On Thu, 4 Jun 2009, Adam Katz wrote:

John Hardin wrote:
I think what Matus was saying is:
181.188.252.222.in-addr.arpa -> "localhost" -> 127.0.0.1 = FAIL.

And what I'm saying is that the second step of that:
"localhost" -> 127.0.0.1
doesn't work since "localhost" has no A record.

So that data comes from /etc/hosts. How does that materially affect the FCrDNS sanity test?

So it should actually go:
181.188.252.222.in-addr.arpa -> "localhost" -> FAIL
and I'm not sure if that result nulls the equation or if it actually
outputs an FCrDNS failure.  My guess is that it does.  YMMV by MTA.

You're treating "localhost" as a special case of FCrDNS. While that's reasonable, you shouldn't have to do that. If you don't have "localhost" in the /etc/hosts file on a production machine you shouldn't be an admin... (<-- sweeping generalization, I know.)

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 jhar...@impsec.org    FALaholic #11174     pgpk -a jhar...@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  When I say "I don't want the government to do X", do not
  automatically assume that means I don't want X to happen.
-----------------------------------------------------------------------
 2 days until the 65th anniversary of D-Day

Reply via email to