Re: DNSTAP overload condition logging

2021-11-19 Thread Carsten Strotmann
Hi Chris, Chris Buxton writes: [[PGP Signed Part:Undecided]] Hi Carsten, From our reading of the code, it appears that when the buffer fills up, it refuses to accept new entries. Older events are not overwritten, but newer events are refused. The fstrm_iothr_submit() function can return su

Re: ***UNCHECKED*** Re: DNSSEC implementation on IPv6 PTR Zones

2021-11-19 Thread raf
On Thu, Nov 18, 2021 at 09:47:03AM -0700, Grant Taylor via bind-users wrote: > On 11/18/21 3:14 AM, Mark Elkins wrote: > > With IPv6 - you might want to use NSEC3 - as there can be huge holes in > > the reverse zone. Make the bad guy work at guessing what is in the zone. > > Be mindful of curre

RHEL, Centos, Fedora rpm 9.16.23

2021-11-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies. -

Re: DNSTAP overload condition logging

2021-11-19 Thread Chris Buxton
Hi Carsten, From our reading of the code, it appears that when the buffer fills up, it refuses to accept new entries. Older events are not overwritten, but newer events are refused. The fstrm_iothr_submit() function can return success, failure, or “fstrm_res_again”, which indicates the queue is

Found the bug (was: ERROR: Failed to create fetch for DNSKEY update)

2021-11-19 Thread Peter
Hija, I finally found the cause of the error! As soon as I stop slaving the root-zones and instead use the (configured or compiled-in) hint-file, the error stops. The actual error-condition (zone is not loaded) then becomes obvious, because this RFC-5011 action happens very early, before any