Re: Clarification on delegated NS

2010-09-30 Thread Mark Andrews
In message , rams writes: > Hi , > > When I created delegated NS record. Bind 9.7.1 p3 is giving SERVFAIL , when > i queried for NS delegated record with NS. > > Could you please clarify me or is it bug in 9.7? To see a delegation you need to do: dig +norec ns zone @parent > Thanks

per-zone-recursion?

2010-09-30 Thread Joerg Dorchain
Hello, I am puzzled with a bind config for a kind of dns-reverse-proxy situation. I have a server with only one public IP addresse, bind running on port 53 of it. This bind serves examples.net. A subdomain dynsub.example.net should be served on some other software answering DNS request with dyna

Re: How does BIND 9 scale with multithreading?

2010-09-30 Thread Matus UHLAR - fantomas
On 29.09.10 10:43, Jonathan Petersson wrote: > I did some benchmarking on this about 1.5 yrs ago, here's a graph > representing the results: http://sedoss.com/bind.png on how many processors was this ran? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT t

Re: How does BIND 9 scale with multithreading?

2010-09-30 Thread Jonathan Petersson
1 QuadCore Intel i7 920 on Fedora 11 x86_64 (can't remember the exact kernel version) with and without hyperthreading and overclocked ranging between 2.8 and 3.4GHz On Thu, Sep 30, 2010 at 2:03 PM, Matus UHLAR - fantomas wrote: > On 29.09.10 10:43, Jonathan Petersson wrote: >> I did some benchmar

RE: When does BIND send queries with DO flag enabled?

2010-09-30 Thread Taylor, Gord
Thanks. It took a long time to sort out the root cause because EDNS0 (dig @host record.sample +edns=0) caused no problems, only +dnssec caused failures. The business partner has already fixed their firewall (allow_dnssec_bit=1 on CheckPoint), but I wanted to understand the root cause in order to p

RE: When does BIND send queries with DO flag enabled?

2010-09-30 Thread Tony Finch
On Thu, 30 Sep 2010, Taylor, Gord wrote: > > The business partner has already fixed their firewall > (allow_dnssec_bit=1 on CheckPoint) Just in case anyone else is worried about interop problems, I note that allow_dnssec_bit=1 is the default setting. A CheckPoint firewall administrator has to deli

GSS-TSIG and Active Directory

2010-09-30 Thread Nicholas F Miller
Does anyone actually have GSS-TSIG working with an Active Directory? I see plenty of posts from people trying to get it to work. I have yet to see anyone who claims to actually have it working. Did MS change something in 2008r2 since GSS-TSIG was implemented in bind to make it inoperable? __

Re: GSS-TSIG and Active Directory

2010-09-30 Thread Tony Finch
On Thu, 30 Sep 2010, Nicholas F Miller wrote: > Does anyone actually have GSS-TSIG working with an Active Directory? There are some GSS-TSIG interop fixes in 9.7.2. Tony. -- f.anthony.n.finchhttp://dotat.at/ HUMBER THAMES DOVER WIGHT PORTLAND: NORTH BACKING WEST OR NORTHWEST, 5 TO 7, DECREA

Re: GSS-TSIG and Active Directory

2010-09-30 Thread Dave Knight
On 2010-09-30, at 11:24 AM, Nicholas F Miller wrote: > Does anyone actually have GSS-TSIG working with an Active Directory? I see > plenty of posts from people trying to get it to work. I have yet to see > anyone who claims to actually have it working. Did MS change something in > 2008r2 since

Re: tkey-gssapi-credential

2010-09-30 Thread Rob Austein
Sorry, I spent most of the last two weeks locked in a conference room and mostly off net, still catching up. At Mon, 27 Sep 2010 07:54:54 -0600, Nicholas F Miller wrote: > > DNS Standard query TKEY > 472-ms-7.32-1772bef1.ddfb6613-c726-11df-dfa0-005056a22c3e >Queries >472-ms-7.32-1772

Re: per-zone-recursion?

2010-09-30 Thread Kevin Darcy
Per-zone recursion control doesn't exist in BIND, because frankly it doesn't make sense. Either a zone type is meaningless *without* recursion (type forward, type stub), or recursion is *unnecessary* because the nameserver answers from authoritative data (type master, type slave). Put anothe

Bind not starting

2010-09-30 Thread rams
Hi, I have configured records as follows in bind. When we start the bind 9.7, bind is not starting. But bind is started successfully when commented below ns domains which are marked as RED. Could you please clarify me. *Note: Bind 9.6 is started successfully with the same below zone. * Error: zon