Re: NOTIFY and TSIG

2024-01-08 Thread Mark Andrews
You use TSIG when transferring a zone to ensure you are talking to a valid primary. Spoofed NOTIFY messages where accounted for when NOTIFY was developed. The server will protect itself from spurious NOTIFY messages by rate limiting. Now if you are using views you can use TSIG to select the co

NOTIFY and TSIG

2024-01-08 Thread Nick Tait via bind-users
Hi list. I've been trying to understand whether it is necessary for the NOTIFY request (i.e. sent from primary to secondary server) to use TSIG, in the case where the secondary server specifies a key in its zone's "primaries" option? For example, assume the following set-up: The primary ser