Re: Beating an Old Horse, but....

Colm MacCárthaigh <[email protected]> Mon, 4 Oct 2010 14:37:52 -0700
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
--001485f85afe4f49af0491d15be2
Content-Type: text/plain; charset=ISO-8859-1

A preprocessor wouldn't do. The name-server would need to support EDNS0, and
the smarts to include DS and RRSIG records correctly. Additionally, in order
to support NSEC and NSEC3 there would need to be a lexicographically ordered
index available - a CDB backend won't do. It's a fairly large undertaking.

On Mon, Oct 4, 2010 at 12:13 PM, Sascha Silbe <
[email protected]> wrote:

> Excerpts from Brian's message of Mon Oct 04 20:46:22 +0200 2010:
>
> > Does anyone know of any existing branches / work being done for DNSCache
> > to support DNSSEC validation?
>
> Personally I'd be more interested in DNSSEC support for tinydns. Either
> as some kind of preprocessor or directly. Even a recipe to leverage the
> BIND tools would be welcome.
>
> Sascha
>
> --
> http://sascha.silbe.org/
> http://www.infra-silbe.de/
>



-- 
Colm

--001485f85afe4f49af0491d15be2
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div><br></div><div>A preprocessor wouldn&#39;t do. The name-server would n=
eed to support EDNS0, and the smarts to include DS and RRSIG records correc=
tly. Additionally, in order to support NSEC and NSEC3 there would need to b=
e a lexicographically ordered index available - a CDB backend won&#39;t do.=
 It&#39;s a fairly large undertaking.</div>
<br><div class=3D"gmail_quote">On Mon, Oct 4, 2010 at 12:13 PM, Sascha Silb=
e <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]=
rg">[email protected]</a>&gt;</span> wrote:<br><blockquot=
e class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc sol=
id;padding-left:1ex;">
Excerpts from Brian&#39;s message of Mon Oct 04 20:46:22 +0200 2010:<br>
<div class=3D"im"><br>
&gt; Does anyone know of any existing branches / work being done for DNSCac=
he<br>
&gt; to support DNSSEC validation?<br>
<br>
</div>Personally I&#39;d be more interested in DNSSEC support for tinydns. =
Either<br>
as some kind of preprocessor or directly. Even a recipe to leverage the<br>
BIND tools would be welcome.<br>
<br>
Sascha<br>
<font color=3D"#888888"><br>
--<br>
<a href=3D"http://sascha.silbe.org/" target=3D"_blank">http://sascha.silbe.=
org/</a><br>
<a href=3D"http://www.infra-silbe.de/" target=3D"_blank">http://www.infra-s=
ilbe.de/</a><br>
</font></blockquote></div><br><br clear=3D"all"><br>-- <br>Colm<br>

--001485f85afe4f49af0491d15be2--