Re: bind 9.11, cookes by default

2016-11-16 Thread Mark Andrews
In message <1479332234.30976.34.ca...@ns.five-ten-sg.com>, Carl Byington writes : > On Thu, 2016-11-17 at 07:47 +1100, Mark Andrews wrote: > > I know you think doing this collectively is a service but having > > individuals discover and complain to the site operators that their > > DNS is broken i

Re: bind 9.11, cookes by default

2016-11-16 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2016-11-17 at 07:47 +1100, Mark Andrews wrote: > I know you think doing this collectively is a service but having > individuals discover and complain to the site operators that their > DNS is broken is the only way there will be enough presur

Re: bind 9.11, cookes by default

2016-11-16 Thread Mark Andrews
I know you think doing this collectively is a service but having individuals discover and complain to the site operators that their DNS is broken is the only way there will be enough presure brought to bear for some of these companies to fix their server configurations. It requires noise for them

bind 9.11, cookes by default

2016-11-16 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Now that bind is sending cookies by default, there are some broken servers out there that we need to configure with send-cookie no;. Unless I am missing something, 9.11.0-P1 will (by default) fail to resolve names like airdownload.wip4.adobe.com. I