issues with mcd.com DNS

Barry Margolin barry.margolin at level3.com
Tue Oct 14 14:28:07 UTC 2003


In article <bmffnc$1hb0$1 at sf1.isc.org>, Dave Lugo  <dlugo at etherboy.com> wrote:
>Mark_Andrews at isc.org wrote:
>
>> 
>> 
>> 	ns.mcdkorea.co.kr only has glue.  According to the zone it
>> 	does not exist.   Once the cache learns that ns.mcdkorea.co.kr
>> 	doesn't exist lookups will fail.
>> 
>
>
>But the catch already has a good answer cached, and a dig done against 
>the cache (run on the same box as the cache) succeeds, while a dig from 
>the same/24 as the cache, against the same cache, fails.  If what you 
>say is correct, I would (with my admittedly junior knowledge of DNS 
>compared to you) expect both digs to fail.

The answer it has cached was glue record from the parent zone, which
doesn't have as much credibility as records from the authoritative server
for the zone itself.  I believe that the glue record is only used for the
first query, after which it queries the authoritative server for the
address.  When that server says that the name doesn't exist, the cached A
record is replaced with a negative cache entry.

-- 
Barry Margolin, barry.margolin at level3.com
Level(3), Woburn, MA
*** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups.
Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.


More information about the bind-users mailing list