Re: DNSSEC and forwarding

2022-03-30 Thread Tony Finch
Duchscher, Dave J via bind-users wrote: > We have an internal DNS server that we would like to forward its > outgoing queries to a main DNS server that connects to the outside world > and is doing DNSSEC validation. The problem is that the DNSSEC > validation doesn't work for queries from the in

DNSSEC and forwarding

2022-03-30 Thread Duchscher, Dave J via bind-users
We have an internal DNS server that we would like to forward its outgoing queries to a main DNS server that connects to the outside world and is doing DNSSEC validation. The problem is that the DNSSEC validation doesn't work for queries from the internal DNS server. Doing DNSSEC validation on

Re: Periodic SERVFAIL for TLD .BY

2022-03-30 Thread Dzmitry Shykuts
"servfail-ttl 0" doesn't help. вт, 29 мар. 2022 г. в 18:16, Ondřej Surý : > The .by domain is kind of bonkers… > > Step 1: get nameservers for 103.by: > > $ dig +noall +authority IN NS 103.by. @a.root-servers.net > by. 172800 IN NS dns1.tld.becloudby.com. > by.

Expired secondary zone retry-interval?

2022-03-30 Thread Oskar
Hi! I just experienced an outage where a zone is defined via catalogzone and the following is set: SOA Refresh 900 SOA Retry 300 SOA Expiry 3600 (i'm aware it's very short) Primary was intermittently unreachable and had wrong config for about 1.5h. According to logs the Secondary was retrying tr