[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IPv6 and Dynamic DNS



 In your previous mail you wrote:

   >(In fact, if a DNS server receives a dynamic update for a reverse
   >entry, and it can verify that the pointed-to forward entry matches,
   >and the source address of the reverse entry is the address being
   >updated, it could consider making the update.  What can we do to improve
   >this model so it need not trust the source address of the update packet?)
   
   This is a question I can understand.  Exactly.  We have ddns working for
   both AAAA and PTR records from IPv6 addrconf.  The issue is for my
   customers how is that made to be secure.  What you ask is exactly what
   we need to solve.
   
=> I have in my TODO list the same kind of tools (ie. something which
updates AAAA & PTR RRs from IPv6 addrconf/neighbor discovery).
Of course we have the same problem and the current proposed solution
is to use TSIG, the future solution is to provide this service via DHCPv6.

Regards

Francis.Dupont@inria.fr