Re: Advice - solution for a company server

From: Imhotep (Imhotep_at_nospam.net)
Date: 09/29/05


Date: Thu, 29 Sep 2005 01:14:36 -0400

Steven L Umbach wrote:

> For an AD domain there is no advantage in cost to use Bind and it would
> actually add the cost of another server to run on. Windows DNS,
> particularly for Windows 2003, has shown to be very robust. Bind can not
> use Active Directory integrated dns zones which use multimaster
> replication which is a huge plus where dynamic dns is used and it also
> makes sense to run DNS on domain controllers for performance reasons.

Multimaster DNS replications is proprietary!!!!

> The
> SANS top 20 vulnerabilities does not even mention DNS for Windows while
> Bind is number one for Unix vulnerabilities though recent versions of Bind
> have proven to be secure so far as Windows 2003 DNS has.

Now hold on if we are going to go back to old versions there are just as
many in MS DNS!

> The latest
> versions of Bind would be the choice
> for DNS servers on the internet. --- Steve

Ask yourself why all the root DNS servers are BIND and not Windows. How many
times have those few (12 or so?) servers withstood multi-country DDOS
attacks!!!

Again, the choice is clear. OpenLDAP with Bind DNS...

Im



Relevant Pages

  • Re: Restrict Dynamic Updates
    ... in the near future from the Windows platform is Windows ... BIND/DNS servers to resolve all non-AD queries and redirect them to ... the AD/DNS servers only for AD-specific queries, allowing the BIND ... ISP/external DNS servers. ...
    (microsoft.public.windows.server.dns)
  • [UNIX] Multiple Remote Vulnerabilities in BIND4 and BIND8
    ... ISS X-Force has discovered several serious vulnerabilities in the Berkeley ... Internet Name Domain Server (BIND). ... majority of DNS servers on the Internet. ... deployed recursive DNS servers on the Internet. ...
    (Securiteam)
  • Re: Windows (XP und 2003) als dhcp Client mit ddns
    ... >>Wenn Du den DHCP auch unter Windows einrichtest,... ... > sein soll dann werde ich schnell den DNS ... Der Bind unter Linux erlaubt Dir dynamische ... Damit die Windows-Clients sich im Bind direkt selbst eintragen ...
    (microsoft.public.de.german.windows.server.networking)
  • RE: Sites and Services
    ... >> same as our existing Bind DNS name. ... Our Windows DNS servers then transfer the zones to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Advice - solution for a company server
    ... For an AD domain there is no advantage in cost to use Bind and it would ... Windows DNS, particularly ... for Windows 2003, has shown to be very robust. ... Bind can not use Active ...
    (microsoft.public.security)