1 Aug 2009 09:18
Re: DNS64 reverse
Mark Andrews <marka <at> isc.org>
2009-08-01 07:18:51 GMT
2009-08-01 07:18:51 GMT
In message <20090731222142.GH14838 <at> shinkuro.com>, Andrew Sullivan writes: > On Sat, Aug 01, 2009 at 07:54:31AM +1000, Mark Andrews wrote: > > You made this way to complicated which is why I suggested the > > CNAME in the first place. > > I am willing to countenance a charge that I've made it more > complicated than you think necessary. Perhaps just synthesizing the > CNAME is indeed trivial (though I think you're waving away some of the > steps I outlined without admitting that you have in fact to do them). > But ⦠> > > > to be _that_ bad, so it's by no means impossible. But it's more > > > complication in an already fragile and complicated mess that we're > > > creating just as a transition strategy. > > > > FUD > > ⦠I am not willing to stand for that. What I am saying is not FUD, > it's simply asking whether a given trade-off is worth it. It's fun to > point and laugh at people we disagree with, but that isn't an > argument. Your making it out to be much harder that it is. You are over estimating the difficulty. Named already does something like this to authorise UPDATES in the 6to4 range. It digs the IPv4 address out of the UPDATE request and matches it against the source address of the UPDATE as well as checking that it is coming in via TCP. Doing this was trivial. Doing a similar thing with queries is(Continue reading)
RSS Feed