Re: managed-keys update when outgoing UDP is blocked

2020-02-24 Thread Tony Finch
Branko Mijuskovic wrote: > > We have an authoritative DNS hidden master (bind-9.11.4-9) running behind > the network where outgoing UDP traffic to unlisted IPs is blocked. > > We are using DNSSEC and I've noticed that we are getting following errors > in the bind9 logfile: 'managed-keys-zone/defau

managed-keys update when outgoing UDP is blocked

2020-02-24 Thread Branko Mijuskovic
Hi All, We have an authoritative DNS hidden master (bind-9.11.4-9) running behind the network where outgoing UDP traffic to unlisted IPs is blocked. We are using DNSSEC and I've noticed that we are getting following errors in the bind9 logfile: 'managed-keys-zone/default: Unable to fetch DNSKEY s

Re: Security sssues with Ubuntu bind9 11.9.3 ?

2020-02-24 Thread Leroy Tennison
If you have a specific CVE you are concerned with, enter it at https://people.canonical.com/~ubuntu-security/cve/. Ubuntu does not update software version in response to security patches but this site gives current status. Ubuntu CVE Tracker S

Re: Advice on balancing web traffic using geoip ACls

2020-02-24 Thread Ondřej Surý
As far as we know the bug is present in all current BIND releases. We are still investigating the issue, but things are looking positive thanks to Vikor Dukhovni’s help with debugging his coredump. Ondřej -- Ondřej Surý — ISC > On 24 Feb 2020, at 11:08, Jukka Pakkanen wrote: > >  > Hi, at th

VS: Advice on balancing web traffic using geoip ACls

2020-02-24 Thread Jukka Pakkanen
Hi, at the download page the status of 9.16 is “Current-Stable” but it also states “only for testing & evalution, *not* recommended for production”? Can you confirm if the DNSSEC inline-signing problem (signing just stops sometimes, affects both 9.11 and 9.14 branch) is present in this or not?