Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread Phil Mayers
On 10/13/2013 10:34 PM, John Oliver wrote: Venting aside, does anyone have a contact at GoDaddy that doesn't suffer from a terminal case of rectal-cranial invesrion? I'm mainly experimenting with DNSSEC, and don't want to move all of my domains over this one issue. But then, if this is the lev

Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread /dev/rob0
On Mon, Oct 14, 2013 at 10:06:07AM +0100, Phil Mayers wrote: > On 10/13/2013 10:34 PM, John Oliver wrote: > > >Venting aside, does anyone have a contact at GoDaddy that doesn't > >suffer from a terminal case of rectal-cranial invesrion? > > GoDaddy are... not good. I would not have high hopes of

Re: moving DNSSEC to a hidden master

2013-10-14 Thread Alan Clegg
On Oct 13, 2013, at 9:03 PM, David Newman wrote: > >>> This is where things fall apart. I run 'rndc freeze' and > >>> increment the zone file's serial number (or make any other > >>> change), and then run 'rndc thaw' and 'rndc reload'. So, I'm going to jump back a bit here If the configurat

Re: moving DNSSEC to a hidden master

2013-10-14 Thread Alan Clegg
On Oct 14, 2013, at 7:43 PM, Alan Clegg wrote: > == Commands typed == > root@server00:/etc/namedb# ls > bind.keys keys master named.conf rndc.key > root@server00:/etc/namedb# cd master > root@server00:/etc/namedb/master# ls > example.com example.com.jbk example.com.signed example.com.sign

Re: moving DNSSEC to a hidden master [SOLVED]

2013-10-14 Thread David Newman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Alan, Thanks very much for your responses. Per my comments inline below, this actually wasn't broken to begin with, but I just wasn't seeing it. On 10/14/13 10:43 AM, Alan Clegg wrote: > > On Oct 13, 2013, at 9:03 PM, David Newman > wrote: > >>

Re: moving DNSSEC to a hidden master [SOLVED]

2013-10-14 Thread Alan Clegg
On Oct 14, 2013, at 9:12 PM, David Newman wrote: > Thanks very much for your responses. Per my comments inline below, > this actually wasn't broken to begin with, but I just wasn't seeing it. 8-) No problems. > > So, I'm going to jump back a bit here If the configuration that > > you post

Re: moving DNSSEC to a hidden master [SOLVED]

2013-10-14 Thread David Newman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/14/13 12:39 PM, Alan Clegg wrote: >> In this case, I started with a serial of 2013092700, incremented >> it to 2013092701, and reloaded. 'dig soa' would still return >> 2013092700. >> >> Problem is, bind logged the current serial number as 2013

Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread John Oliver
On Mon, 14 Oct 2013 11:08:33 -0500, /dev/rob0 wrote: > On Mon, Oct 14, 2013 at 10:06:07AM +0100, Phil Mayers wrote: >> On 10/13/2013 10:34 PM, John Oliver wrote: >> >> >Venting aside, does anyone have a contact at GoDaddy that doesn't >> >suffer from a terminal case of rectal-cranial invesrion? >

Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread John Oliver
On Mon, 14 Oct 2013 11:08:33 -0500, /dev/rob0 wrote: > On Mon, Oct 14, 2013 at 10:06:07AM +0100, Phil Mayers wrote: >> On 10/13/2013 10:34 PM, John Oliver wrote: >> >> >Venting aside, does anyone have a contact at GoDaddy that doesn't >> >suffer from a terminal case of rectal-cranial invesrion? >