North American Network Operators Group Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical Re: [dnsop] DNS Anycast revisited (fwd)
On 4 May 2005, at 09:52, Edward B. Dreger wrote: Actually, the obvious answer is to use TSIG instead of address-based ACLs to authenticate zone transfers. But in cases where that's not possible (because the master servers don't want to implement it, and insist on address-based ACLs), there are hacks available. See http://www.isc.org/pubs/tn/isc-tn-2004-1.html#anchor14 for an example. Joe
|