Speaker
Peter Thomassen
(deSEC)
Description
Typically, ns1.example.net and ns2.example.org have two different IP addresses mapped 1:1. It's conceivable to provision A/AAAA records with both IP addresses for both hostnames (2:2 mapping, or even n-to-n), allowing resolvers to obtain all nameserver IP addresses even when a hostname isn't resolvable during an incident. This talk is about:
- What do current specs say about this?
- How common is this in the wild? (A measurement will be shown.)
- Is this safe to do?
| Talk duration | 5 Minutes Lightning Talk (no Q&A) |
|---|
Primary author
Peter Thomassen
(deSEC)