RE: DNSSEC and forward zone

2023-04-21 Thread David Carvalho via bind-users
that much about the parent setup. Anyway, thanks and regards! David From: bind-users On Behalf Of Petr Menšík Sent: 21 April 2023 10:59 To: bind-users@lists.isc.org Subject: Re: DNSSEC and forward zone Would it make sense to create a subdomain for internal use, but have the main zone

Re: DNSSEC and forward zone

2023-04-21 Thread Petr Menšík
*Sent:* 19 April 2023 10:27 *To:* David Carvalho *Cc:* Bind Users Mailing List *Subject:* Re: DNSSEC and forward zone Hi David, You can disable validation on one or more domains using "validate-except" - https://bind9.readthedocs.io/en/latest/reference.html#namedconf-statemen

Re: DNSSEC and forward zone

2023-04-19 Thread Petr Špaček
were, the key would be different than that on the outside servers, which is the same domain. Not optimistic Regards David -Original Message- From: bind-users On Behalf Of Petr Špacek Sent: 19 April 2023 10:35 To: bind-users@lists.isc.org Subject: Re: DNSSEC and forward zone Yo

RE: DNSSEC and forward zone

2023-04-19 Thread David Carvalho via bind-users
nssec, and even if they were, the key would be different than that on the outside servers, which is the same domain. Not optimistic Regards David -Original Message- From: bind-users On Behalf Of Petr Špacek Sent: 19 April 2023 10:35 To: bind-users@lists.isc.org Subject: Re: DNSSE

RE: DNSSEC and forward zone

2023-04-19 Thread David Carvalho via bind-users
and forward zone Hi David, You can disable validation on one or more domains using "validate-except" - https://bind9.readthedocs.io/en/latest/reference.html#namedconf-statement-validate-except Thank you, Darren Ankney On Wed, Apr 19, 2023 at 5:05 AM David Carvalho via

RE: DNSSEC and forward zone

2023-04-19 Thread David Carvalho via bind-users
and forward zone Hi David, You can disable validation on one or more domains using "validate-except" - https://bind9.readthedocs.io/en/latest/reference.html#namedconf-statement-validate-except Thank you, Darren Ankney On Wed, Apr 19, 2023 at 5:05 AM David Carvalho via

Re: DNSSEC and forward zone

2023-04-19 Thread Petr Špaček
You can disable it, but that's just workaround. It would be better to fix it :-) I would recommend checking logs on resolver which is failing to resolve the domain. I guess you will find out a DNSSEC validation error would tell us what's misconfigured. My bet is that the internal domains are

Re: DNSSEC and forward zone

2023-04-19 Thread Darren Ankney
Hi David, You can disable validation on one or more domains using "validate-except" - https://bind9.readthedocs.io/en/latest/reference.html#namedconf-statement-validate-except Thank you, Darren Ankney On Wed, Apr 19, 2023 at 5:05 AM David Carvalho via bind-users < bind-users@lists.isc.org> wrot

DNSSEC and forward zone

2023-04-19 Thread David Carvalho via bind-users
Hello guys Asking for your help, again. So after setting up DNSSEC I've found I couldn't reach some internal sites on my top domain, served by internal DNS servers There's no need in hiding domains as my e-mail is shown here. Top domain ubi.pt (external