Which timeouts are used by BIND when resolving recursive queries?

2018-10-05 Thread ip admin via bind-users
Hi, I understand that I can configure a global timeout for resolving recursive queries (resolver-query-timeout) but find that I cannot configure the timeout for an individual query used during DNS resolution. For testing I configured one unreachable forwarder (and enabled forward only) and saw

Re: Which timeouts are used by BIND when resolving recursive queries?

2018-10-05 Thread Alberto Colosi
RFC say all read RFC BIND is a DNS system not an alien so follow RFC Go and read RFC From: bind-users on behalf of ip admin via bind-users Sent: Friday, October 5, 2018 4:13 PM To: bind-users@lists.isc.org Subject: Which timeouts are used by BIND when res

Re: DNSSEC: give KSK from my domain to parent zones

2018-10-05 Thread Chris Thompson
On Oct 4 2018, Mark Elkins wrote: On 10/04/2018 05:03 PM, Roberto Carna wrote: [...] I have two DNS servers running BIND 9.10, they have delegated my own domain, let's say "robert.com.uk " and some other domains from our clients, let's say: client1.com.uk

Re: DNSSEC: give KSK from my domain to parent zones

2018-10-05 Thread Roberto Carna
Thanks a lot to all of youNow I understand. But when I check for the DNSEC support with: dig com.uk +dnssec +multi I can see there is no support at all...so use DNSSEC for xxx.com.uk has no sense at allhasn't it? ; <<>> DiG 9.10.3-P4-Debian <<>> com.uk +dnssec +multi ;; global options:

Re: DNSSEC: give KSK from my domain to parent zones

2018-10-05 Thread G.W. Haywood via bind-users
Hi there, On Fri, 5 Oct 2018, Roberto Carna wrote: ... when I check for the DNSEC support with: dig com.uk +dnssec +multi I can see there is no support at all...so use DNSSEC for xxx.com.uk has no sense at allhasn't it? Do you mean "xxx.co.uk" and not "xxx.com.uk"? -- 73, Ged. ___

DNSSEC validation option in BIND 9.10

2018-10-05 Thread Tom Yard
Hi people, I have two BIND 9.10.3 servers with DNSSEC validation enabled, one in one client and the other in another client. Both BIND have the same configuration lines relative to DNSSEC validation: dnssec-validation auto; dnssec-enable yes; and both has the current and future key in bind.keys.