Re: [DNSOP] Localhost entries in zones

Edward Lewis <Ed.Lewis@neustar.biz> Thu, 03 April 2008 14:52 UTC

Return-Path: <dnsop-bounces@ietf.org>
X-Original-To: dnsop-archive@optimus.ietf.org
Delivered-To: ietfarch-dnsop-archive@core3.amsl.com
Received: from core3.amsl.com (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 26AC428C6AA; Thu, 3 Apr 2008 07:52:14 -0700 (PDT)
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8D94628C54C for <dnsop@core3.amsl.com>; Thu, 3 Apr 2008 07:52:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.424
X-Spam-Level:
X-Spam-Status: No, score=-2.424 tagged_above=-999 required=5 tests=[AWL=0.175, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 663bKuJsUmOb for <dnsop@core3.amsl.com>; Thu, 3 Apr 2008 07:52:11 -0700 (PDT)
Received: from ogud.com (hlid.ogud.com [66.92.146.160]) by core3.amsl.com (Postfix) with ESMTP id 23EAB28C6CD for <dnsop@ietf.org>; Thu, 3 Apr 2008 07:52:10 -0700 (PDT)
Received: from [0.0.0.0] (mail.md.ogud.com [10.20.30.6]) by ogud.com (8.13.1/8.13.1) with ESMTP id m33Epw4w022338; Thu, 3 Apr 2008 10:52:05 -0400 (EDT) (envelope-from Ed.Lewis@neustar.biz)
Mime-Version: 1.0
Message-Id: <a06240803c41a9d2e8268@[0.0.0.0]>
In-Reply-To: <B33086268D53A0429A3AA2774C83892C028E15A8@KAEVS1.SIDN.local>
References: <B33086268D53A0429A3AA2774C83892C028E15A8@KAEVS1.SIDN.local>
Date: Thu, 03 Apr 2008 10:48:45 -0400
To: Antoin Verschuren <Antoin.Verschuren@sidn.nl>
From: Edward Lewis <Ed.Lewis@neustar.biz>
X-Scanned-By: MIMEDefang 2.63 on 10.20.30.6
Cc: dnsop@ietf.org
Subject: Re: [DNSOP] Localhost entries in zones
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: dnsop-bounces@ietf.org
Errors-To: dnsop-bounces@ietf.org

At 12:19 +0200 4/3/08, Antoin Verschuren wrote:
>Hi,
>
>I may have missed this, but I'd like to hear the lists opinion about
>this article:
>http://seclists.org/bugtraq/2008/Jan/0270.html
>that states that localhost entries in zones should be discouraged.

My problem with that doc is it says "uh, don't operate DNS servers if 
you make mistakes."  Well, I am referring to the problem of 
"localhost A 127.0.0.1" not having the trailing (FQDN) dot which 
opens the doors to problems.

Here are two rules to combat this:

1) Okay, no one forget the dot, OK?
2) Unless. you. put. dots. after. every. word. for. a. week., you. 
are. prevented. from. ever. typing. named. .

>I know that localhost entries were encouraged in RFC 1537 but that one
>is obsolted by RFC 1912 which doesn't say anything anymore about
>localhost entries, so no encouragement nor disencouragement.
>I think that if localhost entries in zones should be discouraged, it
>should come from the consensus of this WG.

OTOH, I have in the past been religious about including 
localhost(dot) in both the forward and reverse zones of my servers. 
But I don't go to church anymore.  I forget why I dropped the 
practice, I mean putting in the localhost(dot), not the church thing, 
but I know I wasn't happy with it.

Thinking, thinking, no, can't recall the reason now.  Maybe with time 
and discussion I will.
-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis                                                +1-571-434-5468
NeuStar

Never confuse activity with progress.  Activity pays more.
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop