Interesting behavior with wildcard domains

Mark Andrews marka at isc.org
Tue Feb 23 23:30:18 UTC 2016


In message <E7385EF3-1128-4F81-87FD-EF5CB55ED92B at nau.edu>, Mathew Ian Eis write
s:
Illegal character '-' in input file.
> Hi BIND,
>
> Ive encountered (quite by accident) an interesting behavior in BIND with
> wildcard domains:
>
> The relevant configuration is a zone; e.g. bar.com, with what Ill call a
> second level wildcard host, e.g. *.foo.bar.com A 10.10.10.5 in that zone.
> (as opposed to what might be considered the more usual wildcard host
> record of *.bar.com).
>
> buz.foo.bar.com returns A 10.10.10.5 as expected.
>
> However, a query for foo.bar.com returns NOERR with zero results, when I
> would expect a NXDOMAIN.

Why?  If *.foo.bar.com exists then foo.bar.com, bar.com and com all exist.

> Anyone know if the NOERR with zero results is the expected / correct
> behavior?

It is the expected behaviour.

> Thanks in advance,
>
> Mathew Eis
> Northern Arizona University
> Information Technology Services
>


More information about the bind-users mailing list