Re: Primary/Secondary

2025-02-09 Thread Carsten Strotmann via bind-users
Hi, On 9 Feb 2025, at 7:35, Michael De Roover wrote: > I for > one look forward to seeing what people from various parts of the world have > to say about > it. I've been teaching DNS for over 30 years now, and I have always been uneasy using the old terms. I've used to "dance around" them, men

Re: Snapshot versions of BIND 9.18 and 9.20 for testing

2025-01-30 Thread Carsten Strotmann via bind-users
Hi Ondřej, On 31 Jan 2025, at 8:16, Ondřej Surý wrote: > We would appreciate if you can give the following git snapshots a test run > if you have a capacity to do so. I can report that 9.18.34-dev compiles and works fine on OpenBSD 7.6, and 9.20.6-dev compiles and works on NetBSD 10.1. My syst

Re: Problem upgrading to 9.18 - important feature being removed

2024-02-27 Thread Carsten Strotmann via bind-users
Hi Ondřej, > On 27. Feb 2024, at 16:43, Ondřej Surý wrote: > > Carsten, could you please fill a feature request in the GitLab? Done, #4606. Greetings Carsten -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this softwar

Re: Problem upgrading to 9.18 - important feature being removed

2024-02-27 Thread Carsten Strotmann via bind-users
Hi Jim, > On 27. Feb 2024, at 16:39, Jim P. via bind-users > wrote: > > There should also be an option to display the current configuration in > specific detail to easily create a new KASP (side question: why does DNS > need a new acronym?) The term “KASP” for “Key-and-signing-policy” has been

Re: Problem upgrading to 9.18 - important feature being removed

2024-02-27 Thread Carsten Strotmann via bind-users
Hi Matthijs, On 27 Feb 2024, at 15:54, Matthijs Mekking wrote: > - When migrating to dnssec-policy, make sure the configuration matches your > existing keys. the most problems I've seen so far have to do with this step: admins "think" they have created a configuration that matches the current

Old ZSK refuses to retire

2023-04-26 Thread Carsten Strotmann via bind-users
Hi, I have a situation where in a BIND 9 zone with dnssec-policy and inline-signing, after a ZSK rollover, the (old) ZSK is refusing to retire. Although the timing metadata shows the retire and deletion dates in the past, the ZSK is still in the zone and is signing the records (along with the n

KASP: sharing policy and keys between views

2023-03-17 Thread Carsten Strotmann via bind-users
Hi, (please do not start a discussion on the usefulness of views. I'm not in favor of views, but sometimes I have to work with them). I have a client that runs a split horizon (internal / external view of the same domain namespace) setup with BIND 9 on Linux. Both the internal and external vie