Yo Hal!

On Mon, 04 Mar 2019 12:58:14 -0800
Hal Murray via devel <devel@ntpsec.org> wrote:

> rlaa...@wiktel.com said:
> > CNAMEs don't really help. Certificate validation uses the original
> > name anyway.  
> 
> I was assuming we could intercept the CNAME and use that for
> certificate validation.  Maybe I should have said SRV or TXT or ???

The name in ntp.conf MUST match the name in the cert.  Unless you
override it ("noval", pin, etc.).

> The normal  getaddrinfo and friends automatically follow CNAMEs.
> Thus my comment about needing some DNS code.

Which opens a big fat back door.

RGDS
GARY
---------------------------------------------------------------------------
Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97703
        g...@rellim.com  Tel:+1 541 382 8588

            Veritas liberabit vos. -- Quid est veritas?
    "If you can’t measure it, you can’t improve it." - Lord Kelvin

Attachment: pgph0RaJlg_b6.pgp
Description: OpenPGP digital signature

_______________________________________________
devel mailing list
devel@ntpsec.org
http://lists.ntpsec.org/mailman/listinfo/devel

Reply via email to