Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15738

Re: What is the proper way to delegate to a private / hidden sub-domain?

Path csiph.com!eternal-september.org!feeder.eternal-september.org!paganini.bofh.team!news.killfile.org!usenet.stanford.edu!not-for-mail
From Grant Taylor <gtaylor@tnetconsulting.net>
Newsgroups comp.protocols.dns.bind
Subject Re: What is the proper way to delegate to a private / hidden sub-domain?
Date Wed, 6 May 2020 17:03:49 -0600
Lines 106
Approved bind-users@lists.isc.org
Message-ID <mailman.372.1588806226.942.bind-users@lists.isc.org> (permalink)
References <20200506221238.EBB5818DAA0C@ary.qy> <16e156cc-96e3-7534-dcb1-c3a9d2530502@tnetconsulting.net>
NNTP-Posting-Host lists.isc.org
Mime-Version 1.0
Content-Type multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="------------ms010609050101020303020303"
X-Trace usenet.stanford.edu 1588806240 6109 149.20.1.60 (6 May 2020 23:04:00 GMT)
X-Complaints-To action@cs.stanford.edu
To bind-users@lists.isc.org
Return-Path <gtaylor@tnetconsulting.net>
X-Original-To bind-users@lists.isc.org
Delivered-To bind-users@lists.isc.org
DKIM-Signature v=1; a=rsa-sha256; c=simple/simple; d=tnetconsulting.net; s=2019; t=1588806232; bh=ZHOtUODMAy+GgNRn5JBxhQumxgaGCuFSc0mW1a7XE8s=; h=Subject:To:References:From:Message-ID:Date:User-Agent: MIME-Version:In-Reply-To:Content-Type:Cc:Content-Disposition: Content-Language:Content-Transfer-Encoding:Content-Type:Date:From: In-Reply-To:Message-ID:MIME-Version:References:Reply-To: Resent-Date:Resent-From:Resent-To:Resent-Cc:Sender:Subject:To: User-Agent; b=QE5MGgLHtrMIU6AYc9tu+KUCbzXzceTSBdEb6lUdQWIoC/J86KNOskgdOomwGC7yw 0cQm7KwtS8nRHcpY7dd4zD0EepPrQn6B/6PCQDAmvm2G3DERimnL7GLlI6BBG7Bwva ruU/GlH1U8iSM8oMHXsyBchRPLIVTRyeGkYyM4Ck=
User-Agent Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:68.0) Gecko/20100101 Thunderbird/68.8.0
In-Reply-To <20200506221238.EBB5818DAA0C@ary.qy>
X-Spam-Status No, score=-2.2 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DKIM_VALID_EF,GPG_SIGNED,RCVD_IN_DNSWL_NONE, SPF_HELO_PASS,SPF_PASS autolearn=disabled version=3.4.2
X-Spam-Checker-Version SpamAssassin 3.4.2 (2018-09-13) on mx.pao1.isc.org
X-BeenThere bind-users@lists.isc.org
X-Mailman-Version 2.1.29
Precedence list
List-Id BIND Users Mailing List <bind-users.lists.isc.org>
List-Unsubscribe <https://lists.isc.org/mailman/options/bind-users>, <mailto:bind-users-request@lists.isc.org?subject=unsubscribe>
List-Archive <https://lists.isc.org/pipermail/bind-users/>
List-Post <mailto:bind-users@lists.isc.org>
List-Help <mailto:bind-users-request@lists.isc.org?subject=help>
List-Subscribe <https://lists.isc.org/mailman/listinfo/bind-users>, <mailto:bind-users-request@lists.isc.org?subject=subscribe>
X-Mailman-Original-Message-ID <16e156cc-96e3-7534-dcb1-c3a9d2530502@tnetconsulting.net>
X-Mailman-Original-References <20200506221238.EBB5818DAA0C@ary.qy>
Xref csiph.com comp.protocols.dns.bind:15738

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

On 5/6/20 4:12 PM, John Levine wrote:
> Since they can't access the root servers, how do you expect them to 
> do DNS lookups at all?
There is a copy of the root zone in the environment.

There is also enough net zone for the needed tests.

DNSSEC is obviously not in play with doctored zones in the labs.



-- 
Grant. . . .
unix || die

Back to comp.protocols.dns.bind | Previous | NextNext in thread | Find similar | Unroll thread


Thread

Re: What is the proper way to delegate to a private / hidden sub-domain? Grant Taylor <gtaylor@tnetconsulting.net> - 2020-05-06 17:03 -0600
  Re: What is the proper way to delegate to a private / hidden sub-domain? "John Levine" <johnl@iecc.com> - 2020-05-06 20:56 -0400

csiph-web