Hi,
I'm just going to rebuild my server at home and put in a DNS cache to make up for the pants DNS servers at Virgin (I just had to switch because I moved house and the ADSL at the new place is totally shocking.) Virgin sell you the fastest broadband (50Mb) then sit it on DNS infrastructure that can take nearly a second to respond, resulting in decidedly sub-standard performance.
Last time I set up a DNS server DNSSEC wasn't an issue. If I'm installing Bind to resolve local addresses and forward and cache external ones today is there anything I should do differently to be DNSSEC-ready?
Thanks,
Paul.
Sent from my BlackBerry® wireless device
-----Original Message-----
From: Paul Tansom <paul@???>
Date: Wed, 5 May 2010 17:26:36
To: <hampshire@???>
Subject: Re: [Hampshire] problems with accessing startx.co.uk
** Hugo Mills <hugo@???> [2010-05-05 16:55]:
> On Wed, May 05, 2010 at 01:04:51PM +0100, John Lewis wrote:
> > I don't understand the DNS system at all other than a need to put some
> > nameservers into /etc/resolv.conf (or equivalent) and didn't realise
> > until this problem came up that startx.co.uk needed the *.myth.co.uk
> > servers
>
> The DNS is, as James said, a distributed database. It primarily
> contains the information for turning a domain name (e.g. startx.co.uk)
> into an IP address. It can also contain a whole load of other
> information, but we'll ignore that for now.
<snip>
** end quote [Hugo Mills]
As an aside to this, it may be worth noting that today the final root
nameservers are being enabled for DNSSEC, which has caused some to worry about
systems having resolution problems. I believe that this is unlikely on the
whole, unless you have some pretty old routers or software, but probably worth
being aware of. This has been being rolled out for a few months now, and won't
fully go live until July.
http://www.zdnet.co.uk/news/security-management/2010/05/05/anti-spoofing-measure-embedded-at-internet-root-40088850/
http://www.icann.org/en/announcements/announcement-27jan10-en.htm
http://www.root-servers.org/
http://www.root-dnssec.org/
--
Paul Tansom | Aptanet Ltd. |
http://www.aptanet.com/ | 023 9238 0001
======================================================================
Registered in England | Company No: 4905028 | Registered Office:
Crawford House, Hambledon Road, Denmead, Waterlooville, Hants, PO7 6NU
--
Please post to: Hampshire@???
Web Interface:
https://mailman.lug.org.uk/mailman/listinfo/hampshire
LUG URL:
http://www.hantslug.org.uk
--------------------------------------------------------------