3 ms·
I wish DNS providers supported the standard DNS update protocol, instead of having each their own custom HTTP API.
by emersion 5y ago
I wish DNS providers supported the standard DNS update protocol, instead of having each their own custom HTTP API.
- dannyobrien 5y agoabsolutely! it is so much easier to deal with!
- tehbeard 5y agoWithout me having to deep dive through several RFCs... Is it a secure protocol, or is this BGP style we trusted everyone in the beginning and now have to layer security atop it?
- aaronmdjones 5y agoYou can sign update transactions with HMAC-SHA2. I don't believe there's anything in the way of preventing replays though.
- throw0101a 5y agoPer a sibling comment, GSS has timestamps to prevent replays: * https://en.wikipedia.org/wiki/TSIG https://en.wikipedia.org/wiki/TSIG
- yrro 5y agoIt can be secured with GSSAPI.
- throw0101a 5y agoI don't disagree, but in the meantime, a handy CLI utility that can handle a bunch of APIs: * https://github.com/AnalogJ/lexicon https://github.com/AnalogJ/lexicon This way you only have to write one set of boiler plate in case you use multiple providers (or want to change providers).
- atkailash 5y agoIm curious why choose this over Octodns or DNSConfig? It looks a lot more verbose
- michaelcampbell 5y agoI'm probably overlooking it, but does this support dyndns, aka dyn.com, aka Oracle dyndns? I couldn't find that it does.