Re: delay between nsupdate and NOTIFY

2015-06-04 Thread Charles Musser
> > Adjust serial-query-rate. This also controls the notify rate in BIND 9.9. > A seperate control "notify-rate" is coming in BIND 9.11. > Today we tried increasing serial-query-rate from our original value of 1000 up to 5000 for a while, and then up to 1. The symptoms (long delay for NOTIF

Re: delay between nsupdate and NOTIFY

2015-06-04 Thread Mark Andrews
In message <13355440-2405-4868-b90c-6567ccb9d...@sonic.net>, Charles Musser wri tes: > We are experiencing a delay of approximately 9 minutes between the time a zon > e is changed on our DNS master (via nsupdate) and the time at which the NOTIF > Y is sent to slaves. Adjust serial-query-rate. Th

delay between nsupdate and NOTIFY

2015-06-04 Thread Charles Musser
We are experiencing a delay of approximately 9 minutes between the time a zone is changed on our DNS master (via nsupdate) and the time at which the NOTIFY is sent to slaves. We've turned up logging on the master and some slaves, then watched for messages regarding a test zone. On the master, an

Re: GSS-TSIG updates with multiple KSPs on the same BIND server?

2015-06-04 Thread John Marshall
On Thu, 04 Jun 2015, 23:04 +, Vinícius Ferrão wrote: > I always make my own krb5.conf file. Which krb bits on DNS you're talking > about? $ORIGIN example.com. _kerberos TXT "EXAMPLE.REALM" _kerberos._udp SRV 0 0 88 kdc1 SRV 0 0 88 kdc2 _kerberos._tcp SRV 0 0 88 kdc

Re: GSS-TSIG updates with multiple KSPs on the same BIND server?

2015-06-04 Thread Vinícius Ferrão
John, I always make my own krb5.conf file. Which krb bits on DNS you're talking about? Sent from my iPhone > On 04/06/2015, at 19:50, John Marshall > wrote: > > Chiming in to provide moral support due to lack of replies... > >> On 04/06/2015 06:44, Doug Barton wrote: >> Reading through manua

Re: GSS-TSIG updates with multiple KSPs on the same BIND server?

2015-06-04 Thread John Marshall
Chiming in to provide moral support due to lack of replies... On 04/06/2015 06:44, Doug Barton wrote: > Reading through manuals, HOWTOs, etc. on line it SEEMS possible that > BIND 9.8+ could be configured to use multiple KSPs. No experience to share with multiple KSP's/REALMS. Sorry :-( > What I

BIND slave server ignoring responses to all UDP-based SOA queries (zone refresh) for hours at a time

2015-06-04 Thread Irwin Tillman
Apologies in advance for this lengthy description. Since making I made a configuration change a few weeks ago, every 1-3 days, my BIND 9.9.7 server experiences several hours of retry/timeout failures while performing UDP-based SOA serial number queries (zone refresh). My server acts like it doesn