[CentOS] Opinions about SSH and DNS

Sun May 25 23:40:52 UTC 2008
Bill Campbell <centos at celestial.com>

On Mon, May 26, 2008, Clint Dilks wrote:
>Hi People,
>As part of securing SSH we currently have UseDNS set to yes.  But we are 
>finding that a number of ISP's are deliberately refusing to configure 
>matching forward and reverse DNS records.  So I am wondering how many of 
>you are still using this option?

The main utility of using DNS is in conjunction with tcp_wrappers
where one wants to use host/domain names in /etc/hosts.allow.

IHMO, competent ISPs will handle DNS forward and reverse properly.

Unfortunately there are a lot of incompetents who purport to be ISPs.

