3 ms·
I get why that would jump out immediately and you'd stop reading from there on, but straight after that block of code, from the article: "Now I'm certain that
by namecast 11y ago
I get why that would jump out immediately and you'd stop reading from there on, but straight after that block of code, from the article:
"Now I'm certain that a lot of readers will have something to say about the style or the efficiency of this shell script, I just wrote it that way to highlight what steps need to be taken:
it retrieves a TXT record, and doesn't output anything if the record doesn't exist
if unbound-host has not confirmed that the record was correctly DNSSEC signed, it doesn't output anything
if the above is successful, it filters out the text to return only the public key
it doesn't try to do anything complex, because complexity is the enemy of security (or at least, that’s a point of view that I share with a few people)
it works with multiple records
I'm sure you will write your own program to do the above. Just make sure it works only when you want it to. It is critical to ensure that it doesn't return anything at least when:
a record for the corresponding user doesn't exist
the records are not signed or not properly signed
the local copy of the root key (/var/unbound/root.key, here) is corrupted.
"