Subject: Re: IPv6 stuff
To: Ken Hornstein <kenh@cmf.nrl.navy.mil>
From: Stephen Degler <sdegler@degler.net>
List: current-users
Date: 01/15/2002 23:45:29
On Tue, Jan 15, 2002 at 11:22:45PM -0500, Ken Hornstein wrote:
> >I'm using the statless autoconfig.  And like the other responder, I'm
> >pushing the values into DNS manually.  It would be nice to have some
> >hook to run nsupdate though.  This could be done in /etc/rc.d.
> >And you would have to have dynamic updates on in DNS.
> 
> Maybe I'm just paranoid ... but the idea of dynamic updates to DNS has
> always scared the hell outta me.
> 
> --Ken

If you trust TSIG and the machines that you allow to update, then you can
trust dynamic updates.  Yes, there are issues, no doubt.  Compare this to
the failure rate of entering v6 reverse addresses by hand :-).

The biggest problem is getting used to the idea of using nsupdate for
everything.  No zone file edits anymore.

skd