TL;DR Route53ã®DNSã¬ã³ã¼ã管çã«ã¯Roadworkerã¨direnvãçµã¿åããã¦ä½¿ãã¨ä¾¿å© Roadworkerã使ããããããããã«ãVimãã©ã°ã¤ã³ã¨Zshè£å®é¢æ°ãä½ã£ã (TL;DR使ã£ã¦ã¿ããã£ã) çµç·¯ roadworker | RubyGems.org zimbatm/direnv ä¼ç¤¾ã§Route53ã«ç§»è¡ãããã¼ã ããã£ã¦ãã¬ã³ã¼ãã®ç®¡çã«Roadworkerã使ã£ã¦ã¦ã ç§ãã¡ãã£ã¨ä½¿ã£ã¦ã¿ããã§ãããã³ãã³ãã©ã¤ã³ããã®ä½¿ãåæã¨ãRoutefileã®ç·¨éã ãã®ã¾ã¾ã ã¨ä¸ä¾¿ã ã£ãã®ã§ã使ãåæãè¯ããªãããã«direnv使ã£ããã Vimãã©ã°ã¤ã³ã¨zshè£å®é¢æ°ãä½ã£ããããã Macã§ã®ä½æ¥ãæ³å®ãã¦ã¾ãã Roadworkerã®ã¤ã³ã¹ãã¼ã«
äºåã«æã£ã¦ãããããã§ãããã¤ã³ãã©ãã¯ã¬ã¤ã¤çã«ã¯ OS ããä¸ã®è©±ã å°ãåã« GitHub æ代ã®ãããã¤æ¦ç¥ - naoyaã®ã¯ã¦ãªãã¤ã¢ãªã¼ ã§ãGitHub ãä»ãããããã¤ãå®è·µãã¦ããã¨ãããã¨ãç´¹ä»ãããæ®æ®µã®éçºã Pull Request ãã¼ã¹ã§ãã£ã¦ããã®ã§ããããã¤ãã¾ã Pull Request ãå¥æ©ã«å®è¡ãããã¨è²ã æããã¨ãã話ã ãã®ãã©ã¯ãã£ã¹ã®å¯¾è±¡é åãã¤ã³ãã©ã«ã¾ã§æ¡å¤§ãã¦ã¿ã¾ãããã¨ããã®ãä»åã®è©±ã DNS ã¬ã³ã¼ãã Pull Request ã merge ããå¥æ©ã«èªåã§æ´æ° AWS ãå©ç¨ãã¦ããå ´åããã¡ã¤ã³ã®ç®¡çã Amazon Route 53 ã使ãã¨ããããã¨é½åãããã Route 53 ã§ã® DNS ã¬ã³ã¼ãã®æ´æ°ã¯ããã¾ã§ãã©ã¦ã¶ããæä½ãã¦ãããããã ã¨èª°ããã¤ä½æ¥ãããããããªããå±¥æ´ããã©ãã¯ãã¥ãããã¾ãå¤æ´
2014å¹´6æ23æ¥(æ) â ç¡é¡ _ æã¡æé30åã§50æã£ã¦ç¡çã ããâ¦ãã¾ã ä½æãå¢ãããã 2014å¹´6æ26æ¥(æ¨) â ç¡é¡ _ ã²ããã¶ãã«å¤§æçºã«æ¥ããã©ã以åã¨ããããéãããã¦ã¦ã¢ã¬ãåéçºãã£ã¦ãã®ã¯ç¥ã£ã¦ããã©ããã¾ã§ã¨ã¯ãå½æã¯å ¬åº«ãã«ã®è·å¡é£å ã¨ãæ¥çµæ°èã®ç¤¾å¡é£å ã¨ãããå¿ã³ããã§æ¼é£¯é£ã£ã¦ããã©ããã«ã©ãããããã«ãé¢ãã¦ããéããã¨æ¶æ» ãã¡ãã£ã¦ããã _ KDDI ã¨ã NTT com ã¨ãã®ãã«ã¯å¤ããã¬å§¿ã§å®å¿ãããéä¿¡è¨åãå ¥ã£ã¦ããã«ã¯ããç°¡åã«å»ºã¦æ¿ããããããããããã§ããç活彩家ããªãã§ã»ãã³ã«å¤ãã£ã¦ããã§ããã¼ã â .local _ ã¨ãããã¨ã§ã¿ãªãã¾ãã¤ãããã¾ã§ãããä»æ¥è©±é¡ã«ãªã£ããã¨ããã話é¡ã«ãã件ã RFC6762ã Any DNS query for a name ending with ".local." MUS
JPCERT/CCã§ã¯ããªã¼ãã³ãªã¾ã«ãã¼(å¤é¨ã®ä¸ç¹å®ã®IPã¢ãã¬ã¹ããã®å帰çãªåãåããã許å¯ãã¦ããDNSãµã¼ãã¼)ã¨ãªã£ã¦ããDNSãµã¼ãã¼ãæ¥æ¬å½å ã«å¤ãåå¨ãã¦ãããã¨ã確èªãã¦ãã¾ãã ãªã¼ãã³ãªã¾ã«ãã¼ã¯å½å å¤ã«å¤æ°åå¨ãã大è¦æ¨¡ãªDDoSæ»æã®è¸ã¿å°ã¨ãã¦æªç¨ããã¦ããã¨ã®å ±åãããã¾ãã ã¾ããDNSãµã¼ãã¼ã¨ãã¦éç¨ãã¦ãããã¹ãã ãã§ã¯ãªããããã¼ããã³ãã«ã¼ã¿ã¼ãªã©ã®ãããã¯ã¼ã¯æ©å¨ãæå³ãããªã¼ãã³ãªã¾ã«ãã¼ã«ãªã£ã¦ããäºä¾ããããã¨ã確èªãã¦ãã¾ãã æ¬ç¢ºèªãµã¤ãã§ã¯ãã使ãã®PCã«è¨å®ããã¦ããDNSãµã¼ãã¼ã¨ãæ¬ç¢ºèªãµã¤ãã¸ã®æ¥ç¶å ã¨ãªã£ã¦ããããã¼ããã³ãã«ã¼ã¿ã¼ãªã©ã®ãããã¯ã¼ã¯æ©å¨ããªã¼ãã³ãªã¾ã«ãã¼ã¨ãªã£ã¦ããªããã確èªãããã¨ãå¯è½ã§ãã æ¬ãµã¤ãã®è©³ç´°ã«ã¤ãã¦ã¯ãã¡ãããåç §ãã ããã ãã ãã¾å¦çä¸ã§ãããã°ãããå¾ ã¡ãã ããã â»å¤å®å¦ç
ã¯ããã« Dozensã¯ã·ã³ãã«ã§ä½¿ããããDNSãµã¼ãã¹ã§ããã¦ã§ããã©ã¦ã¶ãããã°ã¤ã³ãã¦ä½¿ç¨ããã¨ããé常ã®ä½¿ãæ¹ã®ä»ã«ãã¢ããªã±ã¼ã·ã§ã³ããç´æ¥APIãå¼ã³åºããã¨ã§å種ã®DNSã®æä½ãã§ããããã«ãªã£ã¦ãã¾ããä»åãã¦ã§ããµã¼ãã®æ»æ´»ç£è¦ã¨Dozensã«ããåçãªDNSã¬ã³ã¼ãå 容ã®å¤æ´ãçµã¿åãããè² è·åæ£ãåé·åãå®ç¾ããã½ããã¦ã§ã¢ãDozensHAããéçºãããªã¼ãã³ã½ã¼ã¹ã©ã¤ã»ã³ã¹ã¨ãã¦ãªãªã¼ã¹ãã¾ãããé常ã«ã·ã³ãã«ãªè¨å®ãã¡ã¤ã«1ã¤ã ãã§ãç°¡åã«åºåè² è·åæ£ãåé·åãè¡ããã¨ãã§ãã¾ãã ä½ãå¯è½ãªã®ãï¼ DozensHAã¯ãè¨å®ãã¡ã¤ã«ã«è¨è¿°ããã¦ããã¦ã§ããµã¼ãã®IPã¢ãã¬ã¹ï¼è¤æ°å¯ï¼ã«å¯¾ãã¦HTTPãªã¯ã¨ã¹ããéä¿¡ãã200ã302çã®æ£å¸¸ãªã¹ãã¼ã¿ã¹ã³ã¼ããæå®æéå ã«è¿ã£ã¦ãããã©ããããã§ãã¯ãã¾ããæ£ããåå¿ããã£ãIPã¢ãã¬ã¹ã«ã¤ãã¦ã¯ãDozens
ä»æ¥(4æ30æ¥é )ãä¸é¨ã®äººã ã®éã§ããã¡ã®Webãµã¤ãã§ä½¿ã£ã¦ã.inã®åå解決ãåºæ¥ãªããªã£ãï¼ãã¨ããæ²é³´ãèããã¦ãã¾ãã æ°å¹´åãã¤ã³ãã®ccTLD(country code Top Level Domain)ã§ããã.inããæ¥æ¬å½å ã®Webãµã¼ãã¹ã§ä½¿ãã®ãæµè¡ãã¾ããã ã.inãã¯ãã¤ã³ãã¨èªããããèªåãè¯ããå人ãæ°è»½ã«Webãµã¤ããä½ã£ãã¨ãã«ããã¡ã¤ã³åãåæã«ç»é²ããã¨ããã®ãæµè¡ã£ãããã§ããããã®ã¨ãã«whoisã§ä¸çã«åãã¦é£çµ¡å (å人ã§ããã°æ°åä½æé»è©±çªå·ã®å ´åããã)ãå ¬éãããã®ã¯å«ã ã¨ãããã¨ã§ãwhoisæ å ±å ¬é代è¡ãµã¼ãã¹(ãããã¯ãã©ã¤ãã·ã¼ä¿è·ãµã¼ãã¹)ã使ãã¨ããã®ãå²ã¨ä¸è¬çã«è¡ããã¦ãã¾ããã ãããããã®.inã®ã¬ã¸ã¹ããªã§ããINRegistryããwhoisæ å ±å ¬é代è¡ãµã¼ãã¹ãå©ç¨ãã¦ãããã¡ã¤ã³åã次ã ã¨åæ¢ãã¦ãããã
ãDNS Summer Days 2012 éå¬ã®ãç¥ããã éå¬è¶£æ¨ ã¤ã³ã¿ã¼ãããã®åºå¹¹æè¡ã®ä¸ã¤ã§ããDNSã¯ãIPv6ã®æ®åãã»ãã¥ãªãã£å¼·å ã®ããã®DNSSECãå®ç¨æ®µéã«ãããããã«ä¼´ãããã®éè¦æ§ã¯å¢ãä¸æ¹ã§ããã¾ ããDNSSECãå¥æ©ã¨ãã¦ãæ§ã ãªæ©è½ãDNSã«è¼ãããã¨ããåããåºã¦ãã¦ã ã¾ãã ããã«ãé¢ããããDNSã®éç¨ã«ã¯ããã¾ã§ååãªé¢å¿ãæããã¦ãã¨ã¯è¨ã㪠ãç¶æ³ã§ãxSPããµã¼ãã¹äºæ¥è ãåã ã®ä¼æ¥ãçµç¹ã§ãååãªãªã½ã¼ã¹ãå²ã ãã¦ãã¾ãããã¾ãããããã³ã«ãRFCçã®è§£èª¬ææ¸ã®ãããã«ãããç¸ã¾ã£ ã¦ãDNSããã¡ãã¨ç解ãã¦ããæè¡è ã®æ°ãååã¨ã¯è¨ãã¾ããã DNSã«é¢ãã¦ã¯ããã¾ã§ããå種ã¤ãã³ããDNSOPSã®BoFçã®æ´»åã¯ããã¾ãã ããç¾ç¶ãéã¿ãã¨ãã£ã¨åºæ¬ããçªã£è¾¼ãã 話ã¾ã§ã«ãã¼ããã¤ãã³ãã®éå¬ ãå¿ è¦ã§ããã¨å¤æããè³åã
å é±ãå¿è ãã¼ã«ãºå ¨ãµã¼ãã¹ãä¸æçã«å©ç¨ã§ããªããªãã¾ããã æ ªå¼ä¼ç¤¾ãµã ã©ã¤ãã¡ã¯ããªã¼ï¼å¿è ãã¼ã«ãºå ¨ãµã¼ãã¹ã表示ä¸å¯ã¨ãªãé害ã«ã¤ãã¾ã㦠ãåå.comï¼å¿è ãã¼ã«ãºå ¨ãµã¼ãã¹ã表示ä¸å¯ã¨ãªãé害ã«ã¤ãã¾ã㦠æ¬ã®è«: DNSã®çµçãå£éè¦ãããã¶ã£é£ãã§ã¦å±éºããããåå.comã®æ¤é²äºä»¶ ãã®çç±ã¨ãã¦ãæ ªå¼ä¼ç¤¾ãµã ã©ã¤ãã¡ã¯ããªã¼(å¿è ãã¼ã«ãº)ã®ãã¬ã¹ãªãªã¼ã¹ã«ã¯ä»¥ä¸ã®ããã«ããã¾ãã å¿è ãã¼ã«ãºã®ãµã¼ãã¹ãå©ç¨ããã¦ã¼ã¶ã¼ãµã¤ãã®ä¸é¨ã«ããåå.comã®ç´æ¬¾ã«æµè§¦ãããµã¤ããããããåå.comã¸ã®ãåãåãããè¤æ°ãã£ããããç´æ¬¾ã«åºã¥ããåå.comã§ã¯ä¸æçã«ãã¡ã¤ã³ã®åæ¢æªç½®ãã¨ã対å¿ãè¡ãã¾ãã å人çãªææ³ã¨ãã¦ã¯ãå¿è ãã¼ã«ãºã®ãã¡ã¤ã³åæ¢æªç½®äºä»¶ã¯ä»ã¾ã§ã«ãªãæ°ããã¿ã¤ãã®ãã®ã§ããã¨æãã¾ããã ã¾ãããåå.comã¨ninja.co.jpã«é¢ãã¦
Unboundã¯DNSãªã¾ã«ãããã£ãã·ã¥ãDNSSECæ¤è¨¼æ©è½ãæã¤DNSãã£ãã·ã¥ãµã¼ãã¼ã§ãã次ã®ãããªç¹å¾´ãæã¡ã¾ãã DNSSECå¯¾å¿ DNSãã£ãã·ã¥æ±æã«å¯¾ããèæ§ãå¼·ã è¨å®ã容æã§ããï¼ããã©ã«ãã§å®å ¨ãªè¨å®ãã§ããï¼ é«æ§è½ IPv4ãIPv6ãã¥ã¢ã«ã¹ã¿ã㯠Unboundã¯BSDã©ã¤ã»ã³ã¹ã®å ã§å ¬éããã¦ãã¾ãã DNSã©ã¦ã³ãããã³å¯¾å¿ã«ã¤ã㦠Unboundã¯æåã®ãã¼ã¸ã§ã³ããDNSã©ã¦ã³ãããã³ã«ãã£ã¨å¯¾å¿ãã¦ãã¾ããã§ãããããããUnbound 1.4.17ã«ããã¦DNSã©ã¦ã³ãããã³ã«å¯¾å¿ãã¾ãããunbound.confã«ããã¦"rrset-roundrobin: yes"ãè¨å®ããã¨æå¹ã«ãªãã¾ãã ææ¸ ã¤ã³ã¹ãã¼ã«ã¨è¨å®æ¹æ³ DNSSECãæå¹ã«ããã«ã¯ DNSSECãç¡å¹ã«ããã«ã¯ æé©åã®æ¹æ³ ã½ããã¦ã§ã¢ããã±ã¼ã¸ æ§è½ ããã¥ã¢ã« un
bind ã® tarballã® contrib/queryperf ãã£ã¬ã¯ããªã«å ¥ã£ã¦ããã $ ./configure $ make $ ./queryperf -d input/sample.1 -d XXX.XXX.XXX.XXX -l 10XXX.XXX.XXX.XXX ãããã©ã¼ãã³ã¹ãè¨æ¸¬ããã DNS ãµã¼ãã® IP ã¢ãã¬ã¹ããã®ãããå¢ãã§åãåãããã®ã§èªåã管çãã¦ãªãå¤é¨ã® DNS ãµã¼ãã¸ããããã«ãªã¯ã¨ã¹ããéããªããã¨ã -d ãªãã·ã§ã³ã¯ãµã³ãã«ãã¼ã¿ã®ãã¡ã¤ã«ãæå®ããããµã³ãã«ãã¼ã¿ã¯ queryperf ãã£ã¬ã¯ããªã®ä¸ã® input ãã£ã¬ã¯ããªå ã«ãµã³ãã«ãç¨æãã¦ãããåãã queryperf ãã£ã¬ã¯ããªã®ä¸ã® utils ã®ãªãã« gen-data-queryperf.py ã¨ããã¹ã¯ãªãããããããã¼ã®ãã¼ã¿ãä½ã£ã¦ãããããã¼ã¿ã®éã
by Rob Mayoff These notes are incomplete. dnscache is part of the djbdns package, written by Daniel J. Bernstein, aka djb. I couldn't find any documentation on its log file format, other than this explanation of one field of the stats log entry. This file contains my notes on what the log entries mean. If there are any errors here, they are mine and not djb's. dnscache logs IP addresses as 8 digit
Form based record testersOur reference SPF-result-explanation pageScott Kitterman's SPF record testing toolsE-mail based record testersNOTE: The openspf.net tester is currently out of service We provide an e-mail based record tester. Send an e-mail to spf-test@openspf.net. Your message will be rejected (this is by design) and you will get the SPF result either in your MTA mail logs or via however
ãã¡ã¤ã³åã®ããªã¼æ§é ã¯å§ä»»ã«ãã£ã¦ã¾ã¼ã³ã«åå²ãããåæ£ç®¡çããã¦ãã¾ããSOAã¬ã³ã¼ãã¯ãããã®åå²ãããã¾ã¼ã³ããããã®ãªã¼ã½ãªãã£æ å ±ãè¨ããã¦ããã¬ã³ã¼ãã§ããSOAã¯Start Of Authorityã®ç¥ã§ãã権å¨ã®éå§ãã¨ããæå³ã«ãªãã¾ãã BINDã§ã¯ã¾ã¼ã³ãã¡ã¤ã«ã®å é ãããã©ã«ãTTLã®æå®ã®å¾ã«æ¸ããã¨ã«ãªã£ã¦ãã¾ããã¾ããSOAã¯å§ä»»ã«é¢ãããªã¼ã½ãªãã£æ å ±ãè¨ããã®ã§ãããåã¾ã¼ã³ã®å§ä»»ããããã¡ã¤ã³åã«é¢é£ä»ãããã¾ãã SOAã¬ã³ã¼ãã¯ã¾ã¼ã³ãã¡ã¤ã«ã®ä¸ã§ã¯ããªã¹ã1ã®ããã«è¨è¿°ããã¾ãã @ IN SOAã ns1.example.jp. postmaster.example.jp. ( 2003081901 ã; Serial 3600 ãã ããã ; Refresh 900 ãããããã ; Retry 604800 ãããã; Expire 36
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}