tech-userlevel archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: CVS commit: src/etc/rc.d



Tonnerre LOMBARD <tonnerre%netbsd.ch@localhost> writes:
> On Sat, Aug 08, 2009 at 03:29:34PM -0400, Perry E. Metzger wrote:
>> > Ok, let's talk security then. What do you think your dnssec signature
>> > generator is going to do if named is started before ntpd?
>> 
>> So don't do that.
>
> Don't do what?

Don't do the DNS signature generation at the same moment that you bring
up the name server to provide resolution services locally. There is no
reason that you have to do things that way (and in fact, there are a lot
of reasons not to.) BTW, I don't believe our current scripts are set up
to do that anyway, so this is moot.

Perry
-- 
Perry E. Metzger                perry%piermont.com@localhost


Home | Main Index | Thread Index | Old Index