Re: "djbdns and nxdspecial patch"
Dean Anderson <[email protected]> Mon, 26 Apr 2010 16:04:52 -0400 (EDT)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
It has nothing to do with 'cache policy' per se, nor anything to do with the '/bin/login' program. Of course, running /bin/login is the last step in the network login process. For example tcpd, sshd, etc will try to do (sometimes multiple) reverse DNS lookups on the connecting IP address. This information will often be logged. The multiple systems involved frequently repeat the lookup the IP and and log separately. The queries go to a caching DNS server, eg. dnscache. These queries probably come in too fast for the first few to be answered from cache, so they are repeated by djbdns and the (unique spoofed/not-spoofed) responses will be returned. --Dean On Mon, 26 Apr 2010, Laurent Bercot wrote: > > A few quickly repeated queries are common in Windows and Unix during login. > > I don't understand that part. Could you please elaborate on what you > mean by "a few quickly repeated queries in Unix during login" ? As far > as I know, Unix login has nothing to do with a DNS cache policy; at > worst, the login process is linked against the djbdns client library, > which performs a single recursive query to the configured DNS cache > (or rotates among the known caches if the answer takes time, but > always one query at a time), and the answer does not depend on the > actual server location or resolution process. > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494