
dnscache handles recursive queries only. tinydns and axfrdns handle
authoritative queries only.
TCP is just about necessary to have reasonably secure DNS lookups in
some cases, and I think EDNSO and TCP should be (ought to be) supported
in both dnscache and tinydns.
DNSCurve, which doesn't really exist yet, shows that you can do secure
DNS lookups using UDP. Given the size of the response packet, it'll
use TCP if necessary, just like normal DNS lookups. DNSCurve uses larger
UDP packets, too:
DNSCurve clients are required to set aside a 4096-byte buffer for receiving
a UDP response packet. -- http://dnscurve.org/impl.html
If tinydns really doesn't support TCP, then we should think about fixing
that. It can't be very hard...
It doesn't need to -- there's axfrdns. http://cr.yp.to/djbdns/tcp.html
I am also thinking about changes to dnscache to enable one to configure
it to accept UDP queries, but prefer TCP for recursion. Thoughts?
Since it only handles recursive queries, that's not necessary.
Faried.
--
The Great GNU has arrived, infidels, behold his wrath !
(> (length "eclipse") (length "emacs")) => T