update the rpz records for recursor by API #13869
Replies: 3 comments 7 replies
-
RPZs can be retrieved from an authoritative server using IXFR. See https://docs.powerdns.com/recursor/lua-config/rpz.html#rpzPrimary. You can use the API on that authoritative server to manipulate the records in the RPZ. There are no plans to allow RPZ modification via the recursor API. |
Beta Was this translation helpful? Give feedback.
-
Moving this to discussions |
Beta Was this translation helpful? Give feedback.
-
I have the feeling that we go around in circles. I'll try to explain the steps one last time, using your example:
https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-dns-rpz-00 has all the details how RPZ records work You can also take a look how existing RPZ look, for example the ones published by https://ioc2rpz.net/ |
Beta Was this translation helpful? Give feedback.
-
why
Since we are using different dns components, we now need to integrate them for easy unified management. We have docked the api interfaces of authoritative resolution servers and recursive resolvers, and these apis can be used to easily manipulate dns resources. But we also use rpz file, rpz record parsing, but I can not find the relevant api interface, may I ask if there is a relevant api interface? Or is there a better solution or suggestion for dynamically modifying rpz records remotely?
Looking forward to your reply!
Environment
Expected behaviour
Hope to be able to provide api or related suggestions for dynamically modifying rpz records
Beta Was this translation helpful? Give feedback.
All reactions