Print

Print


Hi Andy,

I simplified things a bit so we don't rely on DNS at all for the majority of cases (anything that looks like a FQDN) but still handles the case reported by @simonmichal.

The problem with using the trick of appending a . is that it still relies on DNS - hence exposing the security issue we were trying to avoid in the first place.

With this, I believe things are secure by default except in detectable backward compatibility scenarios.

Brian


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

{"@context":"http://schema.org","@type":"EmailMessage","potentialAction":{"@type":"ViewAction","target":"https://github.com/xrootd/xrootd/pull/731#issuecomment-395617852","url":"https://github.com/xrootd/xrootd/pull/731#issuecomment-395617852","name":"View Pull Request"},"description":"View this Pull Request on GitHub","publisher":{"@type":"Organization","name":"GitHub","url":"https://github.com"}} {"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/xrootd/xrootd","title":"xrootd/xrootd","subtitle":"GitHub repository","main_image_url":"https://assets-cdn.github.com/images/email/message_cards/header.png","avatar_image_url":"https://assets-cdn.github.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/xrootd/xrootd"}},"updates":{"snippets":[{"icon":"PERSON","message":"@bbockelm in #731: Hi Andy,\r\n\r\nI simplified things a bit so we don't rely on DNS at all for the majority of cases (anything that looks like a FQDN) but still handles the case reported by @simonmichal.\r\n\r\nThe problem with using the trick of appending a `.` is that it still relies on DNS - hence exposing the security issue we were trying to avoid in the first place.\r\n\r\nWith this, I believe things are secure by default except in detectable backward compatibility scenarios.\r\n\r\nBrian"}],"action":{"name":"View Pull Request","url":"https://github.com/xrootd/xrootd/pull/731#issuecomment-395617852"}}} { "@type": "MessageCard", "@context": "http://schema.org/extensions", "hideOriginalBody": "false", "originator": "AF6C5A86-E920-430C-9C59-A73278B5EFEB", "title": "Re: [xrootd/xrootd] Use DNS lookups to expand non-FQDNs (#731)", "sections": [ { "text": "", "activityTitle": "**Brian Bockelman**", "activityImage": "https://assets-cdn.github.com/images/email/message_cards/avatar.png", "activitySubtitle": "@bbockelm", "facts": [ ] } ], "potentialAction": [ { "name": "Add a comment", "@type": "ActionCard", "inputs": [ { "isMultiLine": true, "@type": "TextInput", "id": "IssueComment", "isRequired": false } ], "actions": [ { "name": "Comment", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueComment\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 731,\n\"IssueComment\": \"{{IssueComment.value}}\"\n}" } ] }, { "name": "Close pull request", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"PullRequestClose\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"pullRequestId\": 731\n}" }, { "targets": [ { "os": "default", "uri": "https://github.com/xrootd/xrootd/pull/731#issuecomment-395617852" } ], "@type": "OpenUri", "name": "View on GitHub" }, { "name": "Unsubscribe", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"MuteNotification\",\n\"threadId\": 343573995\n}" } ], "themeColor": "26292E" }

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1