Re: lists subdomain not fully working [SOLVED]

2015-05-26 Thread Lucio Crusca
On May 26, 2015 at 19:27, Niall O'Reilly wrote: TTL and same subnet can't matter. I had in mind rather the warning about the SOA MNAME. You the man! I totally overlooked those messages by zonemaster just because of their green background color, which was meaning to me "these are the OK thi

Re: RRL settings that work for you

2015-05-26 Thread Noel Butler
On 27/05/2015 07:00, Mike Hoskins (michoski) wrote: > Hi folks, > > I've read about RRL with interest since its inception, but just now > getting around to rolling it out. That is partially because we run a very > small authoritative infrastructure serving mostly as Akamai EDNS origins. > How

Re: key-restricted nsupdate of internal view's zone's host REFUSED with 'signer "" denied' ?

2015-05-26 Thread PGNd
On Tue, May 26, 2015, at 02:32 PM, Mark Andrews wrote: > You can't update multiple views with a single update message. Use > two update commands. The update is being processed by the first > view and the policy in the internal zone doesn't allow you to update > *every* record you are attempting

Re: bind9 Numerous recent - error (FORMERR) resolving 'dns3.registrar-servers.com/AAAA/IN'

2015-05-26 Thread Mark Andrews
Well 208.67.220.220 returns the wrong SOA record which is why you are getting the message. For that matter why are you talking to 208.67.220.220 in the first place? It is not normally involved in resolving dns2.registrar-servers.com. registrar-servers.com. 2898IN NS dns1.name-ser

bind9 Numerous recent - error (FORMERR) resolving 'dns3.registrar-servers.com/AAAA/IN'

2015-05-26 Thread David C. Rankin
All, I have run bind8 and bind9 for the past 15 years beginning on Mandrake before it went corporate and tanked. Over the past few weeks to a month or so, my logs have been filling with (FORMERR) messages like: May 26 16:44:24 nirvana named[23136]: DNS format error from 208.67.222.222#53 r

Re: key-restricted nsupdate of internal view's zone's host REFUSED with 'signer "" denied' ?

2015-05-26 Thread Mark Andrews
You can't update multiple views with a single update message. Use two update commands. The update is being processed by the first view and the policy in the internal zone doesn't allow you to update *every* record you are attempting to update so the whole update is refused. Also use two differe

Re: random latency in named

2015-05-26 Thread Mike Hoskins (michoski)
FWIW as another data point we've seen the same in the wild across RHEL/CentOS 5.x and 6.x on "large" (32 core) Xeon based servers (E5-2650's), including 6.6 with the 2.6.32-504.16.2.el6.x86_64 kernel. Observed while debugging other things, and haven't had time to follow up. -Original Message--

RRL settings that work for you

2015-05-26 Thread Mike Hoskins (michoski)
Hi folks, I've read about RRL with interest since its inception, but just now getting around to rolling it out. That is partially because we run a very small authoritative infrastructure serving mostly as Akamai EDNS origins. However, since it is exposed externally, used by a few tenants and RRL

key-restricted nsupdate of internal view's zone's host REFUSED with 'signer "" denied' ?

2015-05-26 Thread PGNd
I run named -v BIND 9.10.2 in split-horizon mode with two views view "internal" { view "external" { For a single zone MYDOMAIN.com I'm targeting two hostnames in the zone test.MYDOMAIN.com external.test.MYDO

Re: lists subdomain not fully working

2015-05-26 Thread Lucio Crusca
Il 25/05/2015 15:39, Niall O'Reilly ha scritto: On Mon, 25 May 2015 11:26:58 +0100, Lucio Crusca wrote: I moved my bind installation to a new server two weeks ago and I copied the zones verbatim: on the old server everything was working ok. More precisely, you weren't aware of a problem, w