Re: rndc

2014-08-01 Thread Alan Clegg
On 8/1/14, 1:58 AM, Reindl Harald wrote: > i did not pretend it's a perfect solution in every environment > but it is suiteable for many and so a valid opportunity Sorry, yours is a bad solution for most and doing rndc correctly is a much better solution for nearly everyone. There, I said it. A

SERVFAIL when increasing recursive-clients? (Was: bind-users Digest, Vol 1902, Issue 2

2014-08-01 Thread Stephane Bortzmeyer
On Fri, Aug 01, 2014 at 09:56:53AM +0700, Xuan Hung wrote a message of 298 lines which said: > I think this problem of me, need have version new of Bind. 9.9.5 is quite recent. Actually, it is the latest in 9.9 branch. What makes you think upgrading would change anything? > I think resolver

Re: rndc (and now nsupdate too)

2014-08-01 Thread Tony Finch
Reindl Harald wrote: > Am 31.07.2014 um 21:08 schrieb /dev/rob0: > > > > The proper tool to manage zone data is nsupdate(8). Likewise well > > suited for automation. > > zone file *editing*? > > sorry, no, i developed 2008 a interface to create all zone files based > on database records, write th

Logs problem with Bind 9.9.4

2014-08-01 Thread ahmed salim
Hi everybody we recently installed Bind 9.9.4 on CentOS 7, and it's working properly. the only problem that we have is the (logging), we can't stop logging. First thing I tried is to disable IPv6 logs, by editing "/etc/sysconfig/named" and make (OPTIONS="-4"), but that doesn't work . After that, I

Re: Logs problem with Bind 9.9.4

2014-08-01 Thread Reindl Harald
Am 01.08.2014 um 11:56 schrieb ahmed salim: > we recently installed Bind 9.9.4 on CentOS 7, and it's working properly. > the only problem that we have is the (logging), we can't stop logging. > First thing I tried is to disable IPv6 logs, by editing > "/etc/sysconfig/named" and make (OPTIONS="-4

Re: rndc (and now nsupdate too)

2014-08-01 Thread Mike Hoskins (michoski)
-Original Message- From: Tony Finch Date: Friday, August 1, 2014 at 5:31 AM To: Reindl Harald Cc: "bind-users@lists.isc.org" Subject: Re: rndc (and now nsupdate too) >Reindl Harald wrote: >> Am 31.07.2014 um 21:08 schrieb /dev/rob0: >> > >> > The proper tool to manage zone data is nsup

Re: rndc (and now nsupdate too)

2014-08-01 Thread Reindl Harald
Am 01.08.2014 um 15:14 schrieb Mike Hoskins (michoski): > From: Tony Finch > Date: Friday, August 1, 2014 at 5:31 AM > To: Reindl Harald > Cc: "bind-users@lists.isc.org" > Subject: Re: rndc (and now nsupdate too) > >> Reindl Harald wrote: >>> Am 31.07.2014 um 21:08 schrieb /dev/rob0: >>>

Re: rndc (and now nsupdate too)

2014-08-01 Thread Mike Hoskins (michoski)
-Original Message- From: Reindl Harald Organization: the lounge interactive design Date: Friday, August 1, 2014 at 9:23 AM To: "bind-users@lists.isc.org" Subject: Re: rndc (and now nsupdate too) > >Am 01.08.2014 um 15:14 schrieb Mike Hoskins (michoski): >> From: Tony Finch >> Date: Frid

Re: rndc (and now nsupdate too)

2014-08-01 Thread Reindl Harald
Am 01.08.2014 um 15:44 schrieb Mike Hoskins (michoski): >>> no argument on nsupdate, but even if you copy files around...you don't >>> need to bounce the nameserver, unless rndc reload is what you mean >>> (when i >>> hear bounce i think stop/start) >> >> since when is -SIGHUP stop/start? > > i

Re: rndc (and now nsupdate too)

2014-08-01 Thread Johannes Kastl
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi everyone, On 01.08.14 15:58 Reindl Harald wrote: > the whole discussion about rndc or not rndc follow up therads and > side-threads startet after that reply below from me yesterday and > whoever brought "bounce" in the game did also not understand

BIND and listening on interfaces

2014-08-01 Thread Reindl Harald
the thread yesterday reminded me on my Fedora bugrpeort https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c3 https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c8 i don't buy "Note that destination IP address must be known and set correctly in reply, otherwise clients will be confused" because

Re: BIND and listening on interfaces

2014-08-01 Thread Barry Margolin
In article , Reindl Harald wrote: > the thread yesterday reminded me on my Fedora bugrpeort > https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c3 > https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c8 > > i don't buy "Note that destination IP address must be > known and set correctly in re

Re: BIND and listening on interfaces

2014-08-01 Thread Reindl Harald
Am 01.08.2014 um 17:16 schrieb Barry Margolin: > In article , > Reindl Harald wrote: > >> the thread yesterday reminded me on my Fedora bugrpeort >> https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c3 >> https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c8 >> >> i don't buy "Note that des

Re: BIND and listening on interfaces

2014-08-01 Thread Phil Mayers
On 01/08/14 15:46, Reindl Harald wrote: if listen-on {0.0.0.0;}; would work a lot of problems could go away - keep in mind that on modern systemd systems a service can bind to 0.0.0.0 even before the network is started Most people just use "rndc reconfig". In bind 9.10 the routing socket, on

Re: rndc (and now nsupdate too)

2014-08-01 Thread Tony Finch
Mike Hoskins (michoski) wrote: > Tony Finch wrote: > > > >In our setup, changes made in the database are turned into an nsupdate > >script, so we don't need to bounce the name server and we can use > >BIND's automatic signing. > > no argument on nsupdate, but even if you copy files around...you d

Re: BIND and listening on interfaces

2014-08-01 Thread Sam Wilson
In article , Reindl Harald wrote: > Am 01.08.2014 um 17:16 schrieb Barry Margolin: > > In article , > > Reindl Harald wrote: > > > >> the thread yesterday reminded me on my Fedora bugrpeort > >> https://bugzilla.redhat.com/show_bug.cgi?id=1073038#c3 > >> https://bugzilla.redhat.com/show_bug.c

Re: rndc (and now nsupdate too)

2014-08-01 Thread Victoria Risk
This recent thread, in which people are describing their scripts and GUI provisioning systems makes me think we should recruit a few of you who think you have a sweet provisioning system, to do a WebEX and describe it for everyone else who is looking for a better system. At the RIPE meeting in

Re: Reload BIND to listen on additional interface?

2014-08-01 Thread Johannes Kastl
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 31.07.14 13:55 Mark Andrews wrote: > > 9.10 also has "rndc scan" for platforms without a routing socket or > if you want to do it manually. As I have not found a working RPM of bind 9.10 for openSUSE this far, I have to ask: How to handle this us

Re: BIND and listening on interfaces

2014-08-01 Thread Reindl Harald
Am 01.08.2014 um 18:06 schrieb Phil Mayers: > Binding separate sockets per IP is IMO just as reliable, and is well tested. > If you > weren't so opposed to "rndc", you could just call "rndc reconfig" in whatever > network system/dispatch tool you have after IPs - or wait for bind 9.10. it's not

Re: BIND and listening on interfaces

2014-08-01 Thread Mark Andrews
In message <53dba84d.8030...@thelounge.net>, Reindl Harald writes: > > the thread yesterday reminded me on my Fedora bugrpeort > https://bugzilla.redhat.com/show_bug.cgi?id=3D1073038#c3 > https://bugzilla.redhat.com/show_bug.cgi?id=3D1073038#c8 > > i don't buy "Note that destination IP address m

php-library added -> Re: rndc (and now nsupdate too)

2014-08-01 Thread Reindl Harald
> This recent thread, in which people are describing their scripts and > GUI provisioning systems makes me think we should recruit a few of > you who think you have a sweet provisioning system at least i add the library i developed to maintain zone-files which needs translation of the comments, to