Re: dns-sec and Maintaining Human Sanity

2010-08-08 Thread Dave Knight
On 2010-08-06, at 6:36 PM, Tony Finch wrote: > > OpenDNSSEC predates BIND's auto-signing functionality, so it has become > partly obsolete - but not completely. OpenDNSSEC is far from obsolete, it's in active development [1] and is being used for some important zones [2]. dave [1] http://ww

Re: Protecting bind from DNS cache poisoning!!!

2010-08-08 Thread Matthew Seaman
On 08/08/2010 11:29:52, Shiva Raman wrote: >I am running Bind caching and bind authoritative servers with current > 9.7 version. I would like > to know the steps to be followed to protect bind from DNS Cache poisoning. > The bind DNS server > is running behind the firewall which allows onl

Protecting bind from DNS cache poisoning!!!

2010-08-08 Thread Shiva Raman
Dear All I am running Bind caching and bind authoritative servers with current 9.7 version. I would like to know the steps to be followed to protect bind from DNS Cache poisoning. The bind DNS server is running behind the firewall which allows only DNS queries . kindly share your views.