Re: Generic records and DKIM
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 18 Mar 2009, Matthew Dempsky wrote: > On Wed, Mar 18, 2009 at 8:14 PM, Dean Anderson <[email protected]> wrote: > > Dnscache has a 512byte limit on the packet size, > > That's blatantly false. dnscache accepts DNS packets over 512 bytes > over TCP, exactly according to the spec. With a patch, it also > accepts larger (illegal) packets over UDP too. Gee, talk about blatantly splitting hairs. Its always funny how people try to jump on the smallest thing. Yes, I did mean UDP, and I know that TCP handles larger responses. I'd suppose that should be obvious given the discussion about TCP recently. But to be precise: Tinydns 1.05 won't send UDP packets larger than 512 bytes, doesn't support EDNSO in the tinydns authority server, and will fallback to TCP on responses larger than 512 bytes. Matthew is Right. I concede that I didn't fully explain this. Happy? You might also want to look at the patch posted by Sami Farin on October 6th, 2008, and the subject thread 'Re: dnscache and oversized answers'. There was some discussion of extending this to include larger 4096 byte packets, but none of it is in the original 1.05 code. In dns_transmit.c, you will find udpbuf to be 513 bytes. This patch(s) made dns_transmit_get fall back to TCP for large packets, and handle ENDSO to some extent (not completely). But they address only dnscache and some of the programs like dnsq, and don't affect tinydns. > >Â FYI, in response to another request, I'm putting together a page > > on the 14 serious flaws with SPF identified to the IETF before approval > > (15 or 16, I think if you include flaws discovered after SPF was > > approved, including a DOS attack). > > Terrific! It sounds like this will be a long and difficult task that > will take a lot of your time away from the mailing list, but don't > worry, we'll understand. Please take your time. Wow, What a really spiteful thing to say. Is it that you don't care about good engineering based on facts and critical analysis? I understand that attitude from the likes of Dave Crocker, William Schlitt, John Levine, Paul Vixie et al who are selling the stuff and some of those are selling CBE/spam services, too. Those people simply can't win technical arguments except by silencing their opponents through dishonest means. But in science and engineering, facts are paramount, and those who ignore and suppress the facts can't possibly deliver on their technical promises. Their promises are just not _possible_ and in this case violate the laws of information theory and ultimately thermodynamics. The people (like yourself) still hoping they will deliver someday despite the mounting evidence found in 15 years of failure, really ought not be spiteful at the people (like myself) who noticed over 10 years ago that the scammers didn't have the technical facts in the beginning. Relatively recently it was discovered that not only didn't the scammers have the technical facts, but they had ulterior conflicting financial motives in sending CBE/spam themselves, which they keep secret. The spam scammers are the Madoff's and AIG's of the antispam industry. But, I guess that Madoff and AIG have their defenders, too---people who think the they are innocent and good---people who won't look at the mounting evidence to the contrary and are just angered by the evidence which defies their belief in the goodness of the scammers. It always amazes me, though. Have a good weekend. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000