I need you help to separate the DNSSEC validation process

2018-11-19 Thread Fatemah Alharbi
Hi all, I need to setup my lab network to have my recursive DNS server (which runs bind v9.9.5) to be able to make partial DNSSEC validation where the client should be able to make the other half of the validation process. In particular, I need the DNS resolver to be able to validate the root a

Re: BIND9.11.4-P1] What happens Combination with dnssec-enable yes; dnssec-validation no; in named.conf

2018-11-19 Thread Tony Finch
Sunghwan Kim(IBI) wrote: > > I would like to know what happens if dnssec-enable yes; dnssec-validation > no; in named.conf are being setting. > > Does it come SERVFAIL ? No. (But see * below...) `dnssec-enable` is to do with handling of DNSSEC records and query flags: setting and recognizing the

BIND9.11.4-P1] What happens Combination with dnssec-enable yes; dnssec-validation no; in named.conf

2018-11-19 Thread Sunghwan Kim(IBI)
Hi All, My running server is BIND-9.11.4-P1. I would like to know what happens if dnssec-enable yes; dnssec-validation no; in named.conf are being setting. Does it come SERVFAIL ? Regards, Sunghwan. -- (주)아이비아이(www.ibi.net) DNS사업부/본부장 02-2165-7234/01

Re: forwarder selection logic by bind9

2018-11-19 Thread József Lázár
Did you have a chance to look at my email below? Thanks again, Joe On Tue, 13 Nov 2018 at 10:42, József Lázár wrote: > Ok, I see. However, could you please specify this "time to time" period? > Does it depends of the dns traffic which the bind receives? > I've tried the following scenario: > Con