Re: CVS commit: src/etc/rc.d

On Sat, 8 Aug 2009 19:23:38 +0200
Alan Barrett <> wrote:

> On Sat, 08 Aug 2009, Tonnerre LOMBARD wrote:
> > I don't think any sysadmin in the right mind would put _solely_ the
> > local host into that file.
> It has been my practice for may years to have "" as the only
> nameserver in /etc/resolv.conf.  I highly recommend this practice.
> If I am behind a broken firewall or DNS interceptor, then I put
> the addresses DHCP told me about into "forwarders" in named.conf,
> not into resolv.conf.
That is *precisely* what I do.

Apart from anything else, last time I looked our resolver library
(unlike OpenBSD's) did not notice if resolv.conf changed; thus, on
laptops that move to different locations, standing applications would
get confused.  Running a local named is the easiest bypass.

                --Steve Bellovin,

