Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 434650 - net-dns/bind-9 - add patches for Response Rate Limiting in BIND9 (DNS RRL) against dns DOS
Summary: net-dns/bind-9 - add patches for Response Rate Limiting in BIND9 (DNS RRL) ag...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All Linux
: Normal enhancement (vote)
Assignee: Christian Ruppert (idl0r)
URL: http://www.redbarn.org/dns/ratelimits/
Whiteboard:
Keywords:
: 427832 434682 (view as bug list)
Depends on:
Blocks:
 
Reported: 2012-09-10 21:03 UTC by William Waisse
Modified: 2012-09-11 18:20 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description William Waisse 2012-09-10 21:03:13 UTC
the ( serious and maintained ) patches from http://www.redbarn.org/dns/ratelimits/ provided by Vernon Schryver and Paul Vixie can really be useful to protect against DNS DOS

 I couldnt find any useflags for that in the BIND gentoo ebuild, and I think it could be a good feature to add a use flag for these patches

" DNS Response Rate Limiting (DNS RRL) which is an experimental feature for ISC BIND9. It is expected that this technology will someday be included in a standard BIND9 release. For now it is available only as a version-specific patch.

These patches and instructions pertain to authority name servers or authoritative views. Use of this kind of rate limiting for recursive or hybrid servers or views is currently unspecified. "

Technical note describing the implementation and operation of DNS Response Rate Limiting (RRL) : http://ss.vix.com/~vixie/isc-tn-2012-1.txt

Draft text for BIND9 Administrators Reference Manual (ARM) describing DNS Response Rate Limiting (RRL) : http://www.rhyolite.com/temp/rl-arm.html
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2012-09-11 14:43:37 UTC
*** Bug 434682 has been marked as a duplicate of this bug. ***
Comment 2 Christian Ruppert (idl0r) gentoo-dev 2012-09-11 18:19:58 UTC
Added in 9.9.1_p2-r3.
Comment 3 Christian Ruppert (idl0r) gentoo-dev 2012-09-11 18:20:52 UTC
*** Bug 427832 has been marked as a duplicate of this bug. ***