Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] DNS Location record question

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] DNS Location record question


Chronological Thread 
  • From: Matthew J Zekauskas <>
  • To:
  • Subject: Re: [Security-WG] DNS Location record question
  • Date: Tue, 5 Sep 2017 10:19:08 -0400
  • Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
  • Ironport-phdr: 9a23:zkdZshISLVU0GfCQr9mcpTZWNBhigK39O0sv0rFitYgfK/zxwZ3uMQTl6Ol3ixeRBMOAuqIC07KempujcFRI2YyGvnEGfc4EfD4+ouJSoTYdBtWYA1bwNv/gYn9yNs1DUFh44yPzahANS47xaFLIv3K98yMZFAnhOgppPOT1HZPZg9iq2+yo9ZDeZwZFiCChbb9uMR67sRjfus4KjIV4N60/0AHJonxGe+RXwWNnO1eelAvi68mz4ZBu7T1et+ou+MBcX6r6eb84TaFDAzQ9L281/szrugLdQgaJ+3ART38ZkhtMAwjC8RH6QpL8uTb0u+ZhxCWXO9D9QLYpUjqg8qhrUgflhjoZOT438G/ZicJ+g6xUrx2juxNxzI/UbZqJNPd9ZK7RYc8WSGRBU8tXSidPApm8b4wKD+cZOuhXtZX9p0cOrRSgCwinGefhwSJLiXDo3q01yfkhERrF3AM6BNIFrXPZrNDvO6cOTeC416jIzTPfb/xIwzf97pbHcgw/rf2WQ71/bNfRxFApGgjYgFuQronlMCmU1uQLq2Wb6fRvVOyvimMptQ1+uD+vyd02honPmI0V1kjI9SRnz4YpK920Ukl7YcSrEJZWqiqUNJN2T9s8T25ypCo217gLtYOmcCQXzZknyRHSZ+Cbf4WN4B/sSumcLi19iX9gZr6zmwu+/VCix+DzTMW501JHojBYntXSsn0BzQLf58aDR/Z740yvwyyA1xrJ5eFBOU00lbTUK5omwrMojpQerUPNEjP4lUnvkaKZdFso9vGv6+v8fLrqvJicN5Joig7lNaQuh8q/DvkiPggWRWib/vi826P/8k3lQbVKifs2nrPesJDHOcQboqm5AwhW0oo59xm/CDKm3MwZnXkBMl1FZAqKg5bzNF3SPfz1COqzj0mxnDpuyfDLMaHtDonII3XBjrjscqxy5ktZxQYt0dxT+opYCrQbL/LyXk/xusbYDhg8MwGsxuboEsl91p8FVGKOBK+ZLL3dsUWO5u0xP+mAepUZtyjgJPg4//Lul2M2mUcBfam12psacGu4Eep6LEWEe3rsg8sBEGcTsgswQ+znk1mCUT9IZ3auRKIw+Cs3CIOgDYffWI+tmrqB0zmnHpFIfGxJFE2DEWq7P7mDDuwBYz+II9Nw1yMLfbmnV4I70xyy7kn3x6c0APDT/3g9vI7/1NVqr8+bpxwx/CFvDM2GmzWIRn1otmIOWzIs2q1j+wpwxkrVgvswuOBRCdEGv6ABaQw9L5OJl+E=
  • Spamdiagnosticoutput: 1:0

FWIW, I think the accuracy/precision values in the records are all defaults (which would lead me to believe they were not explicitly set).    I could be wrong; I just glanced at the RFC <https://tools.ietf.org/html/rfc1876>.

--Matt

On 9/5/17 10:12 AM, Steven Wallace wrote:
Thanks for the catch Michael. I assumed modern times where we use decimal
degrees notation.

So

rtsw.newy32aoa.net.internet2.edu. 3600 IN LOC 40 43 12.248 N 74 0 18.716 W
0.00m 1m 10000m 10m

would be?

rtsw.newy32aoa.net.internet2.edu. 3600 IN LOC 40 43 12 N 74 0 18 W 0.00m 1m
10000m 10m


On Sep 5, 2017, at 9:59 AM, Michael H Lambert
<>
wrote:

On 5 Sep 2017, at 09:53, Chris Wilkinson
<>
wrote:

As Steve notes, knocking down the precision may be the better approach here.
One second of arc is ~30m (at least for longitude at the equator and
latitude). Three decimal places of seconds are thus 3cm. The measurements
probably aren't that precise (LOC records for every port in the router?); it
probably isn't worth the effort to change them at all.

Michael





Archive powered by MHonArc 2.6.19.

Top of Page