|
|||||||||||
|
[Design] Re: lookup of self-TXT/KEY
From: D. Hugh Redelmeier <hugh(at)mimosa.com>
Date: Mon Mar 10 2003 - 15:12:27 EST
| DHR, 1) do you require that you find both the TXT and the KEY record for
The intent is that Pluto will only initiate OE if it can see sufficient credentials in DNS for the other side to respond. For an initiation on behalf of itself, a KEY is sufficient. For an initiation on behalf of a client behind, TXT is required and, if the TXT does not contain the public key, a KEY is also required.
| 2) is there a way to override this?
Not currently.
| 3) Will it retry?
No. This is part of a general (planned to be fixed) lack of retrying.
| The problem that I get is that the DNS query to lookup self may itself
Remember that there is a single thread of queries currently. So the initial queries will fail in a predictable order. Blast a hole to a nice DNS *first* (a lame workaround, not a solution). The other side will probably have a go at OE if it is configured suitably. So all is not lost.
Hugh Redelmeier
-----BEGIN PGP SIGNATURE-----
iQCVAwUBPmzxssFAuQPManGZAQFxTwQArOvNJPP3dJsHXwL+6m0qKb5NsJdLG+Re
hY4hAFm18p7Y4z4fBvjeoH+zWzeJkK3VeyvYDFCokevNnHrz5vbSEL8XTZrO+IH+
g6m1tulvQJpPMIk9OhrjDqZhpnr+k4iuANoAreEre8nBMf+0dUruRnxPl4ItBBBT
1tnUD7O4K3Q=
Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Tue Mar 11 19:34:24 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT |
||||||||||
|
|||||||||||