-
Notifications
You must be signed in to change notification settings - Fork 921
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature-Request: allow-notify-from as per-zone setting #8816
Comments
This is a serious question: why not? |
It's one way (of many) to start a DoS attack against DNS servers. Another technically reason is the management of allowed notify ips. If you have thousands domains in one instance you will also have thousand different notify source ips. It's difficult to managed this in only one option. The feature is already implemented globally. So I hope we haven't discuss the sense of the feature itself. |
This does not make sense. If this is true, you already had way bigger problems.
But I like this reason. I have put your request in the 'auth-helpneeded' milestone, which means that we think it's a decent idea, but will not put it on the roadmap for now. If somebody submits a good patch for it, we will merge it. |
+1 |
Short description
There is a global setting for allow-notify-from in authoritative server settings. But it's not available as per-domain setting in domain metadata.
Please implement it there, too. So it should be consistent with allow-axfr-ips (global) / allow-axfr-from (per-zone)
Usecase
Some special dns setups use different servers / source ips for notifies and axfr. Currently the only way to allow this scenario is to configure the notify IPs globally. But so they could send notifies for all configured domains.
In multi-tenant / shared environments you wouldn't allow an other tenant to notify domains eachother. ;)
Description
It's so simple to explain. See above. :)
The text was updated successfully, but these errors were encountered: