This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Building consensus over DNSSEC enhancements to glibc.


On 11/10/2015 03:03 AM, Rich Felker wrote:
> On Mon, Nov 09, 2015 at 11:57:29AM +0100, Petr Spacek wrote:
>> One of reasons why 'nameserver 127.0.0.1' only cannot work are systems which
>> boot from network. Imagine that the system is booting so it does not
>> necessarily have local resolver running (yet) but the system might need to
>> mount NFS share with / from somewhere, probably from a NFS server which is
>> identified by DNS name.
> 
> That works perfectly well. You simply configure it to use the
> nameservers from dhcp as the upstream sources for the nameserver
> running on localhost.

That does not address the problem of the network being able to set AD bits in DNS packets.
AD bits are _not_ protected by a signature of any kind.

Obviously, a fully validating locally running resolver is the best solution. It's the corner cases we are trying to address.

Paul



Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]