[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Poison in a zone



D. J. Bernstein writes:
> But now Gustafsson admits that the BIND 9 AXFR client doesn't follow
> the ``zone coherency'' religion. It deliberately discards some kinds of
> records! It isn't making a perfect copy of the zone! It's breaking IXFR!

BIND 9 is doing what you yourself said it "must" do.

This does not by itself break IXFR.  In theory, IXFR can break when
the zone transfer graph contains both servers that fully support
out-of-zone glue and servers that do not, but in practice no servers
support out-of-zone glue and the problem does not occur.  This is of
course another argument for completely outlawing out-of-zone glue in
both masters and slaves as you already suggested doing for security
reasons.  Mandating support for out-of-zone glue everywhere would also
work, but outlawing it does seem like the more realistic approach.

In practice, IXFR failures are likely to be caused by inconsistencies
in-domain glue, not out-of-domain glue, and the in-domain case is what
section 4 is primarily trying to address.
-- 
Andreas Gustafsson, gson@nominum.com