[bind10-dev] NS/NSEC3/DNAME at wildcard

Jerry Scharf scharf at isc.org
Sat Feb 5 18:01:29 UTC 2011


Jinmei,

How would this work with zone data in a data source that allows 
incremental updates? If I try to add the wildcard RRs as you describe, 
would the sever reject them? What if someone decides to modify the data 
source externally and the server discovers the wildcards?

I realize this is more general that the specific wildcard problem.

warmly,
jerry


On 2/4/2011 2:31 PM, JINMEI Tatuya / 神明達哉 wrote:
> At Fri, 4 Feb 2011 20:46:54 +0100,
> Peter Koch<pk at DENIC.DE>  wrote:
>
> First, this point:
>
>> {btw, woul "reject" mean to reject/ignore the RRSet or the whole zone?}
>
> It means rejecting the whole zone to be loaded if it includes a
> wildcard name with the RRs in question:
>
> dns_master_load: jinmei.zone:55: *.nswild.jinmei.org: invalid NS owner name (wildcard)
> zone jinmei.org/IN: loading from master file jinmei.zone failed: invalid NS owner name (wildcard)
> zone jinmei.org/IN: not loaded due to errors
>



More information about the bind10-dev mailing list