Re: dnssec-signzone ignoring "-x" option?

2012-09-17 Thread Evan Hunt
> Does anyone use dnssec-signzone with -x? If so, can you check/tell me > your DNSKEY RRset? And if it works, could you reveal the full > commandline argument used, the bind version, and whether any pkcs#11 > provider was compiled in? I just tested it with "dnssec-signzone -Sx example.com" and "dn

dnssec-signzone ignoring "-x" option?

2012-09-17 Thread Paul Wouters
Hi, I'm looking at creating "identical zones" with two independantly developed dnssec signers (bind + opendnssec). I stumbled upon three differences, one of which might be a bug in bind. opendnssec does not easilly allow the DNSKEY RRset to be signed with both KSK and ZSK. So I was looking at u

Re: What can cause excessive amount of _dns-sd queries?

2012-09-17 Thread Matus UHLAR - fantomas
On 23.08.12 13:43, Eivind Olsen wrote: I haven't seen this before.. I'm currently seeing someone (1 ip address) do about 2.1 million queries / hour where a majority of the queries seem to be: b._dns-sd._udp.0.129.16.172.in-addr.arpa IN PTR + db._dns-sd._udp.0.129.16.172.in-addr.arpa IN PTR + r._