Re: VS: Change DNSSEC algorithm and switch to use KASP

2020-04-27 Thread Matthijs Mekking
Hi, If you want to switch to KASP with the a different algorithm, you should be able to use BIND 9.16.2 and just reconfigure your zone to use "dnssec-policy". The existing keys will be removed in a timely manner, while named creates new keys with the new algorithm. Make sure you will submit

Re: Bind suddenly starts responding clients with servfail

2020-04-27 Thread Søren Andersen
The only dns request my server are handling now is just some monitoring dns request.. It's just a few dns request / min, not much. Even the 'rndc' command cannot get any answer from the named process 😕- It looks like named don't even handle the incoming traffic from rndc command, since my revc-

Re: Bind suddenly starts responding clients with servfail

2020-04-27 Thread Frey, Rick E
Recursive clients are lookups/clients on your nameserver on behalf of a query received. If you are seeing that your nameserver is running out of recursive clients after removing “all” traffic, it would indicate something is still querying your nameserver as BIND won’t spontaneously create recur

Bind suddenly starts responding clients with servfail

2020-04-27 Thread Søren Andersen
Hello List, I'm running a few BIND servers, but lately one of my servers suddenly starts responding to clients with servfail for every request from the clients, and BIND doesn't respond to the rndc or statistics interface anymore. My logs for client-channel show me this: 25-Apr-2020 21:52:04.50