Re: inetd.conf security

From: Toomas Soome (Toomas.Soome_at_microlink.ee)
Date: 10/06/04


Date: Wed, 06 Oct 2004 17:16:20 +0300

Frank Cusack wrote:

> Agreed on both points, however nscd introduces its own problems w.r.t.
> host resolution. One no one has yet mentioned is that it doesn't
> honor TTL. This was a "dumb" implementation choice (and dumb of Linux
> to copy) although I understand the value of simple. This is such an
> issue at every place I've ever been that nscd for hostname caching is
> always a no-no. If we need hostnames to be cached we run a local
> caching nameserver.

man nscd.conf:

   positive-time-to-live cachename value
   negative-time-to-live cachename value

ok, this is not related to DNS TTL, but it's still there, you can set
short ttl for hosts/ipnodes and still rely on your named for dns TTL
handling. reading manual is sometimes useful...

toomas

-- 
Tomorrow will be cancelled due to lack of interest.


Relevant Pages

  • Re: inetd.conf security
    ... Frank Cusack wrote: ... > host resolution. ... > issue at every place I've ever been that nscd for hostname caching is ... short ttl for hosts/ipnodes and still rely on your named for dns TTL ...
    (comp.unix.solaris)
  • Re: inetd.conf security
    ... Frank Cusack wrote: ... > host resolution. ... > issue at every place I've ever been that nscd for hostname caching is ... short ttl for hosts/ipnodes and still rely on your named for dns TTL ...
    (comp.sys.sun.admin)
  • Re: inetd.conf security
    ... Frank Cusack wrote: ... > host resolution. ... > issue at every place I've ever been that nscd for hostname caching is ... short ttl for hosts/ipnodes and still rely on your named for dns TTL ...
    (comp.unix.admin)
  • Re: inetd.conf security
    ... however nscd introduces its own problems w.r.t. ... >> host resolution. ... >> caching nameserver. ... > short ttl for hosts/ipnodes and still rely on your named for dns TTL ...
    (comp.unix.solaris)
  • Re: inetd.conf security
    ... however nscd introduces its own problems w.r.t. ... >> host resolution. ... >> caching nameserver. ... > short ttl for hosts/ipnodes and still rely on your named for dns TTL ...
    (comp.sys.sun.admin)

Quantcast