No. This is not a thing regular DNS servers do.-- Mark AndrewsOn 23 May 2025, at 00:23, Karol Nowicki via bind-users wrote:
Does ISC Bind software by native has any dns tunneling prevention embedded ? Thanks Wysłane z Yahoo Mail do iPhone
-- Visit https://lists.isc.org/mailman/listinfo/bind-users
.
Forwarding to the servers you are is providing indirect access to instances with
zone content to serve.
Mark
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org
--
Visit https://lists.isc.org/mailman/listinfo/bind
rt subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +6
s from NSEC3 zones was previously reverted after a bug
> was found that could trigger an assertion failure. ([GL #4460], [GL #4950],
> and [GL #5108]) The bug has now been fixed, and the performance improvement
> has been restored. [GL #5204]
>
>
>
> On 21/04/2025 7:12
your normal working hours.
>>> >
>>> >
>>> akritrim® Intelligence™
>>> --
>>> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe
>>> from this list
>>> ISC funds the development of this software with paid support
>>>
eference thread to refer historical
> incident . I didnt experience this issue since last friday .
>
> Regards
> Duleep.
>
> On Thu, Apr 10, 2025 at 12:02 PM Mark Andrews wrote:
> This was fixed roughly 6 years ago in a later version of BIND 9.11 which has
> since b
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
.168.20.11; };
dnssec-policy "unlimited";
};
Mark
> On 13 Mar 2025, at 09:13, Danjel Jungersen wrote:
>
> On 20-02-2025 08:40, Mark Andrews wrote:
>>> The zone is available publicly, but from public serveres not hosted by me
>>> (one.com).
>>
Returning REFUSED to ANY is anti-pmsocial as it requires every resolver in the world to special case this There are better mechanisms to deal with it like returning TC=1 or BADCOOKIE if there is only a client cookie or returning one of the RRsets at the name. -- Mark AndrewsOn 4 Mar 2025, at 18:21
-statement-logging
--
Mark Andrews
> On 4 Mar 2025, at 06:45, Brett Delmage via bind-users
> wrote:
>
> On Mon, 3 Mar 2025, Michael Richardson wrote:
>
>> Brett Delmage via bind-users wrote:
>> > Specifically for me now that's the query log including the flag
> On 20 Feb 2025, at 17:35, Danjel Jungersen wrote:
>
>
>
> On 19 February 2025 13:01:01 CET, Mark Andrews wrote:
> >You can install a negative trust anchor or sign the zone so that DNSSEC
> >validation works. The zone exists in the public DNS. You can use the s
validation to work with BYOD.
You can also sign your internal zone and add trust anchors for it without
publishing DS records. This won’t work BYOD.
--
Mark Andrews
> On 19 Feb 2025, at 21:54, Danjel Jungersen wrote:
>
> On 19-02-2025 11:44, Mark Andrews wrote:
>> The
The posix boxes are validating the responses and your zone is not properly
delegated/signed so DNSSEC validation fails.
What does the following return?
dig +cd +dnssec mail.jungersen.dk
The answer on the internet is signed.
--
Mark Andrews
> On 19 Feb 2025, at 21:21, Danjel Junger
message or
> its attachments is strictly prohibited.--
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for mor
records and refuse to serve them
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
be from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind
Well it is waiting for the zone contents on stdin. Try specifying both the
zone name and the file that it should be reading.
--
Mark Andrews
> On 5 Jan 2025, at 07:21, f...@www.zefox.net wrote:
>
> I'm setting up a new, non-recursive, authoritative secondary
> nameserver u
You have the error message. Cut and paste it from the logs and post it here.
Saying there is something to do with the user ‘bind’ when you have an actual
error message is wasting everyone’s time.
--
Mark Andrews
> On 30 Dec 2024, at 05:27, Pablo Andalaft Tarodo wrote:
>
>
on.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid
ilman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
&g
gt;
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org
--
Visit https://lists.isc.org/mailman/
> PMc
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users
ailure) for
> americanautowire.com/IN/A at query.c:7814
>
> We can ignore all the IPv6 stuff. But what I don't see is anything that
> explains the failure. Even more oddly is that if I just make the query
> several times in a row, it eventually works just fine.
>
> Is ther
I suspect the OP meant ECS. -- Mark AndrewsOn 24 Nov 2024, at 07:43, Greg Choules via bind-users wrote:Hi.Please can you clarify what you mean and what you're trying to achieve? EDNS support generally has existed in all versions of BIND for many years.Cheers, GregOn Sat, 23 Nov 2024 at 15:43, 从今以
sts.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.
gt; 5020 Salzburg, Austria
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
RPZ stands for RESPONSE POLICY ZONE. It does NOT block queries. It modifies replies. -- Mark AndrewsOn 17 Nov 2024, at 17:28, Blason R wrote:Nah even that didn't work.If I directly query to bind it blocks or wall garden the request but if I send it through windows AD or any other server bind just
atic _Atomic(isc_stdtime_t) last_udpsends_log = 0;
> ^
> netmgr/udp.c:1449:1: error: expected '{' at end of input
> }
> ^
> netmgr/udp.c: At top level:
> netmgr/udp.c:65:1: warning: 'udp_send_direct' used but never defined [enabled
> by default]
>
st
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org
--
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/l
Clear Lake, SD 57226
> Phone: (605) 874-8313
> michael.martin...@itccoop.com
> www.itc-web.com
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Co
ree RAM, disk
> space, CPU <20%, etc.
>
> Any suggestions as to where to look? Nothing gets logged to named.log or my
> queries log file.
>
> Any help would be much appreciated.
>
> Thanks, James.
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users t
t;
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing
> Regards,
>
> Arnold
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
t; DNSSEC algorithms: RSASHA1 NSEC3RSASHA1 RSASHA256 RSASHA512 ECDSAP256SHA256
> ECDSAP384SHA384 ED25519 ED448
> DS algorithms: SHA-1 SHA-256 SHA-384
> HMAC algorithms: HMAC-MD5 HMAC-SHA1 HMAC-SHA224 HMAC-SHA256 HMAC-SHA384
> HMAC-SHA512
> TKEY mode 2 support (Diffie-Hellman): no
&g
address.
> Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
> How does cat play with mouse? cat /dev/mouse
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid
records.
All this needs to go through the IETF.
--
Mark Andrews
> On 28 Sep 2024, at 07:54, Terik Erik Ashfolk wrote:
>
> According to the page
> https://blog.apnic.net/2021/08/25/multi-signer-dnssec-models/
> in MODEL 2.
> I added an improved image as attachment.
>
> MUL
id support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61
> On 11 Sep 2024, at 16:06, Lee wrote:
>
> On Tue, Sep 10, 2024 at 10:52 PM Mark Andrews wrote:
>>
>>> On 11 Sep 2024, at 12:10, Lee wrote:
>>>
>>> On Tue, Sep 10, 2024 at 6:17 PM Mark Andrews wrote:
>>>>
>>>> Comma is legal
> On 11 Sep 2024, at 12:10, Lee wrote:
>
> On Tue, Sep 10, 2024 at 6:17 PM Mark Andrews wrote:
>>
>> Comma is legal in a domain name. It isn’t legal in a host name which are a
>> subset of domain names. Named-checkzone is working exactly as it should.
>
>
Comma is legal in a domain name. It isn’t legal in a host name which are a
subset of domain names. Named-checkzone is working exactly as it should.
If the current origin is example.com. then comma expands to ,.example.com. as
it is treaded as a relative name.
--
Mark Andrews
> On 11
>
> ---+---------
> 117965258 | ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: **
> +
> | ;; flags: qr rd ra; QUESTION: 1, ANSWER: 0, AUTHORIT
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing
On further reflection I suspect broken clocks. Named uses If-Modified-Since to
determine
whether to resend the style file. Named uses the server’s start time as the
modification time
in that calculation.
> On 26 Aug 2024, at 11:06, Mark Andrews wrote:
>
> We are probably not
o looks like I'll have to find out why collecting BIND
> stats via collectd (5.12.0) no longer works after upgrading to
> 9.20.x.
>
> Best regards,
>
> - Håvard
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
>
> On 19 Aug 2024, at 00:59, Marco Moock wrote:
>
> Am 18.08.2024 um 23:44:26 Uhr schrieb Mark Andrews:
>
>>> On 18 Aug 2024, at 20:32, Marco Moock wrote:
>
>> It is. Go to the product page. Look at panel 3 “Configuration".
>> Click on "Admini
this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
>
Negative cache entries.
--
Mark Andrews
> On 15 Aug 2024, at 22:10, Marco Moock wrote:
>
> Hello!
>
> named.stats includes that:
>
> [...]
> ++ Cache DB RRsets ++
> [View: default]
>3184 A
>1059 NS
>
to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/li
he development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas
gt;
>category security { bind_log; };
>
> };
>
>
>
>
> alpha_one_x86/BRULE Herman
> Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and
> server management
> IT, OS, technologies, research & development, security and business d
oftware with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Austra
N A
>
> ;; Query time: 87 msec
> ;; SERVER: 199.38.247.210#53(199.38.247.210) (UDP)
> ;; WHEN: Mon Jul 15 00:56:01 UTC 2024
> ;; MSG SIZE rcvd: 67
> alpha_one_x86/BRULE Herman
> Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and
> server ma
88
[ant:~/git/bind9] marka%
Mark
> alpha_one_x86/BRULE Herman
> Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and
> server management
> IT, OS, technologies, research & development, security and business department
> On 7/12/24 19:01, Mark Andrews wrote:
&
gt; this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
tact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNE
24, at 07:00, Mark Andrews wrote:
>
> It’s just a false positive when the result is NXDOMAIN. Because people forget
> to put delegating NS records in parent zones when both are served by the same
> server the lookups continue on NXDOMAIN. There is an issue to address this.
>
>
It’s just a false positive when the result is NXDOMAIN. Because people forget
to put delegating NS records in parent zones when both are served by the same
server the lookups continue on NXDOMAIN. There is an issue to address this.
--
Mark Andrews
> On 25 Jun 2024, at 06:36, Peter wr
> On 20 Jun 2024, at 15:29, Michael Richardson wrote:
>
>
> Mark Andrews wrote:
>> Named and nsupdate validate input for types they know about (both text
>> and wire). You would have to use versions that are not HTTPS aware and
>> use unknown type format.
>
Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INT
tware with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, A
Have you read the fine documentation on BIND where it is stated this is not
(currently) possible?
If you want to extend named to support this we would be happy to review a
change request. It is complicated however which is why it has not been done.
--
Mark Andrews
> On 13 Jun 2024, at
gt; Contact us at https://www.isc.org/contact/ for more information.
>>
>>
>> bind-users mailing list
>> bind-users@lists.isc.org
>> https://lists.isc.org/mailman/listinfo/bind-users
>>
>>
>> --
>> - Andrew "lathama" Latham -
>>
rs to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mai
insecure. It is just that a myth. Not posting them just makes it harder for
other people to help you.
Mark
> From nsupdate:
>
> nsupdate -L99 -dD -k TrueNAS.key nsupdate-cmds-py.txt
>
> show_message()
> Outgoing update query:
> ;; ->>HEADER<<- opcode: UPDATE, sta
given
NOTHING for people to work with to help you.
Mark
> On 27 May 2024, at 13:39, Mark Andrews wrote:
>
>
>
>> On 25 May 2024, at 03:25, Erik Edwards via bind-users
>> wrote:
>>
>> algorithm hmac-sha256;
>>
>> named-checkconf -p shows
re information.
>>
>>
>> bind-users mailing list
>> bind-users@lists.isc.org
>> https://lists.isc.org/mailman/listinfo/bind-users
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the devel
DNSSEC or adding a HINFO
record for every name in your zone when offline signing.
Mark
--
Mark Andrews
> On 21 May 2024, at 00:31, Ondřej Surý wrote:
>
> I would suggest you to create a feature request in our GitLab. This way it
> won't get lost
> in the tides of time
Named does not support this. There is no requirement to support this.
--
Mark Andrews
> On 21 May 2024, at 00:04, Amaury Van Pevenaeyge
> wrote:
>
>
> Hello everyone,
>
> How is it possible to set up a resource record of type HINFO so that it is
> returned on e
t;
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, I
reports due to garbage records at the zone apex.
Mark
--
Mark Andrews
> On 17 May 2024, at 23:31, Stephane Bortzmeyer wrote:
>
> On Fri, May 17, 2024 at 03:25:01PM +0200,
> Matus UHLAR - fantomas wrote
> a message of 43 lines which said:
>
>> I have noticed that BI
h paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHON
re information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org
--
Visit https://lists.isc.
> On 1 May 2024, at 22:25, Walter H. via bind-users
> wrote:
>
> On 01.05.2024 01:33, Mark Andrews wrote:
>>
>>> On 1 May 2024, at 03:32, Lee wrote:
>>>
>>> On Mon, Apr 29, 2024 at 11:40 PM Walter H. wrote:
>>>> On 29.04.2024 22:19,
is list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Ma
:54 AEST 2024
;; MSG SIZE rcvd: 203
%
> On 30 Apr 2024, at 06:55, Lee wrote:
>
> On Sun, Apr 28, 2024 at 7:56 PM Mark Andrews wrote:
>>
>> It isn’t DNSSEC. It’s a badly configured DNS server that is claiming that it
>> serves .com rather than dnssec-analy
port subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2
I prefer to only name and shame when I’m 100% sure of the target.
--
Mark Andrews
> On 30 Apr 2024, at 06:56, Lee wrote:
>
> On Sun, Apr 28, 2024 at 7:56 PM Mark Andrews wrote:
>>
>> It isn’t DNSSEC. It’s a badly configured DNS server that is claiming that it
>&
And the SMTP server doesn’t need to listen on IPv6 if it isn’t going to accept
messages over that transport. Talk about a way to DoS yourself.
--
Mark Andrews
> On 30 Apr 2024, at 06:19, Lee wrote:
>
> On Sun, Apr 28, 2024 at 2:18 AM Walter H. via bind-users
> wrote:
>
>
/dnssec/>
>
> Hi Josh,
>
> Ok, sounds good!
>
> - J
>
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https
-records ...
>
> would it be a problem with just this DNS zone, why are only problems getting
> the IPv6?
>
>
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support
.
Named was looking up theses NS records I.e. chasing the DS servers. This can
result in named finding delegation errors. QNAME minimisation also exposes
these errors as it also does NS queries. Garbage in breakage out.
--
Mark Andrews
> On 27 Apr 2024, at 00:45, J Doe wrote:
>
> On 2
No. “Forward zones” are not DNS zones. They are overrides to the DNS resolution
processes that just happened to be configured in named by overloading the zone
syntax element. Similarly stub and static stub are not zones. The are other
things.
--
Mark Andrews
> On 23 Apr 2024, at 01
pport subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61
; Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bi
It a hold down cache on bad lookups. The timeout is 10 minutes. To prove
whether a zone is secure or not DS records at delegations in the chain are
looked up. Sometimes that fails. This cache records that failure.
--
Mark Andrews
> On 17 Apr 2024, at 07:03, John Thurston wr
Also authoritative servers lookup information. This includes addresses of
nameservers to send NOTIFY messages. DS queries as part of DNSSEC key
management. DNSKEY queries as part of DNSSEC trust anchor management. Plus
whatever else is required to resolve those queries.
--
Mark Andrews
Allow-notify is additive. You can’t block notify from primaries.
--
Mark Andrews
> On 25 Mar 2024, at 22:34, sami.ra...@sofrecom.com wrote:
>
>
> Hello community,
> I'm trying to configure a DNS slave server (192.168.56.157) . I want to allow
> notificatio
> Thanks,
>
>
>
>
>
> Borja.
>
>
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subscriptions.
> Contact us at https://www.isc.or
to do this. Once your existing
keys
are omnipresent you can update the lifetime to what you want to run with.
On 8 Mar 2024, at 10:57, Mark Andrews wrote:
>
>
>
>> On 8 Mar 2024, at 10:54, Randy Bush wrote:
>>
>>> You DS and DNSKEY rrset are not matched. You
; liaN92BRsQO0ykBep+HxH85CXPhqBMnl2Z43guX2t+QZ
>> B36h61FrpFOt7RUnvJ8Pn3Rz+kx1VVOIsw== )
>>
>>> https://git.rg.net/randy/randy/src/master/scratch.md
>
> yes, we can see that, as we noted. and yes we could rekey 42 zones at
> the parents; great fun.
>
> but WH
oftware with paid support subscriptions.
> Contact us at https://www.isc.org/contact/ for more information.
>
>
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117,
rypto
is performed so it wouldn’t be too expensive to skip to the next RRSIG
on those error codes but really you shouldn’t be publishing broken RRSIGs.
Mark
> On 15 Feb 2024, at 11:25, Mark Andrews wrote:
>
> Well if you are attacking the resolver by sending invalid RRSIGs ...
>
>
/>...)
>
> (I also did/will tell Quad9 about it for their information.)
>
> Cheers,
> --
> Matt Nordhoff
> --
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
> this list
>
> ISC funds the development of this software with paid support subsc
Transfer from a single address.
The IXFR transfer is detecting that a record is being asked to be deleted but
it is not present in the zone. Named will fallback to an AXFR. The logs have
been extended recently to provide more details.
--
Mark Andrews
> On 14 Feb 2024, at 18:41, Andrea
Additionally this behaviour is specified in RFC1034 so every nameserver should
do this.
--
Mark Andrews
> On 14 Feb 2024, at 02:24, Friesen, Don CITZ:EX via bind-users
> wrote:
>
> Andy,
> The existence of 8.f.0.f.1.f.1.0.8.a.b.0.1.0.0.2.ip6.arpa as an
> authoritative
eeks,
one of which has up to date signatures and 2 that have out of date signatures.
This is the sort of thing that happens out there by accident, e.g. unnoticed
zone transfers failing and the zone has not yet expired. Try looking up
multiple answers from that zone with your configuration a
--
Mark Andrews
> On 10 Feb 2024, at 04:18, Randy Bush wrote:
>
>
>>
>> I admit here we most often work with internal only forwarders, which
>> are not accessible from outer internet. So those won't be under attack
>
> i am always impressed by securi
Do the analysis where the resolver is under attack or the auth server with the
best rtt is stale.
--
Mark Andrews
> On 9 Feb 2024, at 21:40, Petr Menšík wrote:
>
> Hello Mark,
>
> allow me here to correct your statement. We spent in Red Hat some time
> thinking and
1 - 100 of 1039 matches
Mail list logo