k.root-servers.net Changing DNS Software at on 19.2.2003
As announced previously k.root-servers.net will start running nsd 1.0.2-rel. The changeover will start at 0900UTC on Wednesday 19.2.2003. Between 0900 and 0930 all instances of K will be sequentially cut over. This way there will be no service interruption. During the cut-over period K will answer either using bind8 or nsd. After 0930 K will answer only using nsd. K will support identification of software and instance via id.server and version.server in class CHAOS as per draft-ietf-dnsop-serverid. This change is designed to increase the diversity of software in the root name server system, the lack of which is widely considered to be a potential vulnerability. The nsd software has been designed from scratch specifically as an authoritative name server. It has no design commonalities with bind, the currently prevalent DNS implementation. In addition to that nsd provides a significant increase in the performance reserve of k.root-servers.net. Please report any anomalies with k.root-servers.net service to <ops@ripe.net> as usual. nsd can be found at http://www.nlnetlabs.nl/nsd/index.html.
Daniel, Most of the root servers are also servers for the .arpa zone Does this proposed change for K as a root server also imply a change for K as a .arpa server? thanks, Geoff At 08:50 AM 2/14/2003 +0100, Daniel Karrenberg wrote:
As announced previously k.root-servers.net will start running nsd 1.0.2-rel. The changeover will start at 0900UTC on Wednesday 19.2.2003. Between 0900 and 0930 all instances of K will be sequentially cut over. This way there will be no service interruption. During the cut-over period K will answer either using bind8 or nsd. After 0930 K will answer only using nsd. K will support identification of software and instance via id.server and version.server in class CHAOS as per draft-ietf-dnsop-serverid.
This change is designed to increase the diversity of software in the root name server system, the lack of which is widely considered to be a potential vulnerability. The nsd software has been designed from scratch specifically as an authoritative name server. It has no design commonalities with bind, the currently prevalent DNS implementation. In addition to that nsd provides a significant increase in the performance reserve of k.root-servers.net.
Please report any anomalies with k.root-servers.net service to <ops@ripe.net> as usual.
nsd can be found at http://www.nlnetlabs.nl/nsd/index.html.
On 14.02 19:10, Geoff Huston wrote:
Does this proposed change for K as a root server also imply a change for K as a .arpa server?
Yes. Increased diversity for the .arpa zone at no extra cost. ;-)
participants (2)
-
Daniel Karrenberg
-
Geoff Huston