From owner-freebsd-stable Mon Jan 27 9:44: 0 2003 Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DACA537B401 for ; Mon, 27 Jan 2003 09:43:58 -0800 (PST) Received: from gicco.homeip.net (dclient80-218-75-162.hispeed.ch [80.218.75.162]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6D1F343F13 for ; Mon, 27 Jan 2003 09:43:57 -0800 (PST) (envelope-from hampi@rootshell.be) Received: from localhost.here (idefix@gicco.homeip.net [127.0.0.1]) by gicco.homeip.net (8.12.6/8.12.6) with ESMTP id h0RHhq9c001973 for ; Mon, 27 Jan 2003 18:43:53 +0100 (CET) (envelope-from hampi@rootshell.be) Received: (from idefix@localhost) by localhost.here (8.12.6/8.12.6/Submit) id h0RHhpC7001972 for freebsd-stable@FreeBSD.ORG; Mon, 27 Jan 2003 18:43:51 +0100 (CET) X-Authentication-Warning: localhost.here: idefix set sender to hampi@rootshell.be using -f Date: Mon, 27 Jan 2003 18:43:51 +0100 From: Hanspeter Roth To: freebsd-stable@FreeBSD.ORG Subject: Re: 4.7-R-p3: j.root-servers.net Message-ID: <20030127174351.GA1740@gicco.homeip.net> Reply-To: freebsd-stable@FreeBSD.ORG Mail-Followup-To: freebsd-stable@FreeBSD.ORG References: <20030126130837.GA399@gicco.homeip.net> <20030126224956.K27492-100000@voo.doo.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20030126224956.K27492-100000@voo.doo.net> User-Agent: Mutt/1.4i Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Jan 26 at 23:48, Marc Schneiders spoke: > A more permanent solution is to run secondary for root. This has Hm, this is an interesting idea. > several advantages. One being speed. The root data will be on your > machine and automatically refreshed every 30 minutes (only when there > are changes, so no useless traffic) by AXFR. If there is another DDoS But if everybody does this the root servers will probably be much more loaded, won't they? So it's probably only for `privileged' users? > attack on the root-servers, you won't suffer from it, for you have the > data yourself. And they don't change much. If root is handled in hint mode I shouldn't suffer too much anyway? > If you care for alternative, extra domains, you replace the IP > numbers indicated by ORSC root-servers (that allow AXFR) and you put What is ORSC? Is it's data identical with the one from the NET servers? Or das it have more or different data? Is it where the hijacks (dns-spoofs) come from? -Hanspeter To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message