Re: [djbdns] gdnsd DNSCurve update

Jason 'XenoPhage' Frisvold <[email protected]> Thu, 17 Jun 2010 21:39:42 -0400
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Jun 17, 2010, at 6:19 PM, Brandon Black wrote:
> No, gdnsd is not not a djb fork.  It's an original, separate codebase
> licensed under the terms of the GPLv3.  It's also *only* an
> authoritative server (i.e. it does the role of djb's "tinydns", but
> not "dnscache").  The project originated in early 2007 as something I
> wrote on Logitech's time because the department I worked for needed it
> (long story, and this email is already going to be longer than you
> want to read), and we decided to GPL it at the time because that was
> the norm in that department, and because Logitech didn't have any
> broader interest in a DNS server as a commercial software product of
> any kind.

Ah..  ok..  I seem to remember seeing something about this a few months back..  Excellent..

> Like Dan and many others, I'm not a believer in DNSSEC, and I think
> DNSCurve is a viable alternative route to solving some of the DNS's
> security problems.  As far as that goes, we need all the
> interoperating implementations we can get if there's to be any hope of
> DNSCurve getting any broader adoption.  So far it looks like gdnsd
> will probably be the first to release a production-quality native
> implementation in an authoritative DNS server (at least, that I've
> heard of), but I hope it's not the last.

I am, myself, still quite skeptical of DNSSEC as well.  At the very least, it seems like an awful lot of effort for such little payoff.  Though, I will admit to being somewhat naive about both DNSSEC and DNSCurve.  As much as I try, I still have not found the time to dig into either.

> On the recursive cache side of things we've got Matthew's patches to
> djb's dnscache as well as George Barwood's GbDns server that I'm aware
> of, and whatever OpenDNS is running in production (I haven't really
> tried to look, but it may in fact be the patched dnscache for all I
> know).

I thought OpenDNS had already put DNSCurve into production?

> -- Brandon

As an aside, are others getting bouncebacks from Amazon and Paypal when you post to this list?

- ---------------------------
Jason 'XenoPhage' Frisvold
[email protected]
- ---------------------------
"Any sufficiently advanced magic is indistinguishable from technology."
- - Niven's Inverse of Clarke's Third Law



-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.14 (Darwin)

iEYEARECAAYFAkwazl4ACgkQ8CjzPZyTUTR0+wCfYIsBgd40FLN+COqXj9nYZjwj
uvUAn2U9vxaQuQrBkrSHoJwM/bWwujJS
=t0VD
-----END PGP SIGNATURE-----