Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -1,6 +1,6 @@
|
||||
# Naming
|
||||
|
||||
IPs are not human readable.
|
||||
IPs are not human-readable.
|
||||
|
||||
Not always the appropriate granularity
|
||||
|
||||
@@ -10,11 +10,11 @@ Not always the appropriate granularity
|
||||
A file maps names to addresses
|
||||
|
||||
- Unix & Linux
|
||||
- `/etc/hosts`
|
||||
- `/etc/hosts`
|
||||
- Windows
|
||||
- `C:\Windows\System32\drivers\etc\hosts`
|
||||
- `C:\Windows\System32\drivers\etc\hosts`
|
||||
|
||||
These are simple but neither automatic or scalable which led to **DNS**.
|
||||
These are simple but neither automatic nor scalable, which led to **DNS**.
|
||||
|
||||
- Was initially `RFC882`
|
||||
- Now is `RFC1035, 1987`
|
||||
@@ -22,24 +22,24 @@ These are simple but neither automatic or scalable which led to **DNS**.
|
||||
DNS is a consistent namespace
|
||||
|
||||
- No reference to addresses, routes etc
|
||||
- Is hierarchical, distributed & cache
|
||||
- All of which to help with scalability
|
||||
- Is hierarchical, distributed and cached
|
||||
- All of which help with scalability
|
||||
- **Federated** - sources control trade-off
|
||||
- This just means DNS are worldwide
|
||||
- **Flexible** - many record
|
||||
- This just means DNS is worldwide
|
||||
- **Flexible** - many records
|
||||
- Simple client-server name resolution protocol
|
||||
|
||||
#### Components
|
||||
|
||||
- *Domain name space* and *resource records*
|
||||
- Tree structured name space
|
||||
- Data associated with names
|
||||
- Tree-structured name space
|
||||
- Data associated with names
|
||||
- *Name server*
|
||||
- Contains records for a sub tree
|
||||
- May cache information about any part of the tree
|
||||
- Contains records for a subtree
|
||||
- May cache information about any part of the tree
|
||||
- Resolver
|
||||
- Extract information from tree upon client requests
|
||||
- `gethostbyname()`
|
||||
- Extracts information from the tree upon client requests
|
||||
- `gethostbyname()`
|
||||
|
||||

|
||||
|
||||
@@ -48,26 +48,26 @@ DNS is a consistent namespace
|
||||
- Ultimate authority with the US Dept. of commerce (NITA)
|
||||
- Managed by IANA, operated by ICANN, maintained by Verisign
|
||||
- Started with only thirteen root server clusters
|
||||
- Now much more
|
||||
- Top level Domains, TLDs
|
||||
- Operated by registrars, delegated by ICANN
|
||||
- Now many more
|
||||
- Top-level domains, TLDs
|
||||
- Operated by registrars, delegated by ICANN
|
||||
- Delegate zones to other registrars
|
||||
- and so on down the hierarchy
|
||||
- Eventually customer rents a name - their **zone**
|
||||
- Registrar installs appropriate *resource records*
|
||||
- Associated with names within the zone
|
||||
- and so on down the hierarchy
|
||||
- Eventually, a customer rents a name - their **zone**
|
||||
- Registrar installs appropriate *resource records*
|
||||
- Associated with names within the zone
|
||||
|
||||
#### Query
|
||||
|
||||
- Query generated by resolver
|
||||
- e.g. call to `gethostbyname()`, `gethostbyaddr()`
|
||||
- e.g. call to `gethostbyname()`, `gethostbyaddr()`
|
||||
- Carried in single UDP/53 packet
|
||||
- Or more rarely TCP/53 in case of truncation
|
||||
- UDP is not smart and therefore does not follow traffic routing (it is selfish)
|
||||
- It is beneficial for the internet as a whole to use UDP sometimes
|
||||
- Or more rarely TCP/53 in case of truncation
|
||||
- UDP is not smart and therefore does not follow traffic routing (it is selfish)
|
||||
- It is beneficial for the internet as a whole to use UDP sometimes
|
||||
- Header followed by question
|
||||
- ID, Q/R, opcode, AA/TC/RD/RA, response code, counts
|
||||
- Query type, query class, query name
|
||||
- ID, Q/R, opcode, AA/TC/RD/RA, response code, counts
|
||||
- Query type, query class, query name
|
||||
|
||||
Response consists of three RRsets following the header and question
|
||||
|
||||
@@ -113,27 +113,27 @@ nott.ac.uk. 3600 IN MX 2 mx192.emailfiltering.com.
|
||||
nott.ac.uk 3600 IN MX 3 mx193.emailfiltering.com.
|
||||
```
|
||||
|
||||
What happens when the resolver queries a server that doesn't know the answer? two solutions:
|
||||
What happens when the resolver queries a server that doesn't know the answer? There are two solutions:
|
||||
|
||||
1. **Iterative** (required)
|
||||
- Server responds indicating who to ask next
|
||||
- This method is slower and more difficult to retrieve an answer
|
||||
- Server responds indicating who to ask next
|
||||
- This method is slower and more difficult to retrieve an answer
|
||||
1. **Recursive** (optional)
|
||||
- Server generates a new query to the next server
|
||||
- Server generates a new query to the next server
|
||||
|
||||

|
||||
|
||||
#### Load Balancing
|
||||
|
||||
DNS may have multiple servers, when a query comes various algorithms can be used to choose the best one, this can be geographical location.
|
||||
DNS may have multiple servers. When a query arrives, various algorithms can be used to choose the best one, for example, based on geographical location.
|
||||
|
||||
#### Operational & Security Issues
|
||||
|
||||
- Usually need primary and secondary servers
|
||||
- Separate IP netblocks, physical networks - more robust
|
||||
- DNS is a *very* common single point of failure
|
||||
- Separate IP netblocks, physical networks - more robust
|
||||
- DNS is a *very* common single point of failure
|
||||
- Cache poisoning
|
||||
- Caching and soft-state means bad data propagates and can persist for some time
|
||||
- Even if through simple mistakes (or of course malicious attacks)
|
||||
- Caching and soft-state means bad data propagates and can persist for some time
|
||||
- Even if through simple mistakes (or of course malicious attacks)
|
||||
- Man-in-the-middle attacks
|
||||
- Can happen with both iterative & recursive queries
|
||||
- Can happen with both iterative & recursive queries
|
||||
Reference in new issue
Block a user