Re: Hostname Naming Compliance

2009-02-23 Thread David Ford
Here's a question. Are we incapable of dealing with things like underscores in hostnames? Is there any significant harm in adapting? -david ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Hostname Naming Compliance

2009-02-23 Thread Michael Milligan
Ah yes, the perennial rathole... Eric C. Davis wrote: > I know the option to use this compliance checker is present, but I'm > curious to know if there are plans to make it mandatory to comply. We RFC 1123 has always been mandatory for Internet connected hosts. Valid characters for a hostname a

Re: [OT] Is it possible to set a ddns hostname to access a name-based virtual host?

2009-02-23 Thread Michael Milligan
hongyi.z...@gmail.com wrote: > >> You *must* reference the location using the same URI if you expect to >> see the same expected results. > > Thanks for your detailed explanations. Another issue: what do you > mean by saying URI? What's the differences between URI and URL? Just being more

Re: Is it possible to set a ddns hostname to access a name-based virtual host?

2009-02-23 Thread Barry Margolin
In article , hongyi.z...@gmail.com wrote: > On Friday, February 20, 2009 at 22:15, serge.fonvi...@gmail.com wrote: > > Let me give an example to illustrate my problem: > > > In the following url, the prola.aps.org is a name-based virtual host: > > > http://prola.aps.org/pdf/PRB/v1/i1/p1_1 > >

Re: empty DoS queries

2009-02-23 Thread Mark Andrews
I suspect you have a broken application on 10.48.0.19. Mark In message <70fo2df49pf...@mid.individual.net>, Frank Kirschner writes: > Hello, > since last night we log emtpty queries (approx. 4000 per seconds) like > this from a client in our LAN: > > 23-Feb-2009 13:20:15.516 qu

Re: client query logging (refused message)

2009-02-23 Thread Mark Andrews
In message , asd...@gmail.com writes: > 62.109.4.89 and 195.68.176.4 are compromized/attackers Actually they are more likely to be under attack. Make sure that you (and your ISP) have deployed the measures in BCP 38 to ensure that you are not the source of such a

Re: Hostname Naming Compliance

2009-02-23 Thread Danny Thomas
Eric C. Davis wrote: > Are there plans for Bind to enforce hostname compliance according > to RFC's or is this going to be left up to each DNS operator? the question of benefit always arises when considering the application of RFCs. It's probably better not enforcing things just for the sake of c

Re: ResendRE: ns_type question

2009-02-23 Thread JINMEI Tatuya / 神明達哉
At Tue, 17 Feb 2009 23:05:27 -0800, Jack Tavares wrote: > > My question is; > > > > the arpa/nameser.h file included does not include > > type definitions for DNSKEY (or other dnssec rr types) > > in the ns_type enum. > > > > am I looking in the wrong place? > > > No, you're looking at the right

RE: Hostname Naming Compliance

2009-02-23 Thread Jeff Lightner
And of course you can legitimately say it is a "Standard" even if it isn't enforced by the software. Your argument would be that people implementing new servers or attempting to access the systems wouldn't be able to do so because they wouldn't have added the "exception to Standard" that your PHB

Re: Hostname Naming Compliance

2009-02-23 Thread Gregory Hicks
> Date: Mon, 23 Feb 2009 19:07:31 + > From: Evan Hunt > To: "Eric C. Davis" > Subject: Re: Hostname Naming Compliance > Cc: "bind-users@lists.isc.org" > > On Mon, Feb 23, 2009 at 01:54:46PM -0500, Eric C. Davis wrote: > > I know the option to use this compliance checker is present, but I'm

Re: Hostname Naming Compliance

2009-02-23 Thread Chris Thompson
On Feb 23 2009, Evan Hunt wrote: On Mon, Feb 23, 2009 at 01:54:46PM -0500, Eric C. Davis wrote: I know the option to use this compliance checker is present, but I'm curious to know if there are plans to make it mandatory to comply. We aren't using this feature now, but I would like to. My pr

Re: Hostname Naming Compliance

2009-02-23 Thread Evan Hunt
On Mon, Feb 23, 2009 at 01:54:46PM -0500, Eric C. Davis wrote: > I know the option to use this compliance checker is present, but I'm > curious to know if there are plans to make it mandatory to comply. We > aren't using this feature now, but I would like to. My problem is > politicking my way

Re: Hostname Naming Compliance

2009-02-23 Thread Eric C. Davis
I know the option to use this compliance checker is present, but I'm curious to know if there are plans to make it mandatory to comply. We aren't using this feature now, but I would like to. My problem is politicking my way around the issue of breaking something that works. If Bind were to s

Re: Hostname Naming Compliance

2009-02-23 Thread Chris Buxton
On Feb 23, 2009, at 10:19 AM, Eric C. Davis wrote: Are there plans for Bind to enforce hostname compliance according to RFC's or is this going to be left up to each DNS operator? It's present in BIND 9.3 and later. All characters except a-z, A-Z, 0-9, and "-" itself are forbidden to appear

Hostname Naming Compliance

2009-02-23 Thread Eric C. Davis
Are there plans for Bind to enforce hostname compliance according to RFC's or is this going to be left up to each DNS operator? Eric Davis Rockefeller University ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listin

Re: comp.protocols.dns.bind

2009-02-23 Thread Chris Buxton
On Feb 20, 2009, at 1:05 AM, Hongyi Zhao wrote: Hi all, Suppose a file named file.pdf stored in the following web location: http://some_domain/path/to/file.pdf Where, the *some_domain* is a name-based virtual host. In this case, is it possible to set a ddns hostname, say through http://www.ch

Re: libbind 6.0b1 bug?

2009-02-23 Thread Evan Hunt
> Actually, it is a compile time problem. > > Is there a place on the isc.org website to report a bug on libbind? > > I ddn't see it anywhere. libbind-b...@isc.org -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. ___ bind-users mailing l

libbind 6.0b1 bug?

2009-02-23 Thread Jack Tavares
Actually, it is a compile time problem. Is there a place on the isc.org website to report a bug on libbind? I ddn't see it anywhere. Thanks -- Jack Tavares ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/b

Re: bind 9.60p1 on solaris 10

2009-02-23 Thread bsfinkel
In Mark Andrews writes: In message <937393c4-77a8-4dba-8a4f-14560c25c...@o11g2000yql.googlegroups.com>, >> SN writes: >>> >>> libcrypto.so.0.9.8 is not being found as a link library. Trying to >>> run as in a chroot'ed environment on solaris 10 (core install). >>> Kindly advise. >> Insta

Re: Is it possible to set a ddns hostname to access a name-based virtual host?

2009-02-23 Thread Serge Fonville
When using apache (you haven't told what web server you are using) you can define a virtual host which has a server name hongyi_zhao.changeip.net and a serveralias of some_domain. then apache will respond to urls which have either in the host header with the defined virtual host. This assumes that

Re: empty DoS queries

2009-02-23 Thread Stephane Bortzmeyer
On Mon, Feb 23, 2009 at 02:20:03PM +0100, Frank Kirschner <147...@celebrate.de> wrote a message of 65 lines which said: > 23-Feb-2009 13:20:15.516 queries: info: client 10.48.0.19#2048: query: > \(none\) IN A + I have no idea. But capturing such queries with something like: tcpdump -w dos-o

Re: rndc -> wrong number of zones

2009-02-23 Thread Chris Thompson
On Feb 23 2009, squid proxy wrote: thx, but what I cannot understand is: I have 2 internal DNS server: Master BIND 9.3.4-P1.1 (debian Etch) SLAVE BIND BIND 9.5.1-P1 (debian Lenny) they have the same number of zones, on both server is recursion yes and both have the same file zones.rfc1918 w

Re: bind 9.60p1 on solaris 10

2009-02-23 Thread SN
On Feb 19, 7:14 pm, Mark Andrews wrote: > In message > <937393c4-77a8-4dba-8a4f-14560c25c...@o11g2000yql.googlegroups.com>, > >  SN writes: > > Hi Group. > > > libcrypto.so.0.9.8 is not being found as a link library.  Trying to > > run as in a chroot'ed environment on solaris 10 (core install). >

Re: bind 9.60p1 on solaris 10

2009-02-23 Thread Gary Mills
In Mark Andrews writes: >In message <937393c4-77a8-4dba-8a4f-14560c25c...@o11g2000yql.googlegroups.com>, > SN writes: >> >> libcrypto.so.0.9.8 is not being found as a link library. Trying to >> run as in a chroot'ed environment on solaris 10 (core install). >> Kindly advise. > Install t

empty DoS queries

2009-02-23 Thread Frank Kirschner
Hello, since last night we log emtpty queries (approx. 4000 per seconds) like this from a client in our LAN: 23-Feb-2009 13:20:15.516 queries: info: client 10.48.0.19#2048: query: \(none\) IN A + 23-Feb-2009 13:20:15.518 queries: info: client 10.48.0.19#2048: query: \(none\) IN A + 23-Feb-200

empty DoS queries

2009-02-23 Thread Frank Kirschner
Hello, since last night we log emtpty queries (approx. 4000 per seconds) like this from a client in our LAN: 23-Feb-2009 13:20:15.516 queries: info: client 10.48.0.19#2048: query: \(none\) IN A + 23-Feb-2009 13:20:15.518 queries: info: client 10.48.0.19#2048: query: \(none\) IN A + 23-Feb-200

Is it possible to set a ddns hostname to access a name-based virtual host?

2009-02-23 Thread Hongyi Zhao
Hi all, Suppose a file named file.pdf stored in the following web location: http://some_domain/path/to/file.pdf Where, the *some_domain* is a name-based virtual host. In this case, is it possible to set a ddns hostname, say through http://www.changeip.net/, without using *some_domain* itself

Re: client query logging (refused message)

2009-02-23 Thread asdlkf
62.109.4.89 and 195.68.176.4 are compromized/attackers See my post here:http://www.linuxforums.org/forum/redhat-fedora-linux- help/140848-var-log-messages-question.html Sample log entries: Feb 19 08:24:17 asdlkf named[6459]: client 62.109.4.89#32721: query (cache) './NS/IN' denied Feb 19 08:24:18

comp.protocols.dns.bind

2009-02-23 Thread Hongyi Zhao
Hi all, Suppose a file named file.pdf stored in the following web location: http://some_domain/path/to/file.pdf Where, the *some_domain* is a name-based virtual host. In this case, is it possible to set a ddns hostname, say through http://www.changeip.net/, without using *some_domain* itself

Re: rndc -> wrong number of zones

2009-02-23 Thread squid proxy
thx, but what I cannot understand is: I have 2 internal DNS server: Master BIND 9.3.4-P1.1 (debian Etch) SLAVE BIND BIND 9.5.1-P1 (debian Lenny) they have the same number of zones, on both server is recursion yes and both have the same file zones.rfc1918 with the same zones. whay at master rn

Re: forward to a dns server with a port different of 53

2009-02-23 Thread Stefan Schmidt
On Mon, Feb 23, 2009 at 11:49:01AM +, Luis Silva wrote: > Hi all, Hi Luis, > I want to have two dns servers in the same machine, and I want the first > one to forward the dns messages to the second. The problem is that I don't > know how to configure bind to forward for a port different from

forward to a dns server with a port different of 53

2009-02-23 Thread Luis Silva
Hi all, I want to have two dns servers in the same machine, and I want the first one to forward the dns messages to the second. The problem is that I don't know how to configure bind to forward for a port different from 53. Is that possible? Many thanks. Kind Regards, Luis

Re: Zone serial not being updated in statistics-channel view of zone

2009-02-23 Thread Matus UHLAR - fantomas
> In message , Chris > Thom > pson writes: > > I have a dynamically updated zone, dynamic.local.test, on my workstation > > testbed (BIND 9.6.0-P1, Solaris 10_x86) which has "zone-statistics yes" > > set. Viewing the statistics at http://localhost:8053 I see under > > "Zones for View _default"