On Thursday, March 20, 2003, at 03:28 PM, Jakob Schlyter wrote:
On Thu, 20 Mar 2003, Bill Sommerfeld wrote:An alternate approach which I think is superior is to ensure that theDNS search path used while resolving SSHFP records comes from a trustedsource (i.e., not from DHCP or PPP/ipcp).how can the ssh client implementation ensure that?
I don't think the implementation can ensure that. However, the users of the client system can ensure that by manually coding a DNS search path that doesn't get over-written by DHCP.
-- wes / wgriffin%jtan.com@localhost / 000f1a2f