Re: Logging with Unencrypted DNS, DoT and DoH

2024-09-19 Thread Borja Marcos via bind-users
> On 17 Sep 2024, at 22:39, Bischof, Ralph F. (MSFC-IS64)[AEGIS] via bind-users > wrote: > > Hello, > BIND 9.18.7 > RHEL 8.10 (Oopta) > I am being asked if it is possible to differentiate the percentage of > queries coming into a server that are unencrypted, DoT and DoH. > Example: For

Re: Determining case of REFUSED queries

2024-09-19 Thread Mark Andrews
I think the reason for the REFUSED is pretty obvious % dig +norec google._domainkey.socialinnovation.ca @173.245.59.231 txt ; <<>> DiG 9.21.0-dev <<>> +norec google._domainkey.socialinnovation.ca @173.245.59.231 txt ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: RE

Determining case of REFUSED queries

2024-09-19 Thread J Doe
Hi list, I have BIND 9.18.29 validating recursive resolver running on OpenBSD 7.5. This resolver performs resolution for a mail server. Sometimes in my logs I will see the following: 17-Sep-2024 16:21:41.562 lame-servers: info: REFUSED unexpected RCODE resolving 'google._domainkey.so

Re: About dnstap feature

2024-09-19 Thread Ondřej Surý
I’m sorry, but the message and the image doesn’t match. If you believe there is a bug, please report it in a coherent way. Our GitLab has some guidances and there are many guides on the internet on how to write good bug reports. I particularly like Simon’s: https://www.chiark.greenend.org.uk/~s