Re: squirting spray foam into the crack at the bottom of the BAW
Hugo Monteiro <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On 03/16/2010 10:20 AM, Maciej Żenczykowski wrote: >> From what i understood, that's exactly Dean point. DNS servers would >> fallback to TCP if: >> > not dns servers, dns caches / recursive resolvers > > They ARE dns servers. The records they serve may or not be local. >> 1 - Responses were larger than 512 bytes (as described in the current RFC). >> 2 - When they felt threatened by a birthday attack. >> > Agreed, I was just pointing out this wouldn't actually work. Many dns > servers simply don't listen for TCP requests or have them firewalled > (I know, I run one such server, never needed TCP, never bothered to > set it up...). You are not actually required to support tcp if you > know all your answers will be small enough. > > And how can you know that every query to your resolver will produce a < 512 bytes answer? Do you by any chance control all the queried authoritative servers? If not, i would say that you are your implementation is not RFC compliant. R's, Hugo Monteiro. -- fct.unl.pt:~# cat .signature Hugo Monteiro Email : [email protected] Telefone : +351 212948300 Ext.15307 Web : http://hmonteiro.net Divisão de Informática Faculdade de Ciências e Tecnologia da Universidade Nova de Lisboa Quinta da Torre 2829-516 Caparica Portugal Telefone: +351 212948596 Fax: +351 212948548 www.fct.unl.pt [email protected] fct.unl.pt:~# _