Blocking version information

Chris Thompson cet1 at hermes.cam.ac.uk
Mon Jun 20 15:08:33 UTC 2005


On Jun 20 2005, Vinny Abello wrote:

> OK, you win. You're completely right. :)
> 
> As much as I'd like to go back and forth with this as I'm laughing 
> reading some of your responses, I simply don't have the time on or 
> off list so as it stands, Brad is correct. I withdraw all my 
> statements. Listen to him and everyone that agrees with him.
> 
> ;)

It's amazing how much heat and light is generated by what is a supremely
marginal issue.

I can't help feeling that Mr Dickinson was pulling our legs when he asked
whether it "would violate any DNS RFCs" to obscure the BIND version. 
We would need the RFC that forbids use of any nameserver software other
than BIND first. [Needs to be written for 1 April 2006, I think.]

As for best current practice, what better sample than the root nameservers?

a.root-servers.net  "VGRS2"
b.root-servers.net  "8.4.1-REL"
c.root-servers.net  "8.4.6-REL"
d.root-servers.net  "8.4.4"
e.root-servers.net  "9.2.3"
f.root-servers.net  "9.3.1"
g.root-servers.net  (returned SERVFAIL)
h.root-servers.net  "8.4.6-REL"
i.root-servers.net  "contact info at netnod.se"
j.root-servers.net  "VGRS2"
k.root-servers.net  "NSD 1.2.4"
l.root-servers.net  "named-8.4.1"
m.root-servers.net  "8.4.6-REL"

Make what you will of that...

-- 
Chris Thompson
Email: cet1 at cam.ac.uk



More information about the bind-users mailing list