Re: how to get differing DNS results

Michael Richardson <[email protected]> Wed, 12 Mar 2003 20:33:40 -0800
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Paul" == Paul Wouters <[email protected]> writes:
    >> Copy and edit the files that you want. If you want them DNSSEC signed,
    >> then 
    >> you should add them to the Makefile. To sign them, you'll need at
    >> least bind9 
    >> snapshot 20021115. DO NOT USE BIND 9.2.x.
    >> 
    >> Each UML root has a testing/baseconfigs/xxx/etc/bind/named.conf. Copy
    >> this 
    >> to your test case. Your test case should be starting named manually
    >> anyway, 
    >> so add -c /testing/pluto/my-test/named-east.conf or whatever.

    Paul> Note that you can't securely resolve against the authorative
    Paul> nameserver. You need to run another caching nameserver for
    Paul> that. (bind9 doesn't verify zones from disk) 

  Yes, a good point.
  I'll change the named.conf's to put resolving from local host (and I hope
that this includes lwres access) into a seperate view from the other code.

  For the purpose of the tests that DHR is writing, DNSSEC is not required
at this time.

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBPnAKIoqHRg3pndX9AQEMywQAz7P9/0X04jqnc6XJRW+zK53CVZN261M7
Lo9a3ATQ3v4MFdmMppZ1Gn3WPY8RTvqbqHdTGXj7dj8a5sP/VOkWRTG9HsOA7x0Q
yJoldwN10u2Q34/P4+nYwW2pUxH4RhO25dPpcXuFuM4vlHL/O72DnrMXTH/9URq5
+W9CiW5XNJk=
=yyug
-----END PGP SIGNATURE-----