[Opendnssec-develop] Re: Adapter configuration

Matthijs Mekking matthijs at nlnetlabs.nl
Thu Jun 21 14:11:06 UTC 2012


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

On 05/30/2012 09:32 AM, Matthijs Mekking wrote:
> Hi Dan,
> 
> [cc'ing the OpenDNSSEC Developers]
> 
> 
> 
> On 05/25/2012 02:54 PM, Daniel Salzman wrote:
>> Hi Matthijs,
> 
>> I'm playing with ods again. It would be nice if: - Peer element 
>> needn't contain Prefix if Key is present.
> 
> I agree it would be nice to have ACL just on TSIG key.

I have fixed this in trunk (r6451), it is now possible to set an ACL
up just based on a <Key/>.

> 
>> - It doesn't depend on the order of items (Port after Key in 
>> Remote).
> 
> I agree, but I am not likely to change. This makes the XML file 
> structure complicated, and comparing to other configuration files
> it is no different: order of items is important.
> 
> We would like to have a different way to configure stuff, instead
> of using your favorite text editor.

We decided to not make the configuration unnecessary complex by
allowing all kinds of ordering.

> 
>> - ods-kaspcheck can check adapter files.
> 
> I agree, that might be useful too.

This will be likely be in the 1.4.0 or 1.4.1 too.

Please let me know how the ACL fix works for you.

Thanks,

Matthijs

> 
> 
>> Btw the link to OpenDNSSEC-1.4.0a2 doesn't work.
> 
> I believe that has been fixed a couple of days ago.
> 
> Best regards, Matthijs
> 
> 
> 
>> Regards, Dan
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJP4yt6AAoJEA8yVCPsQCW59dEIAJ42+mITzZwVhajEug2WNuct
ZqAhBbg99qQ2Y7cmYSwD/22i7TdqQ0Jfg63oHXsmL8SCjWyFioPCP+7SKzjKkchh
ogyRI6Qlr6thMuQE7MBVL/Up5wgxpADT84oTiwlInLnjZwa/cORrPIE7b5khxKR6
cN1hmLhClX3l26gx0E/JSu0U7S0ZUpaf7yRWZQgezt9lPGLWb5UkDH2ukopJQ0tD
Clrl3DEaRSjFbbCadpkltlr0xZhsJSsQC0NFdbzqW9EWy5AS0JJNtyoiiSaZjdq7
/jwekuwZiLRJnhgKFpb2E8JaQ2apFiZm68alb4Xg2LbLfuGOOEc4HE6sk2J+PCU=
=ypmn
-----END PGP SIGNATURE-----



More information about the Opendnssec-develop mailing list