Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #578

Re: lightweight "slave" DNS server, +DNSSEC?

From Ivan Shmakov <ivan@gray.siamics.net>
Newsgroups comp.os.linux.networking
Subject Re: lightweight "slave" DNS server, +DNSSEC?
Date 2011-09-13 01:18 +0700
Organization Aioe.org NNTP Server
Message-ID <86ty8hwrn3.fsf@gray.siamics.net> (permalink)
References (1 earlier) <slrnj6otln.gtj.grahn+nntp@frailea.sa.invalid> <8639g330fb.fsf@gray.siamics.net> <1by5xv3syz.fsf@snowball.wb.pfeifferfamily.net> <86k49eywgp.fsf@gray.siamics.net> <keWdnSXVBZw9UPDTnZ2dnUVZ7vOdnZ2d@lyse.net>

Show all headers | View raw


>>>>> David Brown <david@westcontrol.removethisbit.com> writes:
>>>>> On 12/09/2011 10:51, Ivan Shmakov wrote:

[…]

 >> As it's only a forwarder, and thus doesn't store the zone locally
 >> (beyond its cache), I see it inapplicable to the task of serving a
 >> DNS zone (say, the aforementioned .siamics.net.) as a «slave»
 >> server.

[…]

 > dnsmasq can serve up fixed names, but not with the flexibility of
 > full zone configurations.  Basically, it can read /etc/hosts (or a
 > similar format file) and serve up the names from there.

	Now, when the zone is modified, will it send (receive) notices
	to (from) the other servers for this zone?  (Having a single NS
	serving a “global” zone doesn't seem like a clever solution.)
	Will it support the following AXFR (IXFR) queries?

	Honestly, I'm failing to see any definition of “slave
	nameserver” that dnsmasq may satisfy.

	Besides, my zones generally contain not only AAAA and A records,
	but also MX, SRV, SSHFP, and, on occasion, TXT ones, which, to
	the best of my knowledge, have no representation in the hosts(5)
	format.

 > In many cases, but clearly not all cases, that's all you need.

	Like in serving a .home.local zone, I guess?  For such a case,
	there's no point in having a “slave” NS, which is mentioned in
	both the Subject: and the OP.

	(Having said that, I don't think that it supports DNSSEC,
	either.)

-- 
FSF associate member #7257	Coming soon: Software Freedom Day
http://mail.sf-day.org/lists/listinfo/ planning-ru (ru), sfd-discuss (en)

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-10 12:27 +0700
  Re: lightweight "slave" DNS server, +DNSSEC? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-09-11 08:52 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 16:15 +0700
      Re: lightweight "slave" DNS server, +DNSSEC? Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2011-09-11 11:10 -0600
        Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 09:11 +0200
        Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-12 15:51 +0700
          Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 11:12 +0200
            Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-13 01:18 +0700
              Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david.brown@removethis.hesbynett.no> - 2011-09-12 21:09 +0200
  Re: lightweight "slave" DNS server, +DNSSEC? Hauke Lampe <packbart@blagga.openchaos.org> - 2011-09-11 13:29 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 22:29 +0700

csiph-web