Phil White wrote:
But my concern is more that, if/when DNSSEC gets implemented, AXFR's
cannot be prevented by any method. Therefore, if any of us publish
exceptions, we open
our own domain up to forgery.
SHA hash is an interesting proposal, though.
Agreed. You could then use the records to verify the addresses, but not
to enumerate them.
---
Dustin D. Trammell
Vulnerability Remediation Alchemist
Citadel Security Software, Inc.
-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.txt
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?listname(_at_)½§ÅvÂ¼ð¦¾Øß´ëù1Ií-»Fqx(_dot_)com