Using DynDNS names in authorized_keys

From: Gregor Hoffleit (gregor_at_hoffleit.de)
Date: 11/25/03


Date: Tue, 25 Nov 2003 14:18:52 +0100

Appearently checks in authorized_keys involving dynamic DNS names fail:

    from="niksula.dyndns.org" 1024 35 23...2334 ylo@niksula

As far as I can see, sshd doesn't check if "niksula.dyndns.org" maps to
the IP address of the connection. Instead it does a reverse name
resolution of the IP address of the connection, and since that points to
a name in the ISP's zone, the from test fails.

This behavior sounds reasonably secure.

Anyway, is there some other way to add an additional layer of security
using dynamic DNS addresses?

Regards,
    Gregor



Relevant Pages

  • Re: DC Redundancy Not Working...?
    ... with no FAIL or WARN messages. ... Starting test: OutboundSecureChannels ... The connection was aborted by the remote WINS. ...
    (microsoft.public.windows.server.general)
  • Re: Problem with gethostbyname
    ... WiFi) then the program exits which is undesirable. ... while and then tries again until the connection is available again. ... once a call has failed all subsequent calls fail until the ... I would be very surprised if it gethostbyname() that is causing the program ...
    (uk.comp.os.linux)
  • Re: How can I tell when a remote TCP connection is closed?
    ... recv won't fail - it will return zero bytes read for graceful ... Microsoft MVP, MCSD ... >> I have a client with a TCP connection to a server. ... >> The remote end is doing a shutdown and close on the socket. ...
    (microsoft.public.win32.programmer.networks)
  • Re: connectivity redundancy setup question
    ... > The issue wasn't if the box fails just the connection. ... fail then a PC. ... >> internal interface and have the backup machine take it over ... box and connect both the broadband and POTS modems to it. ...
    (alt.os.linux)
  • Re: Broadband internet connection
    ... connection with the same UID and password - again it fails because of UID ... Pasting user ID's and passwords can sometimes fail. ... box, login would fail. ...
    (microsoft.public.windowsxp.network_web)