Re: bind9 cache

2010-12-04 Thread Mark Andrews
In message <20101204170822.94482eupddwii...@www.jersore.net>, Benny Pedersen wr ites: > > i like to have bind cache in 43200 secs for any zone and update only > if soa changes in that time, how do i configure named.conf to do this ? You can set a maximum bound on how long named will cache reco

Re: DS queries on parents vs. "correct behaviour" in answering

2010-12-04 Thread Mark Andrews
Mark Andrews writes: > > In message <02d001cb93f5$513ca2b0$f3b5e8...@janssen@eurid.eu>, "Peter Janssen > " > writes: > > When a validating resolver queries the parent of a zone for the DS > > record(s), > > and the (child) zone is NOT signed, the response contains no answer > > but it does cont

Re: DS queries on parents vs. "correct behaviour" in answering

2010-12-04 Thread Mark Andrews
In message <02d001cb93f5$513ca2b0$f3b5e8...@janssen@eurid.eu>, "Peter Janssen" writes: > When a validating resolver queries the parent of a zone for the DS > record(s), > and the (child) zone is NOT signed, the response contains no answer > but it does contain NSEC (NSEC3) record(s) in the autho

Re: Private Zones and Deligation bind9.7.2

2010-12-04 Thread Barry Margolin
In article , Martin McCormick wrote: > After setting up a private zone which should have deligated > queries to some Microsoft DNS's, I received a report that an > additional host in that domain did not resolve. They were right. > I had to put an A record in my deligated zone for that system to

Re: bind9 cache

2010-12-04 Thread Barry Margolin
In article , Benny Pedersen wrote: > i like to have bind cache in 43200 secs for any zone and update only > if soa changes in that time, how do i configure named.conf to do this ? > > negative cache i like to have as the zone says in ttl, so just 43200 > on positive You can't. You can con

Private Zones and Deligation bind9.7.2

2010-12-04 Thread Martin McCormick
After setting up a private zone which should have deligated queries to some Microsoft DNS's, I received a report that an additional host in that domain did not resolve. They were right. I had to put an A record in my deligated zone for that system to make it resolve so I think I have something set

DS queries on parents vs. "correct behaviour" in answering

2010-12-04 Thread Peter Janssen
When a validating resolver queries the parent of a zone for the DS record(s), and the (child) zone is NOT signed, the response contains no answer but it does contain NSEC (NSEC3) record(s) in the authority section together with corresponding RRSIG records (parent zone is signed). Would it be consi

bind9 cache

2010-12-04 Thread Benny Pedersen
i like to have bind cache in 43200 secs for any zone and update only if soa changes in that time, how do i configure named.conf to do this ? negative cache i like to have as the zone says in ttl, so just 43200 on positive -- xpoint ___ bind-use