Building consensus over DNSSEC enhancements to glibc.

Florian Weimer fweimer@redhat.com
Wed Nov 18 08:12:00 GMT 2015


On 11/17/2015 02:18 AM, Zack Weinberg wrote:

> Don't you see that the entire rest of this thread demonstrates that
> trying to eliminate all the "broken things distros and dhcp client
> software are doing" is a lost cause?

But there is no quick way around cleaning up this mess.  If we just slap
on a band-aid, eventually all software that writes /etc/resolv.conf
today will learn about it (whether the band-aid is a new file, or an
option in an existing file) and do things that break the configured
security policy of the system.  I don't know if it takes one year or
three years, but it will happen.

Florian



More information about the Libc-alpha mailing list