Skip to content

Add config option IgnoreSRVHost#121

Open
Janfred wants to merge 2 commits intoradsecproxy:masterfrom
Janfred:feature/ignore_srv_hosts
Open

Add config option IgnoreSRVHost#121
Janfred wants to merge 2 commits intoradsecproxy:masterfrom
Janfred:feature/ignore_srv_hosts

Conversation

@Janfred
Copy link
Contributor

@Janfred Janfred commented Apr 13, 2023

This patch adds the configuration option IgnoreSRVHost to the server {} block.

The intention is to prevent or at least significantly reduce the possibility of loops in certain scenarios like a National Roaming Operator in eduroam with a number of radsecproxies with identical configuration.

A NAPTR/SRV record pointing to the own radsecproxies without a more specific destination configured could lead to a loop between the radsecproxies (or even a self-loop) when doing dynamic peer discovery.

@Janfred Janfred force-pushed the feature/ignore_srv_hosts branch from b431027 to 9d22c33 Compare May 3, 2023 09:57
@Janfred Janfred force-pushed the feature/ignore_srv_hosts branch from 9d22c33 to 6d0528f Compare May 24, 2023 13:00
Janfred added 2 commits June 12, 2023 17:45
This is intended to ignore certain hosts for dynamic discovery.
@Janfred Janfred force-pushed the feature/ignore_srv_hosts branch from 6d0528f to 86d2057 Compare June 12, 2023 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant