Re: lwdnsq(8)

Michael Richardson <[email protected]>
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "D" == D Hugh Redelmeier <[email protected]> writes:
    D> | From: Michael Richardson <[email protected]>

    D> I had a quick glance at this man page.

    D> |        If the --single option is given, then the program will not
    D> |        attempt  to execute concurrent queries, but will serialize
    D> |        all input and output.

    D> Perhaps "--single" would be better called "--serial" or "--serialize"
    D> (be lead by the description).

  Done.

    D> |        ID     this  is the queryid value that was provided in the
    D> |        --
    D> |               query. It is repeated on every line to  permit  the
    D> |               replies to be properly associated with the query.

    D> When the response is not ascribed to a query, a queryid of "0" is
    D> used.

  Added.

    D> |        All of the replies which include resource records use  the
    D> |        standard  presentation  format (with no line feeds or car­
    D> |        riage returns) in their answer.

    D> I understand that standard presentation format requires strings to be
    D> less than 256 characters so TXT records we use would have multiple
    D> strings.  But I think that lwdnsq always shows this as a single
    D> string.

  Yes.
  How should this be described.
 
    D> | OE DIRECTIVES
    D> |        If  the file /etc/ipsec.d/lwdnsq.conf exists, and contains
    D> |        a line like
    D> | 
    D> | 
    D> |        queryany=false
    D> | 
    D> |         then instead of doing an ALL query when  looking  for  OE
    D> |        delegation records, lwdnsq will do a series of queries. It
    D> |        will first look for IPSECKEY, and then TXT record.  If  it
    D> |        finds  neither,  it  will then look for KEY records of all
    D> |        kinds, although they do not  contain  delegation  informa­
    D> |        tion.

    D> I'm still not convinced ANY works the way you think it does.

  I've not been shown any evidence, just conjecture, that it doesn't.
  Thus, we will hedge our bet here.

    D> This man page needs a FILES section listing /etc/ipsec.d/lwdnsq.conf.

  True.

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBPj78coqHRg3pndX9AQEIIAP+MqBmlOQjC/rtNBbeuaZ5/u78JFiPHQd8
vC/xodj7MYvObjShkjjOHie063sOVekKuElG6AKrjymHegRV4wi7Xr/G62xp9SGe
rEHT+IX2SBjigSPcf/fc1+qlUn8N1Y9ddrbpkN2GFEJ6pt1nsOpm6dzEYe7BwQpA
GIsGguwHOEM=
=0rjf
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.