Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Dan Parrish via bind-users
my config not being close-enough to stock for the new container to load successfully. An easy issue to understand and fix with the logging change you made. Thanks! --dan -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of thi

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Dan Parrish via bind-users
had basic logging, I could provide more information, possibly even resolved the issue and reported the fix. Can we get logging to work? --dan -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support sub

Re: Documentation on readthedocs - links to older releases return 404 errors

2023-05-31 Thread Dan Mahoney
s version. > > While reading you message I realized that we messed it up and old links with > underscore (e.g. v9_18_10 as opposed to v9.18.10) indeed do not work. > > I'll see if we can restore the old links, but I cannot promise any specific > timeline. Hey there FastEd

Re: Mailing list questions (DMARC, ARC, more?)

2022-10-06 Thread Dan Mahoney
> On Sep 27, 2022, at 02:50, Alessandro Vesely wrote: > > Hi Dan, > > > On Sat 24/Sep/2022 01:10:12 +0200 Dan Mahoney wrote: >>> On Aug 23, 2022, at 07:39, G.W. Haywood via bind-users >>> wrote: >>> On Tue, 23 Aug 2022, Alessandro Vesely

Re: Mailing list questions (DMARC, ARC, more?)

2022-09-23 Thread Dan Mahoney
#x27;we looked at this every step of the way, and it looked good to us. ' === To the best of my knowledge, we're the only folks doing this -- mailman 3 is supposed to implement its own arc-sealing, but 2.x won't ever. Mailman 2.x is largely EOL (but receiving security fixes -

Re: Supporting LOC RR's

2022-05-03 Thread Dan Mahoney
all the info you need would be “in the DNS”. The fun derivation of “shortest distance with highest latency” is a fun exercise for the audience. -Dan > On May 3, 2022, at 3:07 AM, Tony Finch wrote: > > Timothe Litt wrote: >> On 02-May-22 09:02, Stephane Bortzmeyer wrote:

Testing, please ignore

2022-04-25 Thread Dan Mahoney (Gushi)
Testing, please ignore. -Dan -- -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list

testing, please ignore

2022-04-25 Thread Dan Mahoney (Gushi)
Sorry for the noise -- -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lis

test, please ignore

2022-04-25 Thread Dan Mahoney (Gushi)
Thanks, subject is all. -- Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC FB: fb.com/DanielMahoneyIV LI: linkedin.com/in/gushi Site: http://www.gushi.org --- -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Is anyone here forwarding your bind-users messages to gmail or a google-hosted domain?

2022-04-19 Thread Dan Mahoney
rom/to/spf/dkim/dmarc status. We can't easily inspect individual messages. If this sounds like you, please do drop me a line privately at dmaho...@isc.org. I'd love to work with you to ensure I understand what's going on and also see if we can make things work better for eve

Re: test - ignore

2022-01-25 Thread Dan Mahoney
g header.i=@isc.org header.b=q/vOEba5; > dkim=fail reason="signature verification failed" (1024-bit key; > unprotected) header.d=isc.org header.i=@isc.org header.b=ozeUkO/Z > > dont know why it failed I may as well answer this since other people chimed in on the test

One more test -- sorry for the noise

2022-01-25 Thread Dan Mahoney
Sorry for the noise, attempting to validate a DKIM issue ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://

test -- please ignore

2022-01-25 Thread Dan Mahoney
testing, please ignore ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more info

Re: BIND caching of nxdomain responses

2021-10-22 Thread Dan Hanks
On Fri, Oct 22, 2021 at 9:57 AM Dan Hanks wrote: > > Greetings, > > As I understand RFC 2308, when receiving an NXDOMAIN response, and when > deciding how long to cache that NXDOMAIN response, a resolver should use > whichever value is lower of the SOA TTL, and the SOA.mi

Re: BIND caching of nxdomain responses

2021-10-22 Thread Dan Hanks
On Fri, Oct 22, 2021 at 10:29 AM Matus UHLAR - fantomas wrote: > > On 22.10.21 09:57, Dan Hanks wrote: > >As I understand RFC 2308, when receiving an NXDOMAIN response, and when > >deciding how long to cache that NXDOMAIN response, a resolver should use > >whichever value

BIND caching of nxdomain responses

2021-10-22 Thread Dan Hanks
they disagree)? Thanks for any insight, Dan ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org

lists.isc.org upgrade

2021-09-26 Thread Dan Mahoney
Greetings bind-users netizens. Dan Mahoney here, ISC sysadmin/devops person. We've upgraded the underlying server that lists.isc.org runs on, as well as an upgrade to mailman (still in the 2.x line). This means any searchable archives will have to rebuild over the next day, Please repor

lists.isc.org upgrade (newer mailman, newer OS)

2021-09-26 Thread Dan Mahoney
Greetings bind-users netizens. Dan Mahoney here, ISC sysadmin/devops person. We've upgraded the underlying system that lists.isc.org runs on, as well as an upgrade to mailman (still in the 2.x line). This means any searchable archives will have to rebuild over the next day. Please repor

Testing, please ignore

2021-09-26 Thread Dan Mahoney
testing, please ignore ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more info

Re: configure notify for ixfer?

2021-06-01 Thread Dan Sjolseth via bind-users
Inside the zone statement of the primary add: also-notify { ipofsecondary }; This will make transfer in microseconds. Let me know if it works for you. Dan On Jun 1, 2021, at 7:24 PM, Mark Andrews wrote:  On 2 Jun 2021, at 01:18, Cuttler, Brian R (HEALTH) via bind-users wrote: My dns

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-16 Thread Dan Egli via bind-users
  3600    IN      NS  uz5w6sb91zt99b73bznfkvtd0j1snxby06gg4hr0p8uum27n0hf6cd.free.ns.buddyns.com. -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. On 16. 5. 2021, at 8:45, Dan Egli via bind-users wrote: Upgrade to WHAT? You said it

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-15 Thread Dan Egli via bind-users
Upgrade to WHAT? You said it was fixed in 9.11.25, but isn't that a lot OLDER than 9.16.15, which is what I'm running? jupiter ~ # named -v BIND 9.16.15 (Stable Release) jupiter ~ # dig -v DiG 9.16.15 On 5/16/2021 12:06 AM, Mark Andrews wrote: On 16 May 2021, at 10:17, Dan Egl

Re: Inline signing fails dnsviz test - STILL [LONG]

2021-05-15 Thread Dan Egli via bind-users
On 5/10/2021 12:38 PM, Tony Finch wrote: Dan Egli wrote: Still not working for me. The dig doesn't report anything, and I don't HAVE a keyfile since i'm using inline signing. Or does inline signing still require a key to be generated? Yes, you need to do your own key managem

Re: Inline signing fails dnsviz test.

2021-05-10 Thread Dan Egli via bind-users
Okay, so I added the policy, and things MOSTLY look okay. But when I retake the verification test, I get errors about no RRSIGs found. What do I do to resolve that issue? On 5/10/2021 12:38 PM, Tony Finch wrote: Dan Egli wrote: Still not working for me. The dig doesn't report anything

Re: Inline signing fails dnsviz test.

2021-05-10 Thread Dan Egli
On 5/10/2021 12:17 PM, Tony Finch wrote: Dan Egli wrote: Where do I get the DS record, since i'm using bind's inline signing? Use the dnssec-dsfromkey tool, e.g. from a key file (make sure it's the KSK file) $ grep This Kcam.ac.uk.+013+32840.key ; This is a

Re: Inline signing fails dnsviz test.

2021-05-10 Thread Dan Egli
here do I get the DS record, since i'm using bind's inline signing? On 5/10/2021 3:29 AM, John W. Blue via bind-users wrote: Hello Dan. Does your registrar have the ability via a UI to place a DS record in the .name zone? And if so, have you done

Bind won't listen

2021-05-07 Thread Dan Egli
interfaces Why not? My config file specifically says listen-on { 0.0.0.0; }; and listen-on-v6 { ::; }; -- Dan Egli From my Test Server OpenPGP_0x11B7451DF2015959.asc Description: OpenPGP public key OpenPGP_signature Description: OpenPGP digital signature

Re: Bind refusing my DKIM key

2021-05-06 Thread Dan Egli
the tool that created this record that it is INVALID as the field length is TOO BIG. On 7 May 2021, at 14:35, Dan Egli wrote: I don't know what's up, but when I tried to put my DKIM into the test server, named-checkzone keeps giving a syntax error on the key line. Here's w

Bind refusing my DKIM key

2021-05-06 Thread Dan Egli
qbWxlZWRsdz09IA==" But when I run checkzone: dns_rdata_fromtext: myzone.zone:26: syntax error zone eglifamily.name/IN: loading from master file myzone.zone failed: syntax error What's wrong? Why is it failing? -- Dan Egli From my Test Server OpenPGP_0x11B7451DF2015959.

lists.isc.org and DMARC

2021-02-16 Thread Dan Mahoney
Greetings bind-users netizens. Dan Mahoney, ISC SysAdmin here. This is a message about lists.isc.org and DMARC. If you aren't concerned with DMARC, you can ignore it. Over a year ago, we added adaptations to lists.isc.org to allow mail from DMARC-protected domains to be delivered

Re: bind refusing update [never mind]

2020-12-18 Thread Dan Egli
on using that interface. On 12/18/2020 11:59 PM, Dan Egli wrote: I'm really stumped as to what's going on. I'm trying to get dhcpd to automatically update name records for my internal network. This is NOT going to the public internet by any means. It's just an internal network. B

bind refusing update

2020-12-18 Thread Dan Egli
ost.zone";     notify no; }; zone "eglifamily.name" {     type master;     file "pri/eglifamily.zone";     notify yes; }; zone "10.168.192.in-addr.arpa" {     type master;     file "pri/10.168.192.arpa.zone";     notify yes;

Re: statistics file initially created with incorrect permissions

2019-01-21 Thread Dan Langille
> On Jan 21, 2019, at 7:53 PM, Mark Andrews wrote: > >> On 22 Jan 2019, at 2:53 am, Dan Langille wrote: >> >> I'm running bind911-9.11.5P1_2 on FreeBSD 11.2-RELEASE-p8 >> >> bind is running fine, except for the statistics file, which gets created &g

statistics file initially created with incorrect permissions

2019-01-21 Thread Dan Langille
of the file the server appends statistics to when instructed to do so using rndc stats." named seems to be doing this automatically, as opposed to an external cronjob created by myself. 2 - Is the documentation misleading in this regard? Thank you. -- Dan Langille - BSDCan / PGCon d...@lan

Re: Separate DNS slaves as internal and external

2018-03-22 Thread McDonald, Daniel (Dan)
I've hidden those sort of things using response policy zones. On 3/19/18, 6:34 AM, "bind-users on behalf of King, Harold Clyde (Hal)" wrote: I have DNS slaves for internal and external entities. I don't know how to work the NS records so that outside users would only get the external slav

Testing

2018-02-13 Thread Dan Mahoney
Please ignore -- just testing post mailman upgrade. Best, -Dan Mahoney ISC Operations Group ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: dkim cname records replication

2017-05-22 Thread McDonald, Daniel (Dan)
ersion my distro provides ( they call it 9.9.1-400, or something like that. Every security patch applied, since 9.9.1, some of the bug fixes applied) Get Outlook for iOS<https://aka.ms/o0ukef> On Mon, May 22, 2017 at 9:11 PM -0500, "Mark Andrews" mailto:ma...@isc.org>> wrote:

Re: dkim cname records replication

2017-05-22 Thread McDonald, Daniel (Dan)
f> On Mon, May 22, 2017 at 8:45 PM -0500, "Mark Andrews" mailto:ma...@isc.org>> wrote: In message , "McDonald, Daniel (Dan)" writes: > You need to add check-names ignore; to the zone definition when dealing > with active directory. That ignores the invali

Re: dkim cname records replication

2017-05-22 Thread McDonald, Daniel (Dan)
You need to add “check-names ignore; “ to the zone definition when dealing with active directory. That ignores the invalid underscore character. From: bind-users on behalf of Vidal Garza Date: Monday, May 22, 2017 at 10:31 To: Bind Users Subject: dkim cname records replication Hello List,

global server load balancing with the domain name

2017-04-14 Thread McDonald, Daniel (Dan)
Setting up global server load balancing seems easy enough – just add ns records pointing at the load balancer and away you go: example.com. 38400INSOAns20.example.net. dan\.mcdonald.example.com. 2017011107 10800 3600 604800 3600 example.com. 38400IN

Re: Difference between delegation and forward zone

2017-03-06 Thread McDonald, Daniel (Dan)
Yes, you can forward to a subdomain. Just define it as a separate zone and include the forwarders and forward-only lines. I believe you need allow-query-cache for this to work. Delegated zones don’t necessarily need to respond with SOA and NS records. Many load balancers use delegated zones

Test, please ignore

2016-11-20 Thread Dan Mahoney
Sorry for the noise ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: defines ip to acl

2016-10-17 Thread McDonald, Daniel (Dan)
Acls don’t support ranges, only prefixes. You don’t want the whole /24. I think you want: acl net1 {192.168.1.0/26; 192.168.1.64/27; 192.168.1.96/30; } acl net2 {192.168.1.100/30; 192.168.104/29; 192.168.1.112/28; 192.168.1.128/26; 192.168.1.192/29; } On 2016-10-17, 13:41, "bind-users on be

Re: Load balancer for Bind

2016-09-14 Thread McDonald, Daniel (Dan)
I’ve had great success using A10networks Thunder series and AX series for load balancing dns servers, performing GSLB, and for setting up anycast addresses for dns. On 2016-09-14, 11:18, "bind-users on behalf of Job" wrote: Hello, which is the best load balancer for two or more

Testing SMTP

2016-06-24 Thread Dan Mahoney
Sorry for the noise, please ignore. -Dan Mahoney ISC Ops team ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind

Testing

2016-06-24 Thread Dan Mahoney
testing ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Assertion failure when RPZ zone returns NS records?

2016-06-11 Thread McDonald, Daniel (Dan)
Apparently it’s not the way to do what I needed, but I created an RPZ record like this: foo.example.com IN NS ns1.example.org IN NS ns2.example.org My goal was to redirect queries to a load balancer serving foo.e

Re: Reducing memory usage by using db storage - performance?

2016-03-24 Thread McDonald, Daniel (Dan)
> On Mar 24, 2016, at 6:28 AM, MURTARI, JOHN wrote: > > Folks, > Recently been looking at servers that host almost 200K ARPA > zones and load about 80 million resource records. They run on good hardware > and take only a few minutes to load the zones on a clean start. The i

Re: monitoring/graphing/tracking named queries

2015-11-13 Thread McDonald, Daniel (Dan)
On 11/13/15, 4:46 PM, "bind-users-boun...@lists.isc.org on behalf of Frank Even" wrote: >What does everyone do for monitoring their DNS traffic, if anything? We feed the query-logs into splunk, so they can be correlated with all of the other network logs >I've come to a place where I need to

different answers for different users - are views my only option?

2015-06-11 Thread McDonald, Dan
We have an application that that has application servers burried deep behind a few layers of reverse proxies and load balancers, but has a hard-coded server address in a returned java applet. To allow the java applets to work, someone here started deploying host files containing the app servers

Test (please ignore)

2014-05-01 Thread Luther, Dan
Dan Luther Operations Engineer Systems Operation Engineering Level 3 Communications One Technology Center, Tulsa OK 74103 p: 918-547-4370 e: dan.lut...@level3.com<mailto:name.n...@level3.com> ___ Please visit https://lists.isc.org/mailman/li

One final test.

2014-04-22 Thread Dan Mahoney
Sorry again for the noise. -Dan ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Testing, please ignore

2014-04-22 Thread Dan Mahoney
Sorry for the noise. -Dan ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Testing, please ignore

2014-04-22 Thread Dan Mahoney
Sorry for the noise. -Dan Mahoney ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Delegation of part of a zone to a global server load balancer

2014-04-08 Thread McDonald, Dan
On Mon, 7 Apr 2014 18:08:57 –0400, Kevin Darcy mailto:k...@chrysler.com>> wrote: I'm assuming you have forwarding set up. Make sure to set "forwarders { };" in the aelabad.net zone definition. Failure to do so means that your recursive queries for names in subzones forward out towards the Inte

Re: Delegation of part of a zone to a global server load balancer

2014-04-07 Thread McDonald, Dan
<- opcode: QUERY, status: NOERROR, id: 3701 >;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0 >... >;; ANSWER SECTION: >gsstest.domain.com. 3599IN CNAME >gsstest.domain.com.gslb.domain.com. >gsstest.domain.com.gslb.domain.com. 19 IN A ip.ad.dr.es >... > > >-Or

Delegation of part of a zone to a global server load balancer

2014-04-07 Thread McDonald, Dan
What’s the right way to delegate individual zone records to a “global server load balancer”, which is just a simple DNS server that checks to see if a server is up and if so adds the address to the rotation for resolution. I’ve tried simple delegation using ns records, but I don’t get resolution

What is proper fault-tolerant behavior?

2013-09-16 Thread Dan McDaniel
ding how this should work? -- Dan ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

RE: Reinstall after modifying

2013-08-21 Thread McDonald, Dan
-Original Message- From: bind-users-bounces+dan.mcdonald=austinenergy@lists.isc.org on behalf of Maria Sent: Wed 21-Aug-13 16:18 To: ngiw2...@hotmail.com Cc: bind-users@lists.isc.org Subject: Re: Reinstall after modifying On Wed, Aug 21, 2013 at 08:18:36PM +0200, Jan-Piet Mens wro

9.9.4rc1 Linux compile error

2013-08-21 Thread Luther, Dan
FFECTIVE' undeclared (first use in this function) os.c:329: error: 'CAP_SET' undeclared (first use in this function) os.c:338: error: expected ';' before 'curval' make[3]: *** [os.o] Error 1 make[3]: Leaving directory `/home/l

Re: New warning message...

2013-07-24 Thread McDonald, Dan
On Jul 24, 2013, at 4:48 AM, "Stephane Bortzmeyer" wrote: > On Mon, Jul 22, 2013 at 12:39:53PM +0200, > Matus UHLAR - fantomas wrote > a message of 28 lines which said: > >> This was discussed here already, [...] >> The SPF RR is already >> here and is preferred over TXT that is generik RR t

RE: Stalling slave transfers

2013-05-09 Thread Luther, Dan
Tom, What happens when you "dig +tcp example.com @1.2.3.4"? Specifically I'm wondering here if the slave you're having problems with is blocking TCP port 53. Such a configuration would allow you to query the master server, but not transfer to/from it. Dan Luther Operati

RE: "make test" fails on Fedora 10

2013-03-27 Thread Luther, Dan
So it's not. Dan Luther Operations Engineer Systems Operation Engineering Level 3 Communications One Technology Center, Tulsa OK 74103 p: 918-547-4370 e: dan.lut...@level3.com -Original Message- From: Jeremy C. Reed [mailto:jr...@isc.org] Sent: Wednesday, March 27, 2013 3:17

"make test" fails on Fedora 10

2013-03-27 Thread Luther, Dan
/named/named -m record,size,mctx -T clienttest -c named.conf -d 99 -g >named.run 2>&1 &echo $!' I:Checking that reconfiguring empty zones is silent (1) ... which may be part of the problem, at least in my case. So I cheated by issuing a "find . -type d -exec chmod 777 {} \;"

Re: SPF records in reverse zones?

2012-12-05 Thread Dan Mahoney
ecord, in order to route mail to it, which goes a far cry from being "a server that has no entry in the DNS". I can't even imagine what spamfilters would think of such an address. :) -Dan Mahoney ___ Please visit https://lists.isc.org/mai

Re: DNS Blackholing

2012-12-03 Thread Dan Mahoney
s well as the ability to replicate your single policy zone via standard AXFR/IXFR metrics. SpamHaus is currently making some of their data available in this format: http://www.spamhaus.org/news/article/669/ -Dan Mahoney ___ Please visit https://lis

Re: Find all authoritative domains for a nameserver?

2012-12-03 Thread Dan Mahoney
ut the reality is, all these methods require someone to be querying it. Thankfully, spambots seem to do this quite a lot, and manage to find "new" domains at an alarming pace. -Dan Mahoney ISC ___ Please visit https://lists.isc.org/mailman/l

Re: Duplicates in newsgroup gateway

2012-06-25 Thread Dan Mahoney
er. I'll see if I can reach out to the googlegroups folks and figure a way to sort this. -Dan ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org ht

Compiling and testing on Fedora

2012-06-20 Thread Luther, Dan
76) R:FAIL I'm running the "bin/tests/system/ifconfig.sh up" script, and see the "lo:1" through "lo:7" interfaces come up. I don't have this problem on any of my Solaris systems, just the Fedora servers. I do have several lo: interfaces already defined, and they

Re: OT: cached memory

2012-06-13 Thread Dan Letkeman
I understand the concept, as I have read many documents like that. I am more interested in a real world example of how much free memory for caching is recommended for an average server. Dan. On Wed, Jun 13, 2012 at 1:00 PM, Mike Hoskins wrote: > this is a common source of confusion and m

OT: cached memory

2012-06-13 Thread Dan Letkeman
2434 -/+ buffers/cache:368 2649 Swap: 5023 0 5023 Thanks, Dan. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc

Re: How to handle zones that need to be the same in all views?

2012-06-12 Thread Dan Pritts
be different acrossviews, and one for the zones that need to be global.Max.___Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this listbind-users mailing listbind-users@lists.isc.orghttps://lists.isc

Re: Recommended value for max-cache-size for cache-only shared hosts..

2012-06-01 Thread Dan Mason
cleaning-interval whereas if it's 2G you won't notice the interval at all. Also on a busy resolver expect BIND to use about twice as much as where you set your limits. Dan -- Daniel Mason Senior Engineer CenturyLink, Inc. Internal Use Only - Disclose and distribute only to CenturyL

Re: zone update to slave

2012-01-11 Thread Dan Letkeman
Yes, I have already done this for the the forward zones: eg domain.com is the static one and workstations.domain.com is the dynamic one But this is my reverse zone that is shared between the two. I don't know how you would split that up...... Dan. On Wed, Jan 11, 2012 at 7:25 PM,

Re: zone update to slave

2012-01-11 Thread Dan Letkeman
entry to a dynamically updated zone? On Wed, Jan 11, 2012 at 2:51 AM, Matus UHLAR - fantomas wrote: > On 10.01.12 15:06, Dan Letkeman wrote: >> >> It seems as if these types of records get transfered: >> >> 9                       PTR     gvc-busdrivers.wks-gvc.domain.

zone update to slave

2012-01-10 Thread Dan Letkeman
the same results. The first type of record is updated dynamically and the second type of record is added manually. Any ideas what that could be? Thanks, Dan. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this

zone updates different in different views

2011-12-10 Thread Dan Pritts
g free DNS service to all takers recursion no; // Disable lookups for any cached data and root hints allow-query-cache { none ; }; // all views must contain the root hints zone: include "stdzones/named.root.hints"; // this should be a syml

Re: sub-domain setup

2011-11-30 Thread Dan McDaniel
On Mon 28.Nov.11 14:39, Doug Barton wrote: On 11/28/2011 10:20, Dan McDaniel wrote: I'm setting up a new DNS server. We have two offices linked by a VPN. I'm trying to decide whether to have everything under a single domain (example.com) or to split them into sub-domains (office1.e

sub-domain setup

2011-11-28 Thread Dan McDaniel
e the pros and cons of the two different setups? Dan ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

[META] Usenet/bind-users cross-posting is back

2011-11-06 Thread Dan Mahoney
e htdig patchset for mailman stopped working in a recent version of mailman and we have to re-integrate a different search engine). Regards, Dan Mahoney ISC Operations Team ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

[META] Usenet cross-posting is back.

2011-11-03 Thread Dan Mahoney
s on our site -- the htdig patchset for mailman stopped working in a recent version of mailman and we have to re-integrate a different search engine). Regards, Dan Mahoney ISC Operations Team ___ Please visit https://lists.isc.org/mailman/listinfo/bind-

Testing, please ignore

2011-11-01 Thread Dan Mahoney
Please ignore. Internal test from ISC. -Dan Mahoney ISC Operations ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: Slow list

2011-07-05 Thread Dan Mahoney
because mailman asks postfix to do a "verify" (but not an SMTP VRFY) of the addresses as part of the VERP that it does. One annoying thing that I should note is that removing those problem users and flushing the queues does NOT help. -Dan

RE: BIND 9.7 Serial Number Decrease Problem

2011-06-06 Thread McDonald, Dan
> -Original Message- > From: bind-users-bounces+dan.mcdonald=austinenergy@lists.isc.org > [mailto:bind-users-bounces+dan.mcdonald=austinenergy@lists.isc.org] > On Behalf Of Tony Finch > Sent: Monday, June 06, 2011 2:43 PM > To: Barry Finkel > Cc: bind-users@lists.isc.org > Subject:

recursive server querying authoritative - timeout before trying next server?

2011-05-26 Thread Dan Pritts
led "deadwood" that defaults to 2 seconds. But, I couldn't find anything on BIND. thanks, danno -- Dan Pritts, Sr. Systems Engineer Internet2 office: +1-734-352-4953 | mobile: +1-734-834-7224 ___ bind-users mailing list bind-users@lists.is

Re: 9.8.0 in 2008 R2 x64 server

2011-04-05 Thread Dan Mahoney
files are > identical to our old, working server. Tested with "administator" as the user > as well, same problem. Start a command shell as that user and try to more the file? -Dan ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: force to flush from jnl to zone files

2011-03-19 Thread Dan Durrer
Terry, rndc freeze zonename disables dynamic updates and syncs up the current zone data to the zone file. rndc thaw zone name when your done editing then file. Dan Sent from my iPad On Mar 19, 2011, at 7:57 AM, terry wrote: > Hello, > > My BIND has been using dynamic updates

RE: R: Operating system recommendation

2011-03-11 Thread Dan
I'm going to end discussion here Jeff as no "personal attacks" were made, only possible suggestions to help you and possibly try something new and exciting in your life, this becomming more of an OS war than anything useful to Bind mailing list, so its more suited for anothe

RE: R: Operating system recommendation

2011-03-11 Thread Dan
the "cruft" you suggest. Its clear from that statement you don't run any BSD's and cost your company money running RHEL vs Centos or anything free that a competent admin could run just as well, perhaps the bit of money your company could save you could use towards a ploy for

Re: Operating system recommendation

2011-03-10 Thread Dan
sideration should be your knowledge set of unix in general, if your linux understanding is really good, then it may be time to graduate from newbie linux admin to senior solaris/freebsd admin, only installing linux where necessary to make your life as easy as possible. Dan. On Fri, 11 Mar 201

Re: Operating system recommendation

2011-03-10 Thread Dan
stalls" on any problems. Its like the saying, once you go black, you don't go back. Dan. On Thu, 10 Mar 2011, Doug Barton wrote: On 03/09/2011 11:52, pollex wrote: Hi, I want to know in your experience what is the best operating system to run bind for an ISP. We currently have Debian fo

Re: Bind 9.8 with dlz and dnssec

2011-03-10 Thread Dan
Evan you looked into why a master in 9.8 will not respond as authoratative for a dlz+mysql zone even though dig axfr zone from slave works Dan. On Thu, 10 Mar 2011, Evan Hunt wrote: Now DLZ supports dynamic updates and theoretically it is possible to make such tricks: rndc freeze

Re: Some hosts not resolving from No-IP by our DNS servers

2011-03-09 Thread Dan Durrer
Yeah.. in-ip.info is probably supposed to be no-ip.info? Dan Durrer No-IP On Mar 9, 2011, at 10:38 AM, Chuck Swiger wrote: > Hi-- > > On Mar 9, 2011, at 10:25 AM, Frank Pikelner wrote: >> I'm having a problem resolving several hosts from NO-IP. When I attempt to >>

Re: rndc: 'reload' failed: not found

2011-03-08 Thread Dan
ind98 dlz master "authoratative" so would not transfer the zone, a bug I still have not heard back on... Dan. On Tue, 8 Mar 2011, Paul Ooi Cong Jen wrote: On 08-Mar-2011, at 4:31 PM, Eivind Olsen wrote: Cent OS+BIND 9.7.3+DLZ(BDB as backend) # rndc reload 2mysite.net rndc: '

bind 9.8.0 BUG dlz zone transfer

2011-03-04 Thread Dan
ong on all versions of bind, and queries seem fine on 9.8, I can tell for certain queries are executing perfect like the previous versions and returning responses as they should, so I have ruled out mysql, there must be a bug within the 9.8 source tree doing this not updating aa SOA

Re: Optimising rndc reload times on a slave server with 50,000 zones

2011-03-02 Thread Dan Durrer
Running off SSDs has also proved to help startup/reload times in our usage. Dan Durrer No-IP On Mar 2, 2011, at 5:32 AM, david klein wrote: > One other thing: on the filesystem in which reside directories that > house the zone files, set the mount option "noatime". This wi

Re: Dynamically add zones

2010-07-30 Thread Dan Durrer
options { ... new-zone-file "/etc/named.d/new_zones.list"; }; include "/etc/named.d/new_zones.list"; ## new_zones.list zone mynewzone.com { type slave; file "mynewzone.com"; masters { 1.1.1.1; }; }; script rndc_addzone.sh --- #!/bin/bash echo "Adding Zone" ${1} cd /var/nam

Re: Dynamically add zones

2010-07-30 Thread Dan Durrer
zone comes back as refused. If I run reconfig it will start answering queries, but I'm guessing that is because its just re-reading the include from new-zone-file. Am I missing something here? Dan On Jul 29, 2010, at 5:33 PM, Dan Durrer wrote: > Alan, > > So is managed

Re: Dynamically add zones

2010-07-30 Thread Dan Durrer
Do you guys have any hints yet on what it might look like or are you still looking for recommendations? Dan Durrer No-IP On Jul 30, 2010, at 10:44 AM, Evan Hunt wrote: >> Note that the syntax for this set of tools (dynamic zone creation) is a >> bit in flux and may b

Re: Dynamically add zones

2010-07-29 Thread Dan Durrer
Alan, So is managed.zone.list and zone.list named differently on purpose or is that a typo? Dan On Jul 29, 2010, at 5:23 PM, Alan Clegg wrote: > On 7/29/2010 7:19 PM, Dan Durrer wrote: >> Alan, >> >> I was playing around with your example. I can get it to add the

  1   2   >