[aklug] Re: GCI DNS and BIND Settings

From: Arthur Corliss <acorliss@nevaeh-linux.org>
Date: Wed Mar 26 2008 - 20:49:49 AKDT

On Wed, 26 Mar 2008, dhull wrote:

> 99.99% of the time I'm using GCI DNS. Most of the time it's working just fine. The caching issue makes sense. I've seen DNS TTL settings for 1 day. When I was playing with DNS I configured mine for 30 minutes. Didn't want to wait long for changes to take effect.
>
> Since I'm pointing fingers here and there about DNS I feel it's only fare to talk about my own DNS server. It doesn't have ACL support. Is that bad. Sure it is. What kind of crazy things have others done to it? Who knows. Should I be watching it? I don't think so. It was never designed as a production DNS server.

I thought you said you installed BIND 9? If so, you *do* have ACL support.
I'm not aware of a configure switch to kill that functionality.

> Times have changed. I need a production quality DNS server. That means reinstalling and adding some security features to BIND.

Your sample config file may not list the options, but that doesn't
necessarily mean you don't have them. Quite frankly, I'd be surprised if
you didn't have them already.

         --Arthur Corliss
           Live Free or Die
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Wed Mar 26 20:50:29 2008

This archive was generated by hypermail 2.1.8 : Wed Mar 26 2008 - 20:50:29 AKDT