Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Undo customer resolution logic but keep zone awareness #23

Closed
mrjones-plip opened this issue Aug 16, 2018 · 1 comment
Closed

Undo customer resolution logic but keep zone awareness #23

mrjones-plip opened this issue Aug 16, 2018 · 1 comment
Labels
enhancement New feature or request
Milestone

Comments

@mrjones-plip
Copy link
Contributor

mrjones-plip commented Aug 16, 2018

In prior commits (possibly PR #11?) we changed the DNSAuth resolves customers. We had it use the zone instead of the Server IP (aka host) . We need to change the way this works to again. The problem is that, baring qname minimization, you could potentially see a query for www.foo.bar three times: once to one of the root servers (bar), once to customer 1 (foo.bar), and once to customer 2 (www.foo.bar). The query name is identical across all three queries (www.foo.bar), yet they’re going to three different customers and three different IP addresses. Only the IP addresses distinguish them.

However! There still may be an instance where two customers with two zones are behind the same IP. In this case you'd need to use both IP and zone to resolve the log entry to a customer. Presumably we'll do this through an additional column in the customers DB.

One more trick we need to do: when using the IP, it should accept it in CIDR notation as well as exact IP. Further, see if it's reasonable to have both IPv4 and IPv6 IPs in there. Feel free to recommend a schema update if needed. Because CIDR notation (as well as individual IPs) can cause overlaps of matches, we should log "WARNING" or something when there's more than one match found.

@mrjones-plip
Copy link
Contributor Author

Fixed in #27

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant