secure (g)libc gethostbyname
Date: Mon, 02 Aug 2004 15:58:50 +0100
i wonder what the state of secure dns resolution at the client side is
within the (g)libc libraries.
i know that dnssec allows secure (authenticated) zone transfers.
i also know that dnssec allows a chain of trust to be established using
PKI ... but i'mnot sure if this chain ends at your ISP/nearest dns server.
does the client side (libc) allow this chain of trust ot extend to it so
that the communication between the dns requestor and the nearest dns
server is authenticated, validated and possibly encrypted.
that is - at install time, the administraor adds the secret which
identifies the nearest dns server (when writing /etc/resolv.conf). this
way, no dns answers are accepted from other hosts and also spoofing is
prevented too. encyrption of teh actual payload is optional.
is there support for this or is it planned?
- Re: Clients cannot find sharepoint
... The client machines had an entry in the append DNS ... Get ipconfig/all result on SBS and client computer. ... This newsgroup only focuses on SBS technical issues. ...
- Re: Internet Speed
... I think what we are trying to say is to use the DHCP from the SBS and NOT ... DNS and WINS point to the SBS. ... as the server IP address. ... it is recommend to configure all SBS client computers' IP and DNS ...
- Re: GPO problems
... It was the ISA 2004 firewall client. ... DNS settings and network properties on the server and client computers. ... > Service of SBS is configured to be the DNS server on the problematic ...
- Re: Multiple DCs more of a hinderance than help
... since the Exchange Server shows DC1 as the %LOGONSERVER% when I ... It would be helpful to see an ipconfig /all from a client machine, ... the client side resolver works. ... If first DNS is down, will it use the second DNS to find another DC to ...
- RE: suddenly strange DNS/Active Directory related symptoms
... another client who was also experiencing the outage that SBCGlobal corrected ... The DNS service does not load all its zones on a DNS server that is running ... Domain Zone. ... Microsoft CSS Online Newsgroup Support ...