February 4, 2012

Topics


Search Site

Follow

  RSS CricketonDNS   RSS Infra20

Favorite Links


Tag Cloud


Archives

Entries for month: April 2010

This Theory, That I Have, That Is to Say, Which Is Mine...

April 26 2010 by Cricket Liu (Infoblox)

 

Waaaay back when I ran hp.com, I had what I only now realize was an enviable position:  I was HP’s hostmaster (the somewhat-ceremonial title given to the person responsible for a zone) but not much else.  I dabbled in NTP and ran a big mail relay, but the bulk of my responsibility was DNS.  From when I got to work in the morning to when I left in the evening, I could concentrate on DNS.

At the time, I didn’t realize what a luxury that was.  I figured every big company probably had a person dedicated to DNS.  And in those days, some did. Partly, this was because we hostmasters could get away with it.  DNS was such a black art that you could simply assert that it took up most of your time and your management wouldn’t know any better.

How the times have changed.  I’ve had the opportunity to meet the folks responsible for DNS at many big companies, but I hesitate to call them “hostmasters”—not because they don’t deserve the customary title, but because it sells them short.  These people run routers, switches, firewalls, mail servers, and more.  Almost no one has the luxury of specializing in DNS any more.  The economic climate dictates that we all take on more responsibilities to make our employers more competitive.

 

Read more...

Posted in DNSSEC | BIND | Automation | 2 comments



Well Lookee Here, If It Isn't a Use Case!

April 12 2010 by Cricket Liu (Infoblox)

 

A few weeks ago, Mauricio Vergara Ereche, who in addition to having a very cool-sounding name works for Chile's NIC, noticed that queries to one of the root name servers were returning odd answers.  In particular, queries he sent to i.root-servers.net for domain names like www.facebook.com were being answered not with referrals to the com name servers, as you'd expect, but with an address record for www.facebook.com.  Unfortunately, that address record wasn't correct; it led nowhere.

Further probing determined that it was queries sent to the instance of i.root-servers.net in Beijing that were being answered bogusly.  And it wasn't i.root-servers.net that was behaving badly:  Kurt Erik Lindqvist, the CEO of Netnod, which helps coordinate i.root-servers.net's operation, as well as Xiaodong Lee, CTO of CNNIC, China's NIC, which hosts the Chinese i.root-servers.net, both denied having anything to do with the mischief.  Instead, the working theory is that China's government is intercepting the queries and forging the bogus responses, partly to keep ordinary Chinese citizens from Harmful Western Imperialist Influences like Facebook (and of course FarmVille).

 

Read more...

Posted in DNSSEC | 2 comments