Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #570

Re: lightweight "slave" DNS server, +DNSSEC?

From Ivan Shmakov <ivan@gray.siamics.net>
Newsgroups comp.os.linux.networking
Subject Re: lightweight "slave" DNS server, +DNSSEC?
Date 2011-09-11 22:29 +0700
Organization Aioe.org NNTP Server
Message-ID <86pqj714jk.fsf@gray.siamics.net> (permalink)
References <86hb4l3r1t.fsf@gray.siamics.net> <j4id42$2nv$1@einschein.formularfetischisten.de>

Show all headers | View raw


>>>>> Hauke Lampe <packbart@blagga.openchaos.org> writes:
>>>>> Ivan Shmakov wrote:

 >> I wonder, is there a lightweight DNS server to be used as a
 >> “slave”?

 > I use NSD: http://nlnetlabs.nl/projects/nsd/ It's lightweight enough
 > to serve a number of DNSSEC-signed zones from a small virtual server.

	I've quickly scanned through its page, the Debian's
	Description:, and news:gmane.network.dns.nsd.general.  It seems
	like a good choice, thanks!

 >> The zones to be served are DNSSEC-signed, so it should check the
 >> signature on AXFR/IXFR and only accept the new data if it's valid.

 > I don't know any nameserver software that does this check on AXFR.
 > The transferred data is protected by TSIG but the server doesn't
 > validate the RRSIGs.

	Somehow, I've assumed that BIND will do it.  Apparently, I was
	mistaken.

	I'd probably use TSIG instead.

 > You could certainly script the zone transfer and validation outside
 > the server process and then load the zone as master.

	ACK.

 >> Will Maradns or PowerDNS fit?

 > PowerDNS *might* be able to verify transferred records within an
 > AXFR-script (http://doc.powerdns.com/slave.html#id440309).  I have no
 > firsthand experience in doing so, though.

	It doesn't look feasible to use this feature for DNSSEC
	validation, yet it may come handy for other tasks.  Thanks.

-- 
FSF associate member #7257	Coming soon: Software Freedom Day
http://mail.sf-day.org/lists/listinfo/ planning-ru (ru), sfd-discuss (en)

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-10 12:27 +0700
  Re: lightweight "slave" DNS server, +DNSSEC? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-09-11 08:52 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 16:15 +0700
      Re: lightweight "slave" DNS server, +DNSSEC? Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2011-09-11 11:10 -0600
        Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 09:11 +0200
        Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-12 15:51 +0700
          Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 11:12 +0200
            Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-13 01:18 +0700
              Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david.brown@removethis.hesbynett.no> - 2011-09-12 21:09 +0200
  Re: lightweight "slave" DNS server, +DNSSEC? Hauke Lampe <packbart@blagga.openchaos.org> - 2011-09-11 13:29 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 22:29 +0700

csiph-web