what to do after received multiple NS record?

2009-05-19 Thread MontyRee
Hello, all. If client executes recursive query, client will receive some NS records like below. $ dig www.example.com example.com.172800 IN NS a.iana-servers.net. example.com.172800 IN NS b.iana-servers.net. if a.iana-servers.net. is

Re: choosing key for auto-signing

2009-05-19 Thread Mark Andrews
In message <200905200158.n4k1wmzv006...@edge.twig.com>, Richard Doty writes: > I am running bind 9.5.0, and have a dynamic zone with two ZSK set > up in the pre-publish manner - one ZSK is "published" but not used > for signing, one ZSK is "active" and signs all records. That's > how I use them w

choosing key for auto-signing

2009-05-19 Thread Richard Doty
I am running bind 9.5.0, and have a dynamic zone with two ZSK set up in the pre-publish manner - one ZSK is "published" but not used for signing, one ZSK is "active" and signs all records. That's how I use them when I do a full re-sign with dnssec-signzone. But when I make a dynamic update to the

Re: Are the TYPE65535 RRs necessary?

2009-05-19 Thread Mark Andrews
In message , Chris Tho mpson writes: > > So what are the TYPE65535 records actually for? > > Thanks to Evan Hunt and Mark Andrews for their replies. > > As I now understand it, then, TYPE65535 (or TYPE65534 - I would have seen > those as well if they had been created) RRs are used for initial si

"Malformed Transaction" after thawing large zone with lots of DDNS updates / BIND 9.6.0-P1

2009-05-19 Thread ip admin
Hi, A large zone is frozen with 'rndc freeze', changes are done to the zone file, DDNS updates are enabled again with 'rndc thaw'. I can see the following series of events in the logs (filtered): 05-May-2009 13:08:10.466 notify: info: zone corp.internal.com/IN: sending notifies (serial 201241049

Re: bind 9.4.2 secondary refusing request

2009-05-19 Thread Chris Buxton
On May 19, 2009, at 11:24 AM, Arno _ wrote: Hello, I'm having an issue with a bind 9.4.2 on Solaris 10, on the secondary the dns is refusing to answer to a request, and the same request is qnswered on the primary. here is the dig ouput on the secondary on 9.4.2: hyperion:~ $ dig @ns2.test i

Re: bind 9.4.2 secondary refusing request

2009-05-19 Thread Jeremy C. Reed
> Any clue why the 9.4.2 is refusing to answer ? 9.4.2 introduced allow-query-cache. (This is not a secondary, but using forwarding.) Try specifically setting allow-query-cache ACL as needed. ___ bind-users mailing list bind-users@lists.isc.org https://

Re: match-recursive-only vs configured zones

2009-05-19 Thread Chris Buxton
On May 19, 2009, at 10:50 AM, Matus UHLAR - fantomas wrote: On May 19, 2009, at 9:45 AM, Matus UHLAR - fantomas wrote: I'd like to know how does match-recurtsive-only view interact with configured zones. On 19.05.09 10:25, Chris Buxton wrote: The order of views matters. The first one matched,

bind 9.4.2 secondary refusing request

2009-05-19 Thread Arno _
Hello, I'm having an issue with a bind 9.4.2 on Solaris 10, on the secondary the dns is refusing to answer to a request, and the same request is qnswered on the primary. here is the dig ouput on the secondary on 9.4.2: hyperion:~ $ dig @ns2.test ifbp.ch ; <<>> DiG 9.3.5-P1 <<>> @ns2.test ifb

Re: match-recursive-only vs configured zones

2009-05-19 Thread Matus UHLAR - fantomas
> On May 19, 2009, at 9:45 AM, Matus UHLAR - fantomas wrote: >> I'd like to know how does match-recurtsive-only view interact with >> configured zones. On 19.05.09 10:25, Chris Buxton wrote: > The order of views matters. The first one matched, wins. > > Let's suppose you have a config along these

Re: match-recursive-only vs configured zones

2009-05-19 Thread Chris Buxton
On May 19, 2009, at 9:45 AM, Matus UHLAR - fantomas wrote: Hello, I'd like to know how does match-recurtsive-only view interact with configured zones. The order of views matters. The first one matched, wins. Let's suppose you have a config along these lines: view "resolver" { match-

Bind is hanging on CentOS 4.4

2009-05-19 Thread Jesse Cabral
I have been having an issue with Bind hanging for several months. I am currently running BIND 9.5.1-P2 on CentOS 4.4 kernel 2.6.9-42.0.3Elsmp as mail server using MailScanner, Postfix, spamassassin-clamav, openwebmail, pop-before-smtp. Binds was hanging with 9.2.4 as well so I upgraded to the c

match-recursive-only vs configured zones

2009-05-19 Thread Matus UHLAR - fantomas
Hello, I'd like to know how does match-recurtsive-only view interact with configured zones. When a zone is configured, clients accessing it are not recursive, unless it's forward (maybe stub?) zone... when I configure all zones in one view, and create other view using match-recursive-only, will

Re: BIND Slave Server won't update zones

2009-05-19 Thread Chris Buxton
On May 19, 2009, at 7:54 AM, Boris Dimitrov wrote: I want to have full automatic transfer from master to slave , if I create slave zones manual it's not a problem for master to update them, but i want to do this automatic if it is possible ? Can anybody help me with this ? I googled around but

BIND Slave Server won't update zones

2009-05-19 Thread Boris Dimitrov
Hi list, I've got some confusion with BIND master/slave servers that i'm trying to setup. First , i already have master that work well for our zones . The problem is my slave server didn't update from master when receive notify. all options are ok , but i got this error on slave : May 19 17:34:1

Re: Are the TYPE65535 RRs necessary?

2009-05-19 Thread Chris Thompson
So what are the TYPE65535 records actually for? Thanks to Evan Hunt and Mark Andrews for their replies. As I now understand it, then, TYPE65535 (or TYPE65534 - I would have seen those as well if they had been created) RRs are used for initial signing with a key, or removing signatures for a del

named querylog, cache hit

2009-05-19 Thread Anatoly Pugachev
Hello! This is a request to enhancement. Is it possible to make named querylog log somehow if clients query hit the server cache or not, not regarding to other logged query options (like +EDC). Thanks. ___ bind-users mailing list bind-users@lists.isc

Re: Odd config problem

2009-05-19 Thread Mark Andrews
In message <1875f6be-6efd-4cff-b724-e616c172f...@vallden.com>, Hans Vallden wri tes: > > On 18.5.2009, at 17:17, Mark Andrews wrote: > > >> I use the secure BIND template by Rob Thomas (http://www.cymru.com/Documen > ts/ > >> secure-bind-template.html > >> ). I have had a peculiar problem with t

Re: Odd config problem

2009-05-19 Thread Hans Vallden
On 18.5.2009, at 17:17, Mark Andrews wrote: I use the secure BIND template by Rob Thomas (http://www.cymru.com/Documents/ secure-bind-template.html ). I have had a peculiar problem with this template conf, which I have not been able to resolve. My problem is that some slave zones return REFU