Re: How to Setup a Name Servers visible on Internet?

2011-06-16 Thread Eric Kom
Good Morning all, I changed some settings in my zones data files but still have a same complaints: has 0 SOA records, has no NS records and not loaded due to errors. please see below my zone files: File: /var/cache/bind/metropolitanbuntu.co.za ;$ORIGIN metropolitanbuntu.co.za. $TTL 3H metropol

Re: question about thehartford.com domain

2011-06-16 Thread Mark Andrews
In message <4dfa62ca.7060...@gmail.com>, David Sparro writes: > On 6/15/2011 7:41 PM, M. Meadows wrote: > > > > The DNS admins at thehartford.com seem to feel that this nameserver > > mismatch is working as expected. > > > > So I'm just wondering if anyone still feels that the nameserver mismatch

Re: question about thehartford.com domain

2011-06-16 Thread Kevin Darcy
On 6/15/2011 7:41 PM, M. Meadows wrote: The DNS admins at thehartford.com seem to feel that this nameserver mismatch is working as expected. Here's some of the feedback we received from them when we questioned the setup: ~ We use load balancers for the majority of our i

Re: question about thehartford.com domain

2011-06-16 Thread David Sparro
On 6/15/2011 7:41 PM, M. Meadows wrote: The DNS admins at thehartford.com seem to feel that this nameserver mismatch is working as expected. So I'm just wondering if anyone still feels that the nameserver mismatch seen with the digs in earlier parts of this email thread may present a problem to

Re: ksk in a volume

2011-06-16 Thread Tony Finch
Niobos wrote: > > However, I don't see any security-benefits in this scenario: If the attacker > gets hold of the credentials to update the zone dynamically, he can do so in > both cases (KSK online or offline). If your server is compromised, he can > add/remove records in both cases. In case of Z

Re: ksk in a volume

2011-06-16 Thread Niobos
On 2011-06-15 15:51, Noel Rocha wrote: In this situation: - KSK signed ZSK(DNSKEY RR). - ZSK signing others RR of zone. I don't see reason for the KSK be present in operations unless add/delete RR DNSKEY. I had the same idea roughly a year ago. And while you're right, it doesn't change much in