Am 17.04.2017 um 06:01 schrieb Chris Laprise:
> On 04/16/2017 08:29 PM, 'David Shleifman' via qubes-devel wrote:
>> - keep the original name; give user an ability to trigger
>> resolution of all names associated with a given VM Firewall.
> A more usable variation of that may be to detect the presence of
> domain names, and enable automatic/recurring name resolution.
Both (but the last one especially) offer you unique and ingenious ways
of shooting yourself in both feet. There was an extensive discussion on
that somewhere on the FreeBSD mailing lists about 16 years ago (having
to do with source-based routing and split-horizon zones where resolution
of names depended on firewall (and packet forwarding rules) state.
Even without that a vulnerability in your name server might lead to
interesting results. Using symbolic names which are not just local macro
expansions should be discouraged.
Achim