Large RPZ with a lot of views.

2014-10-17 Thread Matt Doughty
Hi, I have a configuration with a lot of views and I want all of them to use the same RPZ zone with is 100K+ entries. It takes far too long to load all the views when I include the RPZ zone in each view as a master zone. I have tried: 1. setting up the zone at the top level, but you can't do that

Re: BIND listen backlog too small

2014-10-17 Thread Shawn Zhou
Thanks Cathy. The link you provided is very useful. On Friday, October 17, 2014 12:36 AM, Cathy Almond wrote: On 16/10/2014 23:52, Shawn Zhou wrote: > Thanks Mark. That's what I was looking for! > > > On Thursday, October 16, 2014 3:36 PM, Mark Andrews wrote: > > > > 2fd63cf5 (M

RE: Inline-signing feature request: Directly set the signed zone's serial number

2014-10-17 Thread Darcy Kevin (FCA)
FYI, If you had to do this all over again, and your tools are flexible enough to handle arbitrary RRTYPEs, you might consider using a "private" RRTYPE (in the 65280-65534 range). See http://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml#dns-parameters-4 and/or http://tools

Re: Inline-signing feature request: Directly set the signed zone's serial number

2014-10-17 Thread Chris Thompson
On Oct 8 2014, Tony Finch wrote: Terry Burton wrote: This is especially useful in bootstrapping scenarios where the zone data is held under strict revision control or generated by some provisioning system that "owns" the serial number. Our provisioning system used to think it owned zone ser

Re: BIND listen backlog too small

2014-10-17 Thread Cathy Almond
On 16/10/2014 23:52, Shawn Zhou wrote: > Thanks Mark. That's what I was looking for! > > > On Thursday, October 16, 2014 3:36 PM, Mark Andrews wrote: > > > > 2fd63cf5 (Mark Andrews 2003-04-10 02:16:11 + 279) > tcp-listen-queue ; > More info here too: https://kb.isc.org/artic