LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-24-2013, 06:08 PM   #1
u2013
LQ Newbie
 
Registered: Apr 2013
Posts: 14

Rep: Reputation: Disabled
"'./ANY/IN'" means what? Does a reply get sent back to the query?


Moderator, or anyone else, I got two important questions please. Well, at least important to me.

1. Does a reply message get sent back to the requester about the denial or rejection? I refer to when there is a "named[21729]: client 9.10.11.12#39948: query (cache) './ANY/IN' denied", then is there also an associated reply sent back by the queried dns server to the machine that is doing the querying?

2. What does the "'./ANY/IN'" mean, or what is the query being done on? There is no domain name indicated, and so what is being queried when just a dot "."?
 
Old 04-25-2013, 12:20 PM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,168
Blog Entries: 1

Rep: Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038Reputation: 2038
Quote:
Originally Posted by u2013 View Post
Moderator, or anyone else, I got two important questions please. Well, at least important to me.

1. Does a reply message get sent back to the requester about the denial or rejection? I refer to when there is a "named[21729]: client 9.10.11.12#39948: query (cache) './ANY/IN' denied", then is there also an associated reply sent back by the queried dns server to the machine that is doing the querying?

2. What does the "'./ANY/IN'" mean, or what is the query being done on? There is no domain name indicated, and so what is being queried when just a dot "."?
1. Of course. The client gets a REFUSED answer
2. Means that the client asks for the . (hint) zone

PS. Since you're new here, next time start a new thread instead of hijacking another one's thread

Regards
 
Old 04-25-2013, 01:01 PM   #3
u2013
LQ Newbie
 
Registered: Apr 2013
Posts: 14

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by bathory View Post
1. Of course. The client gets a REFUSED answer
2. Means that the client asks for the . (hint) zone

PS. Since you're new here, next time start a new thread instead of hijacking another one's thread

Regards
Thanks for the reply.

1. Sorry, but no, I don't believe it is a "of course". While I was waiting, I did two minor tests. A REFUSED message getting sent back depends on the version of bind installed. A little older version in fact simply did not reply, or maybe it is the settings. The client message display upon query was definitely different. One was REFUSED, as you indicated, and the other was a No Response.

So, this brings me to the question.
Is there a way to configure the DNS to not send a reply back of REFUSED?
I again reference the same data sample posted above by the user that started the post.

2. Okay, I thought it maybe something like. So in his example, it is asking for the root list. I confirmed this is how it is indicated in a DNS bind/named configuration file. He has properly disabled recursive. Does it make sense for him to not provide out hints either? If yes, how?

3. If the recursive was only limited to his localnet, then what effect would adding "additional-from-cache no;" into his configuration file accomplish, or bad idea, and why?

Again, the question is for anyone that wishes to reply.
 
Old 04-25-2013, 03:02 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by u2013 View Post
Is there a way to configure the DNS to not send a reply back of REFUSED?
That in essence would a violation of the protocol IMHO. True, inference, but it would be like denying the OpenSSH daemon to send version information required for handshaking or denying Apache to send back 404s. Not signalling a client means it does not receive any hints to back off.


Quote:
Originally Posted by u2013 View Post
Does it make sense for him to not provide out hints either?
IIGC hints are either supplied or not supplied. When they're not supplied ISC BIND uses built-in ones and only at startup to select and query one of the root servers for the current root server nfo. Not supplying hints means a client has no means to find out the root servers and continue its query there. That would only make sense inside a completely isolated network.


Quote:
Originally Posted by u2013 View Post
If the recursive was only limited to his localnet, then what effect would adding "additional-from-cache no;" into his configuration file accomplish, or bad idea, and why?
Better see something like http://www.zytrax.com/books/dns/ch7/queries.html
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Quick Reply "post reply" button. IsaacKuo LQ Suggestions & Feedback 16 07-01-2018 02:52 PM
Indie Royale "Back To School Bundle" includes "Swords and Solders" dugan Linux - News 0 09-15-2012 05:23 PM
K3b: - Howto re-dock "Directories" and "Contents" windows back into the main window? hagies Linux - Software 4 04-26-2006 08:38 AM
Adding a "Subscribe" button next to "Reply"? pnellesen LQ Suggestions & Feedback 2 06-21-2005 09:12 PM
Take all posts from "Website Suggestions & Feedback" out of the "0 Reply Thread&q t3gah LQ Suggestions & Feedback 7 03-21-2005 07:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 12:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration