regex 'fun'

Alexander Clouter alex at digriz.org.uk
Thu Nov 5 16:12:17 CET 2009


Alan DeKok <aland at deployingradius.com> wrote:
>
> Alexander Clouter wrote:
>
>> What I was touting privately to Alan involved maintaining a zone file, 
>> akin to what you promoted in you dyndiscovery draft[1] but for for a 
>> custom 'root' server list.
> 
> If Stefan is talking about a repository with certs && CRL's, adding 
> routing information wouldn't be that hard.  i.e. "upstream for foo.edu 
> is bar.com".  That addresses a lot of the multi-hop issues that DNS 
> just can't solve.
>
With a twist it could if I understand the problem correctly.  Along side 
the SRV records you would have to add 'reverse hop' records and follow 
the chain till the proxy discovers its-self; discover the route path in 
order from destination to sender.  However I am guessing this would be 
error prone and of course required *everyone* in eduroam adding suitable 
'reverse hop' records to their realm; easily monitorable mind you.

Cheers

-- 
Alexander Clouter
.sigmonster says: Everyone hates me because I'm paranoid.




More information about the Freeradius-Users mailing list