[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Just send UTF-8 with nameprep (was: RE: [idn] Reality Check)



Patrik Fältström <paf@cisco.com> writes:

> Regarding only doing nameprep in the authoritative servers, that is
> definitly not enough. That means that you might get a query after owner A,
> which nameprepped is B, and because of this, one send a query for owner A,
> but get B as a response.

This is a good point!

> I really want DNS servers to reject those kind of responses (where the
> owner in the response doesn't match the owner in the query),

BIND 4, 8, and 9 will reject such responses, both in "named" and in
libresolv.

/Bob