Building consensus over DNSSEC enhancements to glibc.
Paul Wouters
pwouters@redhat.com
Fri Nov 20 01:11:00 GMT 2015
On 11/19/2015 11:24 PM, Florian Weimer wrote:
> On 11/19/2015 06:22 AM, Carlos O'Donell wrote:
>> Dare I say that systemd-resolved might solve some of this already?
>
> Unfortunately, systemd-resolved caches far too aggressively and will
> poison its cache, even accidentally. Various parties have tried to
> explain this to the upstream developers, but have not succeeded.
Yeah, I ran into similar problems and mostly got back "I wrote avahi so I know DNS".
> systemd-resolved should be safe to run behind a BIND 9 recursive server
> in non-forwarding mode, but not much else (I believe even Unbound is
> unsafe due to its last-resort message handling).
>
> systemd-resolved also does not handle exotic record types, I think, it
> is more an NSS-level solution than a libresolv-level solution.
>
> (An earlier attempt in this direction is lwresd, which is part of BIND 9.)
libreswan (well, openswan) used to support lwresd but we replaced it with libunbound.
I'm not sure if ISC still supports it or actively maintains it.
Paul
More information about the Libc-alpha
mailing list