Re: rpz fail

2019-08-27 Thread Lee
On 8/27/19, Tony Finch wrote: > Lee wrote: >> >> Can someone please explain why using this as my rpz zone does NOT >> block everything for *.2o7.net? >> >> 2o7.net CNAME . >> *.2o7.net CNAME . >> bcbsks.com.102.112.2o7.net CNAME . > > I suspect this is RPZ obeying the weird semantics of DNS wildc

Re: rpz fail

2019-08-27 Thread Tony Finch
Lee wrote: > > Can someone please explain why using this as my rpz zone does NOT > block everything for *.2o7.net? > > 2o7.net CNAME . > *.2o7.net CNAME . > bcbsks.com.102.112.2o7.net CNAME . I suspect this is RPZ obeying the weird semantics of DNS wildcard matching. The * only matches if the ans

rpz fail

2019-08-24 Thread Lee
tl,dr: https://github.com/StevenBlack/hosts/issues/451 Can someone please explain why using this as my rpz zone does NOT block everything for *.2o7.net? $ cat db.test-rpz $ORIGIN rpz.test. $TTL1s @ IN SOA localhost. admin ( 2019082405 6h 15 1d 1s ) IN NS localhost. 2o7.net CNAME . *.2o7.n