Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #566

Re: lightweight "slave" DNS server, +DNSSEC?

From Ivan Shmakov <ivan@gray.siamics.net>
Newsgroups comp.os.linux.networking
Subject Re: lightweight "slave" DNS server, +DNSSEC?
Date 2011-09-11 16:15 +0700
Organization Aioe.org NNTP Server
Message-ID <8639g330fb.fsf@gray.siamics.net> (permalink)
References <86hb4l3r1t.fsf@gray.siamics.net> <slrnj6otln.gtj.grahn+nntp@frailea.sa.invalid>

Show all headers | View raw


>>>>> Jorgen Grahn <grahn+nntp@snipabacken.se> writes:
>>>>> On Sat, 2011-09-10, Ivan Shmakov wrote:

 >> I wonder, is there a lightweight DNS server to be used as a "slave"?
 >> The zones to be served are DNSSEC-signed, so it should check the
 >> signature on AXFR/IXFR and only accept the new data if it's valid.
 >> (It isn't much an issue to prepare a list of trusted keys for it,
 >> but DLV support will nevertheless be handy.)

 >> Will Maradns or PowerDNS fit?

 >> Or is BIND 9.7 really the best possible solution for this task?

 > Is there any specific reason why you think bind won't do?  Or do you
 > simply think it's overkill because it has lots of features which you
 > don't need?

	Mostly the latter.  However, I'm also somewhat constrained in
	resources (virtual memory, for instance), since this NS is going
	to be run on a so-called "virtual server", and it's a really
	cheap one.  (Not that I had any issues in a similar case, but
	nevertheless.)

-- 
FSF associate member #7257	Coming soon: Software Freedom Day
http://mail.sf-day.org/lists/listinfo/ planning-ru (ru), sfd-discuss (en)

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-10 12:27 +0700
  Re: lightweight "slave" DNS server, +DNSSEC? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-09-11 08:52 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 16:15 +0700
      Re: lightweight "slave" DNS server, +DNSSEC? Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2011-09-11 11:10 -0600
        Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 09:11 +0200
        Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-12 15:51 +0700
          Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 11:12 +0200
            Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-13 01:18 +0700
              Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david.brown@removethis.hesbynett.no> - 2011-09-12 21:09 +0200
  Re: lightweight "slave" DNS server, +DNSSEC? Hauke Lampe <packbart@blagga.openchaos.org> - 2011-09-11 13:29 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 22:29 +0700

csiph-web