Re: Create DS and DLV records

2010-05-05 Thread Stephane Bortzmeyer
On Wed, May 05, 2010 at 11:59:23AM +0530, rams wrote a message of 36 lines which said: > could you please explain me, how to create DS and DLV records into my zone. If you want to add DS or DLV records in _your_ zone, you typically never create them. Managers of child zones do it and they sen

Re: Switching to TCP in BIND.

2010-05-05 Thread Sam Wilson
In article , Stephane Bortzmeyer wrote: > On Wed, Apr 28, 2010 at 11:59:11AM -0400, > Kevin Darcy wrote > a message of 21 lines which said: > > > I know of no such feature. What do you mean by "spoofed" anyway? How > > would you expect named to detect "spoofing", and is that its job? > > I

Re: Switching to TCP in BIND.

2010-05-05 Thread sthaug
> > > I know of no such feature. What do you mean by "spoofed" anyway? How > > > would you expect named to detect "spoofing", and is that its job? > > > > It seems (not tested by me) that Nominum CNS does that: when many > > responses arrive which do not match (src IP address, query ID, etc) > > a

Re: Switching to TCP in BIND.

2010-05-05 Thread Stephane Bortzmeyer
On Wed, May 05, 2010 at 09:35:38AM +0100, Sam Wilson wrote a message of 22 lines which said: > > It seems (not tested by me) that Nominum CNS does that: when many > > responses arrive which do not match (src IP address, query ID, etc) > > any pending answer, it switches to TCP, assuming someon

Re: Switching to TCP in BIND.

2010-05-05 Thread Sam Wilson
In article , sth...@nethelp.no wrote: > > > > I know of no such feature. What do you mean by "spoofed" anyway? How > > > > would you expect named to detect "spoofing", and is that its job? > > > > > > It seems (not tested by me) that Nominum CNS does that: when many > > > responses arrive which

Re: Switching to TCP in BIND.

2010-05-05 Thread Sam Wilson
In article , Stephane Bortzmeyer wrote: > On Wed, May 05, 2010 at 09:35:38AM +0100, > Sam Wilson wrote > a message of 22 lines which said: > > > > It seems (not tested by me) that Nominum CNS does that: when many > > > responses arrive which do not match (src IP address, query ID, etc) > >

RE: Preparing for upcoming DNSSEC changes on 5/5

2010-05-05 Thread Lightner, Jeff
8:30 EDT 05/05/2010 and the world hasn't ended here yet. We can celebrate Cinco de Mayo in peace. If only I didn't detest tequila. Side note: I've actually been to Puebla Mexico which is where the battle that Cinco de Mayo commemorates took place. -Original Message- From: bind-users-bo

Re: Preparing for upcoming DNSSEC changes on 5/5

2010-05-05 Thread Alan Clegg
On 5/5/2010 1:32 PM, Lightner, Jeff wrote: > 8:30 EDT 05/05/2010 and the world hasn't ended here yet. > > We can celebrate Cinco de Mayo in peace. If only I didn't detest > tequila. > > Side note: I've actually been to Puebla Mexico which is where the > battle that Cinco de Mayo commemorates to

RE: Preparing for upcoming DNSSEC changes on 5/5

2010-05-05 Thread Chris Thompson
On May 5 2010, Lightner, Jeff wrote: 8:30 EDT 05/05/2010 and the world hasn't ended here yet. The switchover of j.root-servers.net to "DURZ" is scheduled for 17:00-19:00 UTC (see http://www.root-dnssec.org/ - or just try "dig dnskey . @j.root-servers.net"). We aren't there yet ... We can cel

Re: DNSSEC

2010-05-05 Thread Warren Kumari
On May 4, 2010, at 11:01 AM, Linux Addict wrote: On Tue, May 4, 2010 at 10:43 AM, Stephane Bortzmeyer > wrote: On Tue, May 04, 2010 at 10:27:25AM -0400, Linux Addict wrote a message of 89 lines which said: > lacks EDNS, defaults to 512" > DNS reply size limit is at least 490" > "Tested at 2

Re: DNSSEC

2010-05-05 Thread Linux Addict
On Wed, May 5, 2010 at 11:53 AM, Warren Kumari wrote: > > On May 4, 2010, at 11:01 AM, Linux Addict wrote: > > On Tue, May 4, 2010 at 10:43 AM, Stephane Bortzmeyer wrote: > >> On Tue, May 04, 2010 at 10:27:25AM -0400, >> Linux Addict wrote >> a message of 89 lines which said: >> >> > lacks EDN