AS information available via DNS
Tony Bates Tony.Bates at ripe.net
Wed May 12 15:02:40 CEST 1993
Havard Eidnes <Havard.Eidnes at runit.sintef.no> writes: * > * > [mature-tony-1480] host -lt txt as1104.aut-num.ripe.net * > * > AS1104.aut-num.ripe.net TXT 184.108.40.206 * > * > AS1104.aut-num.ripe.net TXT 220.127.116.11 * > * > AS1104.aut-num.ripe.net TXT 18.104.22.168 * > * > AS1104.aut-num.ripe.net TXT 22.214.171.124 * > * > AS1104.aut-num.ripe.net TXT 126.96.36.199 * > * > AS1104.aut-num.ripe.net TXT 188.8.131.52 * > * ... * > * I'm not sure of what a solution to this problem should be, however, o * r * > * whether we just ignore the problem. * > * > That was my feeling too. If people like the idea and we can reliably use * > it for the update procedure then I'll just make sure we either make * > "warning" documentation to use TCP based queries or we put up a good * > resolver. * * I've given this some further thought, and a possibility could be to do it * like this: * * $origin as224.aut-num.ripe.net. * @ IN SOA ... * ; * @ NS ... * @ NS ... * ; * 1 A 184.108.40.206 * 2 A 220.127.116.11 * 3 A 18.104.22.168 * 4 A 22.214.171.124 * ; * * etc. * Hmm... Don't like this too much either sorry. I agree about the labels are immaterial but doesn't really get round the main thing which in my opinion is listing the nets. * Since you are primarily concerned with the value parts of the RRs in the * zone, the labels you use to identify each individual entry is of lesser * concern. This avoids the problem of truncated UDP response packets, but * also removes the possibility to retrieve the network list by using a single * DNS query (over TCP). Instead, one have to use a zone transfer to * accomplish the same task. * * I'm not sure this is a desireable solution... I think the technically more * correct thing would be to deploy/distribute (contribute to BIND) a better * resolver library but it will take a while for it to be widely distributed * (eg. via vendors). * I agree. Anyone know if this will happen in 4.9 or not ? On this whole subject. It appers that from the repsonses I've had the general feeling is not to do the update procedure this way. We will use the standard "centralised" type mechanism based on logins and guarded files and not persure this any further. However as part of this whole idea I plan to leave the ability to list all the nets from the DNS so will generate network lists based on AS so at least the functionality is there for those who want to make use of it. --Tony.
[ dns-wg Archives ]