Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #570
| From | Ivan Shmakov <ivan@gray.siamics.net> |
|---|---|
| Newsgroups | comp.os.linux.networking |
| Subject | Re: lightweight "slave" DNS server, +DNSSEC? |
| Date | 2011-09-11 22:29 +0700 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <86pqj714jk.fsf@gray.siamics.net> (permalink) |
| References | <86hb4l3r1t.fsf@gray.siamics.net> <j4id42$2nv$1@einschein.formularfetischisten.de> |
>>>>> Hauke Lampe <packbart@blagga.openchaos.org> writes: >>>>> Ivan Shmakov wrote: >> I wonder, is there a lightweight DNS server to be used as a >> “slave”? > I use NSD: http://nlnetlabs.nl/projects/nsd/ It's lightweight enough > to serve a number of DNSSEC-signed zones from a small virtual server. I've quickly scanned through its page, the Debian's Description:, and news:gmane.network.dns.nsd.general. It seems like a good choice, thanks! >> The zones to be served are DNSSEC-signed, so it should check the >> signature on AXFR/IXFR and only accept the new data if it's valid. > I don't know any nameserver software that does this check on AXFR. > The transferred data is protected by TSIG but the server doesn't > validate the RRSIGs. Somehow, I've assumed that BIND will do it. Apparently, I was mistaken. I'd probably use TSIG instead. > You could certainly script the zone transfer and validation outside > the server process and then load the zone as master. ACK. >> Will Maradns or PowerDNS fit? > PowerDNS *might* be able to verify transferred records within an > AXFR-script (http://doc.powerdns.com/slave.html#id440309). I have no > firsthand experience in doing so, though. It doesn't look feasible to use this feature for DNSSEC validation, yet it may come handy for other tasks. Thanks. -- FSF associate member #7257 Coming soon: Software Freedom Day http://mail.sf-day.org/lists/listinfo/ planning-ru (ru), sfd-discuss (en)
Back to comp.os.linux.networking | Previous | Next — Previous in thread | Find similar | Unroll thread
lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-10 12:27 +0700
Re: lightweight "slave" DNS server, +DNSSEC? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-09-11 08:52 +0000
Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 16:15 +0700
Re: lightweight "slave" DNS server, +DNSSEC? Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2011-09-11 11:10 -0600
Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 09:11 +0200
Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-12 15:51 +0700
Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 11:12 +0200
Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-13 01:18 +0700
Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david.brown@removethis.hesbynett.no> - 2011-09-12 21:09 +0200
Re: lightweight "slave" DNS server, +DNSSEC? Hauke Lampe <packbart@blagga.openchaos.org> - 2011-09-11 13:29 +0000
Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 22:29 +0700
csiph-web