Yo Hal! On Mon, 04 Mar 2019 12:58:14 -0800 Hal Murray via devel <devel@ntpsec.org> wrote:
> rlaa...@wiktel.com said: > > CNAMEs don't really help. Certificate validation uses the original > > name anyway. > > I was assuming we could intercept the CNAME and use that for > certificate validation. Maybe I should have said SRV or TXT or ??? The name in ntp.conf MUST match the name in the cert. Unless you override it ("noval", pin, etc.). > The normal getaddrinfo and friends automatically follow CNAMEs. > Thus my comment about needing some DNS code. Which opens a big fat back door. RGDS GARY --------------------------------------------------------------------------- Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97703 g...@rellim.com Tel:+1 541 382 8588 Veritas liberabit vos. -- Quid est veritas? "If you can’t measure it, you can’t improve it." - Lord Kelvin
pgph0RaJlg_b6.pgp
Description: OpenPGP digital signature
_______________________________________________ devel mailing list devel@ntpsec.org http://lists.ntpsec.org/mailman/listinfo/devel