RRL probably not useful for DNS IP blacklists, was Re: New Versions of BIND are available (9.9.4, 9.8.6, and 9.6-ESV-R10)

2013-09-20 Thread Shane Kerr
Noel, On 2013-09-20 12:48:31 (Friday) Noel Butler wrote: > On Fri, 2013-09-20 at 01:59 +, Vernon Schryver wrote: > > > plenty of delayed mail - hostname lookup failures (mostly because of > > > URI/DNS BL's), so it certainly works as intended :) > > > > That sounds unrelated to RRL. Agai

Re: BIND9 statistics-server: JSON?

2013-03-15 Thread Shane Kerr
On Fri, 15 Feb 2013 06:57:10 +0100 Jan-Piet Mens wrote: > As a fan of BIND's statistics-server I was tempted to see if I could > reduce the size of the data (XML) named produces by adding an option > to produce JSON. The patch [1] (which is terribly quick and dirty) > does that. > > [1] https://

Re: spf ent txt records.

2013-03-13 Thread Shane Kerr
Hugo, On Wednesday, 2013-03-13 11:33:35 +, hugo hugoo wrote: > Dear all, > > I received the following question and I am not able to aswer as spf > records are still mysterious to me. We are using BIND 9.7. > > Thanks in advance for your answers, > > Hugo, > > > > Does our DNS-ser

Re: BIND roadmap

2013-02-28 Thread Shane Kerr
William, On Thursday, 2013-02-28 11:19:01 +1100, Mark Andrews wrote: > > In message > , > wbr...@e1b.org writes: > > Congrats to ISC and everyone that has worked on BIND 10! > > > > I am building new name servers and redesigning our infrastructure > > with an eye towards streamlining, improvin

Re: Configure error - BIND10, 1.0.0 on Mac OS X 10.8.2

2013-02-25 Thread Shane Kerr
James, On Monday, 2013-02-25 13:56:58 +1100, James Brown wrote: > > On 23/02/2013, at 9:44 AM, JINMEI Tatuya / 神明達哉 > wrote: > > > At Sat, 23 Feb 2013 09:30:55 +1100, > > James Brown wrote: > > > >> Received an error running configure on Mountain Lion: > >> > >> ./configure > >> checking f

Re: Difference between multiple NS and NS having multiple A

2013-02-19 Thread Shane Kerr
Mark & Alexander, On Monday, 2013-02-18 08:43:32 +1100, Mark Andrews wrote: > > In message > , > Alexander Gurvitz writes: > > Is there any practical difference between the following two: > > > > 1. > > example.com. NS ns1.example.com. > > example.com. NS ns2.example.com. > > ns1.example.com.

Re: Performance impact of a large ACL list.

2013-02-08 Thread Shane Kerr
Augie, On Monday, 2013-02-04 19:01:38 -0600, "Jeremy C. Reed" wrote: > On Mon, 4 Feb 2013, Augie Schwer wrote: > > > Does anyone have any experience using a large ( 1k ) entry ACL list? > > Was there any performance degradation? > > > > I haven't implemented my ACL yet, but it has quickly ball

Re: what do you use for logging?

2013-01-18 Thread Shane Kerr
All, On Friday, 2013-01-18 10:01:49 +, "Niall O'Reilly" wrote: > > On 18 Jan 2013, at 06:27, Jan-Piet Mens wrote: > > >> Could "CLI utility" be man(1) and info(1)? :-) > > > > It could, yes, but `b10-msg NNN` isn't going to break BIND 10's > > development budget (I hope), > > +1 >

Re: lame-servers: error (FORMERR) resolving [something]

2013-01-14 Thread Shane Kerr
Daniele, It may be a simple case of your firewall not allowing any DNS queries that do not request recursion. Difficult to know. You may want to try: dig +trace www.isc.org This will follow the referrals from the root, and you can verify that this works. The next step may be to try: dig +trac

Re: lame-servers: error (FORMERR) resolving [something]

2013-01-08 Thread Shane Kerr
Daniele, On Tuesday, 2013-01-08 09:49:57 +0100, Daniele wrote: > Hi all. > > Sometimes I can't resolve some addresses and, in the logs, I can find > the message in the title: >lame-servers: error (FORMERR) resolving [something] > (where `something` is the address I'm trying to resolve). >

Re: Improved SSL Error Logging [RT #29932]

2012-12-06 Thread Shane Kerr
Noel, On Thursday, 2012-12-06 11:03:24 +1000, Noel Butler wrote: > Hi Shane, Mark, Evan > > On Tue, 2012-10-16 at 08:22 +0200, Shane Kerr wrote: > > > > These changes are in our review queue now, so will go in future > > releases. > > > I guess this was n

Re: Linux issue with make test failures, 9.9.2-P1

2012-12-06 Thread Shane Kerr
Jeff, On Wednesday, 2012-12-05 09:27:10 -0500, Jeff Earickson wrote: > > The "make test" stuff is failing miserably for me on Linux (Redhat > 6.3, x64) with 9.9.2-P1: Someone suggested to me: There should be *.run (maybe tests/system/*/*/*.run) files that will have the run-time log output.

Re: Improved SSL Error Logging [RT #29932]

2012-10-15 Thread Shane Kerr
Noel, These changes are in our review queue now, so will go in future releases. Cheers, -- Shane Kerr ISC On Saturday, 2012-10-13 11:07:01 +1000, Noel Butler wrote: > Thanks Mark, > > These changes have been committed for future patch releases? > > > Cheers > >

Paradigm shift for error handling

2011-11-16 Thread Shane Kerr
All, On Wed, 2011-11-16 at 13:18 +, Evan Hunt wrote: > > can we have a paradigm shift from ISC please? instead of falling over > > dead with insist/assert, please bleat a warning and drop the problematic > > issue on the floor instead and press on with business. many BIND DoS > > attacks (an

Re: subdomain issue

2011-11-09 Thread Shane Kerr
Tarak, You probably meant for this to go to the bind-users list, not the bind10-users list. I have Cc'd that list here - hopefully someone can help you out. Cheers, -- Shane On Tue, 2011-11-08 at 19:22 +0530, trm asn wrote: > Dear List, > > Please help me out to investigate the below scenario