Re: Question about missing bind.keys

2022-03-29 Thread Evan Hunt
On Wed, Mar 30, 2022 at 12:16:05AM -0400, J Doe wrote: > I have a question about the bind.keys file and what happens when it is > not available. [...] > ** If I don't have bind.keys in my BIND directory but have: > dnssec-validation auto in my named.conf, is BIND automatically getting > the trus

Question about missing bind.keys

2022-03-29 Thread J Doe
Hello, I have a question about the bind.keys file and what happens when it is not available. According to the ARM: dnssec-validation This option enables DNSSEC validation in named. . . . (To prevent problems if bind.keys is not found, the current trust anchor is also co

Re: Periodic SERVFAIL for TLD .BY

2022-03-29 Thread Anand Buddhdev
On 29/03/2022 17:16, Ondřej Surý wrote: The .by domain is kind of bonkers… [snip] Sascha Pollok also ran into this issue with .BY. He asked me about it, and I found their setup to be very weird. TTL misalignment leads to sporadic SERVFAILs. Sascha posted about it to the dns-operations list:

Re: Periodic SERVFAIL for TLD .BY

2022-03-29 Thread Ondřej Surý
The .by domain is kind of bonkers… Step 1: get nameservers for 103.by: $ dig +noall +authority IN NS 103.by. @a.root-servers.net by. 172800 IN NS dns1.tld.becloudby.com. by. 172800 IN NS dns2.tld.becloudby.com. by.