Re: Beating an Old Horse, but....
Colm MacCárthaigh <[email protected]> Mon, 4 Oct 2010 14:37:52 -0700
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
--001485f85afe4f49af0491d15be2 Content-Type: text/plain; charset=ISO-8859-1 A preprocessor wouldn't do. The name-server would need to support EDNS0, and the smarts to include DS and RRSIG records correctly. Additionally, in order to support NSEC and NSEC3 there would need to be a lexicographically ordered index available - a CDB backend won't do. It's a fairly large undertaking. On Mon, Oct 4, 2010 at 12:13 PM, Sascha Silbe < [email protected]> wrote: > Excerpts from Brian's message of Mon Oct 04 20:46:22 +0200 2010: > > > Does anyone know of any existing branches / work being done for DNSCache > > to support DNSSEC validation? > > Personally I'd be more interested in DNSSEC support for tinydns. Either > as some kind of preprocessor or directly. Even a recipe to leverage the > BIND tools would be welcome. > > Sascha > > -- > http://sascha.silbe.org/ > http://www.infra-silbe.de/ > -- Colm --001485f85afe4f49af0491d15be2 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable <div><br></div><div>A preprocessor wouldn't do. The name-server would n= eed to support EDNS0, and the smarts to include DS and RRSIG records correc= tly. Additionally, in order to support NSEC and NSEC3 there would need to b= e a lexicographically ordered index available - a CDB backend won't do.= It's a fairly large undertaking.</div> <br><div class=3D"gmail_quote">On Mon, Oct 4, 2010 at 12:13 PM, Sascha Silb= e <span dir=3D"ltr"><<a href=3D"mailto:[email protected]= rg">[email protected]</a>></span> wrote:<br><blockquot= e class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc sol= id;padding-left:1ex;"> Excerpts from Brian's message of Mon Oct 04 20:46:22 +0200 2010:<br> <div class=3D"im"><br> > Does anyone know of any existing branches / work being done for DNSCac= he<br> > to support DNSSEC validation?<br> <br> </div>Personally I'd be more interested in DNSSEC support for tinydns. = Either<br> as some kind of preprocessor or directly. Even a recipe to leverage the<br> BIND tools would be welcome.<br> <br> Sascha<br> <font color=3D"#888888"><br> --<br> <a href=3D"http://sascha.silbe.org/" target=3D"_blank">http://sascha.silbe.= org/</a><br> <a href=3D"http://www.infra-silbe.de/" target=3D"_blank">http://www.infra-s= ilbe.de/</a><br> </font></blockquote></div><br><br clear=3D"all"><br>-- <br>Colm<br> --001485f85afe4f49af0491d15be2--