>
> -----BEGIN PGP SIGNED MESSAGE-----
[...]
> Also you want to use resolv+ for the rebuilt shlib, this will give y
ou
> BIND 4.8.3, enhanced security in the form of a hostname spoofing che
ck
> from local hostnames. plus the feature of being able to lookup
> hostname from NIS, /etc/hosts and DNS in any order you choose.
And start using 4.9.3 ASAP once released.
Start using it now; 4.9.3 beta 17 is much more reliable than most
vendor code I've seen. And there are important security benefits as
well -- Paul Vixie will be presenting a companion paper to mine
that describes how he fixed lots of holes.
--Steve Bellovin
|
|