Building consensus over DNSSEC enhancements to glibc.
Paul Wouters
pwouters@redhat.com
Fri Nov 6 23:37:00 GMT 2015
On 11/07/2015 03:28 AM, Rich Felker wrote:
> On a system configured with DNSSEC you do not allow resolv.conf to be
> changed by dhcp clients. Doing so is a bug.
Life is more complicated than that. That's why things like dnssec-trigger exist to begin with.
1) Blocked port 53 except to local resolver
2) hotspots
3) transparent redirection to non-dnssec resolver
Additionally, we are seeing more initiatives in the DPRIVE working group to work on dns privacy, so more and more
we will see people who don't want to use the local resolvers for anything else but portal negotiation. Which is
a good thing I think.
Paul
More information about the Libc-alpha
mailing list