Conflicting glue records?

Matus UHLAR - fantomas uhlar at fantomas.sk
Thu Jan 8 11:15:35 UTC 2009


> > On 07.01.09 19:14, Dawn Connelly wrote:
> >> Each registrars push the information that they have. So if you have
> >> apples.com with an NS record of ns1.dns.com==137.161.0.1 and
> >> oranges.com with a NS record of ns1.dns.com=137.161.0.2

> On Thu, Jan 8, 2009 at 12:31 AM, Matus UHLAR - fantomas
> <uhlar at fantomas.sk> wrote:
> > I think only the registrar of dns.com should provide glue records for
> > anything below dns.com. If it happend this way, it's imho broken.

On 08.01.09 00:41, Dawn Connelly wrote:
> Right, but his question was regarding the host record for the name
> server. You tell the registrar the name and IP address of the name
> servers that are authoritative for the domain. The registrar then
> pushes those glue records to the root servers. Root doesn't care what
> the name and/or IP address of the name servers are. They are unrelated
> across domains. There isn't any cross domain verification. If you say
> that the FQDN and IP address of the authoritative name server is
> something, the registrar believes you and tells root. Root believes
> the registrar. The registrar and root don't do a lookup on the FQDN of
> the name server that is provided- hence it being called a glue record.
> You have to manually enter that data. At least that has been the case
> with ever registrar I've dealt with.

What I was trying to say it, that both registrat and root (if possible)
should check if the glue belongs under registered domain. If not, the glue
should not be accepted.

If I register example.com, it's OK to register _anything_.example.com as
glue. However, registering _anything_.example.net should not be accepted.

I wonder how is it possible that anyone accepts that. 
-- 
Matus UHLAR - fantomas, uhlar at fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Enter any 12-digit prime number to continue.



More information about the bind-users mailing list