[Hipsec-rg] reverse DNS lookups of HITs
oleg.ponomarev at hiit.fi (Oleg Ponomarev) Mon, 12 January 2009 21:41 UTC
From: "oleg.ponomarev at hiit.fi"
Date: Mon, 12 Jan 2009 23:41:38 +0200
Subject: [Hipsec-rg] reverse DNS lookups of HITs
In-Reply-To: <77F357662F8BFA4CA7074B0410171B6D07B0BC78@XCH-NW-5V1.nw.nos.boeing.com>
References: <77F357662F8BFA4CA7074B0410171B6D07B0BBE5@XCH-NW-5V1.nw.nos.boeing.com> <alpine.LFD.2.00.0901071641330.12787@stargazer.pc.infrahip.net> <77F357662F8BFA4CA7074B0410171B6D07B0BC6B@XCH-NW-5V1.nw.nos.boeing.com><alpine.LFD.2.00.0901121802320.17180@stargazer.pc.infrahip.net><77F357662F8BFA4CA7074B0410171B6D07B0BC70@XCH-NW-5V1.nw.nos.boeing.com> <alpine.LFD.2.00.0901122112420.17180@stargazer.pc.infrahip.net><77F357662F8BFA4CA7074B0410171B6D07B0BC76@XCH-NW-5V1.nw.nos.boeing.com> <alpine.LFD.2.00.0901122213140.17180@stargazer.pc.infrahip.net> <77F357662F8BFA4CA7074B0410171B6D07B0BC78@XCH-NW-5V1.nw.nos.boeing.com>
Message-ID: <alpine.LFD.2.00.0901122313150.17180@stargazer.pc.infrahip.net>
Hi! On Mon, 12 Jan 2009, Henderson, Thomas R wrote: >> I guess one modern server could keep like ten million records in RAM? >> How many base exchanges can it do per second? Reverse DNS updates are >> rare anyway. >> >> When HIP gets widely deployed and there are millions of users, we might >> hope to use more resources :) > > This type of question is precisely what this research group's primary > charter is to answer, in my opinion. What are the consequences of > deploying HIP on a large scale in the Internet? If it means that we > will have a few root servers handling reverse DNS queries for all hosts, > without any aggregation, how will that architecture scale, Sure! I would like to get more precise/supported estimations and could do some experiments/benchmarks with the conventional software (which is not optimal for this usage pattern). > and how will the deployment incentives work? What are the incentives to host the root-servers (e.g. f.root-servers.net at 46 and j.root-servers.net at 52 sites)? Internet stability? Hopefully the same will work for HIP when deployed. > Or, if that turns out to be a bad idea, what are the practical > alternatives that allow someone to write domain-name-based ACLs? > > I think it would be great to gather more input on these types of > deployment questions. Actually I wonder how could I use HITs without reverse domains, I don't want to keep random hex sequences in the memory, but it is probably just my feeling. -- Regards, Oleg.
- [Hipsec-rg] meeting minutes posted Henderson, Thomas R
- [Hipsec-rg] reverse DNS lookups of HITs Henderson, Thomas R
- [Hipsec-rg] reverse DNS lookups of HITs Oleg Ponomarev
- [Hipsec-rg] reverse DNS lookups of HITs Miika Komu
- [Hipsec-rg] reverse DNS lookups of HITs Oleg Ponomarev
- [Hipsec-rg] reverse DNS lookups of HITs Andrew McGregor
- [Hipsec-rg] reverse DNS lookups of HITs Oleg Ponomarev
- [Hipsec-rg] reverse DNS lookups of HITs Andrew McGregor
- [Hipsec-rg] reverse DNS lookups of HITs Oleg Ponomarev
- [Hipsec-rg] reverse DNS lookups of HITs Xu Xiaohu
- [Hipsec-rg] reverse DNS lookups of HITs Henderson, Thomas R
- [Hipsec-rg] reverse DNS lookups of HITs Tim Shepard
- [Hipsec-rg] reverse DNS lookups of HITs Oleg Ponomarev
- [Hipsec-rg] reverse DNS lookups of HITs Henderson, Thomas R
- [Hipsec-rg] reverse DNS lookups of HITs Oleg Ponomarev
- [Hipsec-rg] reverse DNS lookups of HITs (was RE: … Henderson, Thomas R
- [Hipsec-rg] meeting minutes posted Oleg Ponomarev
- [Hipsec-rg] meeting minutes posted Henderson, Thomas R
- [Hipsec-rg] meeting minutes posted Oleg Ponomarev
- [Hipsec-rg] meeting minutes posted Henderson, Thomas R
- [Hipsec-rg] reverse DNS lookups of HITs Miika Komu
- [Hipsec-rg] meeting minutes posted Oleg Ponomarev