Re: [gentoo-user] Secure DNS servers

2014-06-16 Thread Michael Orlitzky
On 06/16/2014 02:15 PM, James wrote: Hello, I'm reading up on how to secure DNS primary and secondary servers. I guess DNSSEC is pretty important. Any other areas I should read up on? It's been a few years since I admin'd a dns server The benefits of DNSSEC are debatable. We're moving

Re: [gentoo-user] Secure DNS servers

2014-06-16 Thread thegeezer
generally using something like ISC BIND you can set filters and easily create an external view and internal view, so that you can do split dns based on network connection. if doing something like this test it and then test it again to make sure there is no leak due to a typo. it would be easier

Re: [gentoo-user] Secure DNS servers

2014-06-16 Thread Rich Freeman
On Mon, Jun 16, 2014 at 2:49 PM, Michael Orlitzky m...@gentoo.org wrote: The benefits of DNSSEC are debatable. We're moving the centralized trust from one group of scumbags (the CAs) to another group of scumbags (the registrars). So the benefits to authentication are not entirely clear-cut.