Re: DNSSEC with 9.7.2-P2

2010-12-01 Thread David Forrest
On Wed, 1 Dec 2010, lst_ho...@kwsoft.de wrote: Zitat von David Forrest : On Tue, 16 Nov 2010, Mark Andrews wrote: Isn't sufficient to configure the root trust anchor inside "managed-keys {};" statement? If I understand correctly the key should be automatically updated, shouldn't it? For

Re: DNSSEC with 9.7.2-P2

2010-12-01 Thread lst_hoe02
Zitat von David Forrest : On Tue, 16 Nov 2010, Mark Andrews wrote: Isn't sufficient to configure the root trust anchor inside "managed-keys {};" statement? If I understand correctly the key should be automatically updated, shouldn't it? For 9.7 yes. I just updated to 9.7.2-P3 and got

Re: DNSSEC with 9.7.2-P2

2010-12-01 Thread David Forrest
On Tue, 16 Nov 2010, Mark Andrews wrote: Isn't sufficient to configure the root trust anchor inside "managed-keys {};" statement? If I understand correctly the key should be automatically updated, shouldn't it? For 9.7 yes. I just updated to 9.7.2-P3 and got this message on start: Dec 1 1

Re: DNSSEC with 9.7.2-P2

2010-11-15 Thread Mark Andrews
In message <20101115140938.ga17...@evileye.atkac.brq.redhat.com>, Adam Tkac wri tes: > On Sat, Nov 13, 2010 at 11:35:57AM +1100, Mark Andrews wrote: > > > > In message <4cdd6467.9050...@imperial.ac.uk>, Phil Mayers writes: > > > On 12/11/10 15:45, Lightner, Jeff wrote: > > > > > > > For Producti

Re: DNSSEC with 9.7.2-P2

2010-11-15 Thread Adam Tkac
On Sat, Nov 13, 2010 at 11:35:57AM +1100, Mark Andrews wrote: > > In message <4cdd6467.9050...@imperial.ac.uk>, Phil Mayers writes: > > On 12/11/10 15:45, Lightner, Jeff wrote: > > > > > For Production (RPM based system) you should use RHEL or CentOS which > > > has a much longer life cycle. (Sp

Re: DNSSEC with 9.7.2-P2

2010-11-15 Thread David Forrest
On Fri, 12 Nov 2010, Phil Mayers wrote: On 12/11/10 12:49, David Forrest wrote: and, on checking named.conf, I found the entry for br. as: trusted-keys { "br." 257 3 5 "AwEAAdDoVnG9CyHbPUL2rTnE22uN66gQCrUW5W0NTXJBNmpZXP27w7PMNpyw3XCFQWP/XsT0pdzeEGJ400kdbbPqXr2lnmEtWMjj3Z/ejR8mZbJ/6OWJQ

RE: DNSSEC with 9.7.2-P2

2010-11-12 Thread Ian Tait
Phil Mayers Cc: bind-users@lists.isc.org Subject: Re: DNSSEC with 9.7.2-P2 In message <4cdd6467.9050...@imperial.ac.uk>, Phil Mayers writes: > On 12/11/10 15:45, Lightner, Jeff wrote: > > > For Production (RPM based system) you should use RHEL or CentOS > > which has a much

Re: DNSSEC with 9.7.2-P2

2010-11-12 Thread Mark Andrews
In message <4cdd6467.9050...@imperial.ac.uk>, Phil Mayers writes: > On 12/11/10 15:45, Lightner, Jeff wrote: > > > For Production (RPM based system) you should use RHEL or CentOS which > > has a much longer life cycle. (Speaking of which, RHEL6 was just put in > > I don't agree with your line o

Re: DNSSEC with 9.7.2-P2

2010-11-12 Thread Phil Mayers
On 12/11/10 15:45, Lightner, Jeff wrote: For Production (RPM based system) you should use RHEL or CentOS which has a much longer life cycle. (Speaking of which, RHEL6 was just put in I don't agree with your line of reasoning. RHEL may have longer update cycles, but there's no guarantee a par

RE: DNSSEC with 9.7.2-P2

2010-11-12 Thread Lightner, Jeff
er 12, 2010 10:33 AM To: bind-users@lists.isc.org Subject: Re: DNSSEC with 9.7.2-P2 On 12/11/10 14:51, Alan Clegg wrote: > On 11/12/2010 7:49 AM, David Forrest wrote: >> While running BIND 9.7.2-P2 built with defaults on F11 > > [..] > >> and, on checking named.conf, I found the

Re: DNSSEC with 9.7.2-P2

2010-11-12 Thread Phil Mayers
On 12/11/10 14:51, Alan Clegg wrote: On 11/12/2010 7:49 AM, David Forrest wrote: While running BIND 9.7.2-P2 built with defaults on F11 [..] and, on checking named.conf, I found the entry for br. as: trusted-keys { "br." 257 3 5 "AwEAAdDoVnG9CyHbPUL2rTnE22uN66gQCrUW5W0NTXJBNmpZXP27w7PMN

Re: DNSSEC with 9.7.2-P2

2010-11-12 Thread Paul Wouters
On Fri, 12 Nov 2010, Alan Clegg wrote: On 11/12/2010 7:49 AM, David Forrest wrote: While running BIND 9.7.2-P2 built with defaults on F11 [..] and, on checking named.conf, I found the entry for br. as: trusted-keys { "br." 257 3 5 "AwEAAdDoVnG9CyHbPUL2rTnE22uN66gQCrUW5W0NTXJBNmpZXP27w7P

Re: DNSSEC with 9.7.2-P2

2010-11-12 Thread Alan Clegg
On 11/12/2010 7:49 AM, David Forrest wrote: > While running BIND 9.7.2-P2 built with defaults on F11 [..] > and, on checking named.conf, I found the entry for br. as: > trusted-keys { > "br." 257 3 5 > "AwEAAdDoVnG9CyHbPUL2rTnE22uN66gQCrUW5W0NTXJBNmpZXP27w7PMNpyw3XCFQWP/XsT0pdzeEGJ400kdbbPqXr

Re: DNSSEC with 9.7.2-P2

2010-11-12 Thread Phil Mayers
On 12/11/10 12:49, David Forrest wrote: and, on checking named.conf, I found the entry for br. as: trusted-keys { "br." 257 3 5 "AwEAAdDoVnG9CyHbPUL2rTnE22uN66gQCrUW5W0NTXJBNmpZXP27w7PMNpyw3XCFQWP/XsT0pdzeEGJ400kdbbPqXr2lnmEtWMjj3Z/ejR8mZbJ/6OWJQ0k/2YOyo6Tiab1NGbGfs513y6dy1hOFpz+peZzGsCm

DNSSEC with 9.7.2-P2

2010-11-12 Thread David Forrest
While running BIND 9.7.2-P2 built with defaults on F11 While processing: Nov 12 06:07:57 maplepark sendmail[3928]: oACC7utt003928: from=, size=5486, class=-30, nrcpts=1, msgid=<003e01cb8262$1ee2b150$5ca813...@com.br>, proto=ESMTP, daemon=MTA-v6, relay=webster.isc.org [IPv6:2001:4f8:1:d::12]