CNAME and Other Data (olympusgroove.com)

Kerry Thompson kerry at security.geek.nz
Wed Feb 9 18:24:37 UTC 2005


Don Lehman said:
> Hi All,
>
> I just noticed that "olympusgroove.com" is returning a CNAME to
> "wip.olympusgroove.com".  The RFCs say this isn't allowed (since they
> need an NS record and SOA record for the zone). and I've always advised
> others that this will not work. Well, they are doing it and it seems to
> be working? Are there things that are not working? How do I continue to
> recommend against this?
>

It works because many clients are quite tolerant to this behaviour. You
should recommend against it because it may not work on some clients, and
if the tolerant clients become more strict in following the RFC they may
also stop working.

olympusgroove.com has a few issues, see its DNS Report at
http://dnsreport.com/tools/dnsreport.ch?domain=olympusgroove.com

-- 
Kerry Thompson
IT Security Consultant
http://www.crypt.gen.nz



More information about the bind-users mailing list