Jul. 13th, 2019

DNS в VCS

Jul. 13th, 2019 11:10 am
victor_sudakov: (Default)
В «NCSC Advisory on Ongoing DNS Hijacking Campaign» дается совет:

if operating your own DNS infrastructure, consider robust change control processes to manage any changes to your zone file. Ideally you should use a DNS zone file that is managed through a version control system, such as git. This will provide a backup of your DNS records, allow change-auditing and easy rollback. Enforce levels of organisational approval which is monitored before changes are made.

[...]

if you operate a critical domain, consider monitoring for domain transfers, WHOIS data changes, and nameserver changes.


А я ещё с 2000 года держал зоны tomsk.ru, tomsk.su и остальные в CVS, и мониторил изменения в базе RIPN, посылая каждые 2 часа whois-запрос и сравнивая с результатом last known good запроса.

Я молодец?

Profile

victor_sudakov: (Default)
Виктор Судаков

December 2024

S M T W T F S
1234567
891011121314
15161718192021
22232425262728
293031    

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Aug. 26th, 2025 12:38 am
Powered by Dreamwidth Studios