max-transfer-time-out ?

Mark.Andrews at nominum.com Mark.Andrews at nominum.com
Thu Feb 10 23:45:04 UTC 2000


> Hello,
> 
> would it be wise to have a "max-transfer-time-out" option ?
> 
> It seems such a setting is missing (but perhaps, of course,
> the named might have a built-in limit ?).
> 
> The motivation is that by not setting an upper limit to the
> time it may take for a transfer to take place, the named puts
> some "trust" on the proper behaving of the partner asking for
> the transfer.
> Without a time-limit, what are the defenses of named against
> a program that opens, but never reads, from possibly numerous
> tcp connections for zone transfers.

	BIND treats TCP sockets as a scarce resource and will
	free ones when needed.  The one choosen is based on a
	number of factors.

	Mark
> 
> Greetings,
> 
> Marc Lampo
> 
> 
> Sent via Deja.com http://www.deja.com/
> Before you buy.
> 
> 
--
Mark Andrews, Nominum Inc. / Internet Software Consortium
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark.Andrews at nominum.com



More information about the bind-users mailing list