Re: Necessity of DNSSEC Lookaside Validation(DLV)

2009-04-09 Thread Mark Andrews
In message , Chandan Laskar writes: > > Thanks Bill. > > We have authoritative Name Server. Caching is not enable in the Name > Server. > > Also based on website > (http://www.netwidget.net/books/apress/dns/info/dlv.html), DLV is not an > IETF standarized feature and BIND 9.3.2 (We have 9.6

Re: Necessity of DNSSEC Lookaside Validation(DLV)

2009-04-09 Thread Mark Andrews
In message , Chandan Laskar writes: > > Thanks Mark. > > Can somebody provide me list of parent zone which has already signed? or > any website to get this information? You really only need to care if your parent zones are signed or not. The following tld's are current

Re: ip forwarding DNS 9.6.0

2009-04-09 Thread Mark Andrews
In message <83f1e37b-72bd-4454-8c2d-4fa91d5fc...@cs.moravian.edu>, myron writes : > On Apr 7, 2009, at 7:44 PM, Mark Andrews wrote: > > > > > In message , > > myron writes: > >> I started reading up on Kirk's suggestions of the allow-*** settings. > >> In the global options level > >> I put > >

Re: Necessity of DNSSEC Lookaside Validation(DLV)

2009-04-09 Thread Kevin Darcy
Chandan, Are you more interested in marking off bullet points on some "security compliance checklist", or actual, practical, real-world security? Just wondering... - Kevin Ch

RE: Necessity of DNSSEC Lookaside Validation(DLV)

2009-04-09 Thread Vyto Grigaliunas
The .gov TLD is now signed. See http://dotgov.gov/dnssecinfo.aspx for all of the details. Thanks. Vyto Fermi National Accelerator Lab _ From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Chandan Laskar Sent: Thursday, April

Re: Trouble configuring forwarders for reverse zones.

2009-04-09 Thread Chris Buxton
On Apr 9, 2009, at 9:59 AM, M-lists wrote: Much obliged Chris: I'll give that a go. Just out of interest though, how come you can't just specify a netmask? It seems convoluted to have such different ways of specifying reverse forwarders for classfull and classless Subnets. The answer is

RE: Trouble configuring forwarders for reverse zones.

2009-04-09 Thread M-lists
Much obliged Chris: I'll give that a go. Just out of interest though, how come you can't just specify a netmask? It seems convoluted to have such different ways of specifying reverse forwarders for classfull and classless Subnets. C. -Original Message- From: Chris Buxton [mailto:cbu

Re: ip forwarding DNS 9.6.0

2009-04-09 Thread myron
On Apr 7, 2009, at 7:44 PM, Mark Andrews wrote: In message , myron writes: I started reading up on Kirk's suggestions of the allow-*** settings. In the global options level I put options { directory "/etc/dns"; allow-query-cache { any; }; allow-query { any; };

Re: Necessity of DNSSEC Lookaside Validation(DLV)

2009-04-09 Thread Chandan Laskar
Thanks Mark. Can somebody provide me list of parent zone which has already signed? or any website to get this information? Also not understood about SEP. Can you please tell me what is the full form of that? Thanks and regards, Chandan Laskar 2nd Floor Data Center, ITC Center, 4, Russel St

RE: about allow-transfer

2009-04-09 Thread Todd Snyder
or allow-transfers { acl1; acl2; }; -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Jonathan Petersson Sent: Thursday, April 09, 2009 3:20 AM To: Jeff Pang Cc: Bind Mailing Subject: Re: about allow-transfer allow-transfer

Re: Necessity of DNSSEC Lookaside Validation(DLV)

2009-04-09 Thread Chandan Laskar
Thanks Bill. We have authoritative Name Server. Caching is not enable in the Name Server. Also based on website (http://www.netwidget.net/books/apress/dns/info/dlv.html), DLV is not an IETF standarized feature and BIND 9.3.2 (We have 9.6.0.-P1) is the current recommended implementation Versi

Re: bind 9.4 acache crashes

2009-04-09 Thread Sotiris Tsimbonis
On 9/4/2009 10:10 πμ, Sotiris Tsimbonis wrote: On 7/4/2009 12:09 μμ, Sotiris Tsimbonis wrote: On 6/4/2009 9:23 μμ, JINMEI Tatuya / 神明達哉 wrote: At Fri, 03 Apr 2009 18:38:01 +0300, Sotiris Tsimbonis wrote: Anyone else seen crashes like these? FWIW, I've never seen any of these. Solaris 10

Re: about allow-transfer

2009-04-09 Thread Jonathan Petersson
allow-transfer { slaveip; }; On Wed, Apr 8, 2009 at 11:42 PM, Jeff Pang wrote: > hello, > > I have two bind-9.6 (one master one slave) for product application. > how to set allow-transfer in master's named.conf? > shall it be: > > allow-transfer { none; }; > > or: > > allow-transfer { all; }; > >

Re: bind 9.4 acache crashes

2009-04-09 Thread Sotiris Tsimbonis
On 7/4/2009 12:09 μμ, Sotiris Tsimbonis wrote: On 6/4/2009 9:23 μμ, JINMEI Tatuya / 神明達哉 wrote: At Fri, 03 Apr 2009 18:38:01 +0300, Sotiris Tsimbonis wrote: Anyone else seen crashes like these? FWIW, I've never seen any of these. Solaris 10, Bind 9.4.3b2 Logfile: 10-Mar-2009 09:14:19.46