[Pdns-users] Verisign bullshit

bert hubert ahu at ds9a.nl
Tue Sep 16 06:30:13 UTC 2003


On Mon, Sep 15, 2003 at 08:23:59PM -0700, Ian R. Justman wrote:

> Curious, is there a way that the recursor (or really, ANY nameserver for 
> that matter) can be set up so then it doesn't query any rootservers that 
> Verisign doesn't control?  As you all may know, these assholes are now 
> resolving for EACH AND EVERY GODDAMNED DOMAIN NAME THAT DOESN'T EXIST.

It's not that simple. The only way so far to recognize their bogus answers
is by IP address. They control the GTLD servers and all GTLD servers now
show this behaviour. You can't easily do without, except by downloading the
.COM and .NET source yourself.

I'll add a feature to pdns to ignore answers containing a specified IP
address, which will effectively make this go away.

Thanks.

-- 
http://www.PowerDNS.com      Open source, database driven DNS Software 
http://lartc.org           Linux Advanced Routing & Traffic Control HOWTO


More information about the Pdns-users mailing list