Re: Multiple BIND instances

2012-02-07 Thread /dev/rob0
ice and the resolver are affected. I think the OP's goal (quite reasonable IMO) was to keep them separate, and what Jeff and I are talking about will do that. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in

lists.isc.org rDNS failed, DNSSEC?

2012-02-23 Thread /dev/rob0
- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: lists.isc.org rDNS failed, DNSSEC?

2012-02-28 Thread /dev/rob0
be validated to DNS replies, if the signatures are simply >ignored. At this point, those of us who do the validation are the ones who are suffering. I think we need something like a softfail, at least for expired RRSIGs. I don't know if it is possible to make that distinction, howev

Re: lists.isc.org rDNS failed, DNSSEC?

2012-02-28 Thread /dev/rob0
4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@li

Re: Named will not start when $ORIGIN is present, other errors also, bind 9.7.3-p3

2012-03-06 Thread /dev/rob0
are working as expected. You use the name of the zone for your "zone" statement. > 124 zone "zone001" IN { The argument for "zone" is the NAME OF YOUR ZONE. It is not an arbitrary string as you are using. If you want to serve a zone called "k

Re: Listen-on question

2012-04-13 Thread /dev/rob0
administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org http

Re: Listen-on question

2012-04-14 Thread /dev/rob0
you could simply remove "listen-on" from your options stanza. If you want to exclude the WAN interface, that's a different matter, but not difficult; just list all your internal addresses in listen-on statements. -- http://rob0.nodns4.us/ -- system administration and consulting

Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread /dev/rob0
her data The top of a zone cannot be a CNAME, because SOA and NS are required. The OP needs to talk to Google about their suggestion. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: __

Re: How to stop ANY zone transfer

2012-04-16 Thread /dev/rob0
ferent name, or if the testing host is not configured as a master to the slaves. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https:/

Re: Configuring CNAME for nosslsearch.google.com

2012-05-08 Thread /dev/rob0
quot;localhost."). > named-checkzone would have told you about both these problems. > > Less serious problems: > > It's better to use a $TTL directive than rely on it defaulting to > the SOA.MINTTL value (or specify all TTLs explicltly). > > You probably me

spam on the list

2012-05-16 Thread /dev/rob0
om:" header. "@.*@" in From: headers could be held for moderation and (in most cases) discarded. Thank you. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: __

Re: bind multiple instances

2012-05-18 Thread /dev/rob0
- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: ho to filter hundeds of domains ?

2012-08-30 Thread /dev/rob0
http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: question about how a particular dig works ...

2012-09-18 Thread /dev/rob0
ww.careerone.com.au > ... how does the cname record get defined and loaded successfully? I'd guess this is served by something other than BIND named. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen

Re: BIND 9.8.0 dns64 feature

2012-10-19 Thread /dev/rob0
ou can download the full source code from isc.org. If your organization has a budget for it, you could probably hire ISC for custom programming work. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___

Re: Shared dynamic zone on external view?

2012-11-08 Thread /dev/rob0
her-key subdomain ANY; > > grant princi...@rea.lm subdomain ANY; > > }; > > }; > > > > When I reload the configuration or try to initiate a zone > > transfer with dig and the "shared" key, I have this message > > in the logs. > >

Re: First usage of BIND9

2012-11-24 Thread /dev/rob0
firewall. Offer void where taxed or prohibited, or where something funny is going on (like a router hijacking DNS.) -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject:

Re: First usage of BIND9

2012-11-24 Thread /dev/rob0
e server, which is > what you are asking for. Most "caching-only" servers are in fact "caching-mainly". You might want a zone "localhost", and empty-zones-enable. My blank named.conf example does work, but is probably too minimal for most

Re: Building from source and running in chroot environment

2013-03-13 Thread /dev/rob0
e with the BIND 9 ARM. See chapter 7 thereof, which covers this. Bv9ARM.ch07.html#id2603962 -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https:

Re: ANNOUNCEMENT: New BIND versions are available.

2013-04-13 Thread /dev/rob0
fit of seeing the announcements on the discussion list is that in some cases discussion of the announcement itself might take place. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: __

Re: Views Question

2013-04-30 Thread /dev/rob0
d per view. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bi

Re: IPv4 not working reverse on > /24 cidr

2013-07-23 Thread /dev/rob0
ITYM RFC 2317, "Classless IN-ADDR.ARPA delegation": https://tools.ietf.org/html/rfc2317 -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please

Re: detect if zone/s is frozen

2013-09-03 Thread /dev/rob0
thaw"ed the zone until something odd happens > later on. I would suggest that if you're making much use of rndc freeze, YDIW. Consider using nsupdate(8) to make your changes. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen on

Re: detect if zone/s is frozen

2013-09-03 Thread /dev/rob0
On Tue, Sep 03, 2013 at 09:24:00PM +, Mike Hoskins (michoski) wrote: > -Original Message- > > From: /dev/rob0 > >On Tue, Sep 03, 2013 at 12:31:08PM -0700, Justin T Pryzby wrote: > >> Is there a nice way to tell if any zone is frozen (or a > >> specifi

Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread /dev/rob0
- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-us

Re: Refreshing cache in other DNS servers

2013-10-15 Thread /dev/rob0
not standards- compliant or if you cannot get support for it, you might consider replacing it with the Windows port of BIND. Good luck. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: _

BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2013-11-20 Thread /dev/rob0
on this myself, but I thought I should toss the idea out for comments and suggestions first. Specifically, I suppose that whatever work that is done should be compatible with the DocBook source and other BIND9-ARM formats. -- http://rob0.nodns4.us/ -- system administration and consultin

Re: any news/info re: RPZ2+RRL patches for bind 9.9.4-P1?

2013-11-21 Thread /dev/rob0
t; 9.9.4-P1? RRL is included in 9.9.4 already. Deployed and working here. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/

Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2013-11-21 Thread /dev/rob0
On Wed, Nov 20, 2013 at 09:43:40PM +, Evan Hunt wrote: > On Wed, Nov 20, 2013 at 03:27:59PM -0600, /dev/rob0 wrote: > > Looking at the HTML source for the Table of Contents, it seems > > like someone had this idea before but didn't follow through. > > There a

Re: error (no valid DS)

2013-11-26 Thread /dev/rob0
sulting Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: caps compiling error

2013-11-26 Thread /dev/rob0
he two --without-*, and as you can see, the removal of --with-idn. I had to experiment a few times to see where ./configure failed, adjusted it, and tried again. -- http://rob0.nodns4.us/ -- system administration and consulting Offlist GMX mail is seen only if "/dev/rob0" is in the

Re: Unable to transfer IPv4 reverse zone

2013-12-19 Thread /dev/rob0
192.168.5.2; > }; > allow-update { > key rndc-key; > }; > }; > > Slave Zone Configuration: > > zone "5.168.192.in-addr.arpa" { > type slave; > masters { > 1

Re: which end does the problem exist?

2013-12-19 Thread /dev/rob0
GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Adding DS records

2013-12-20 Thread /dev/rob0
sked here was in August: https://lists.isc.org/pipermail/bind-users/2013-August/091340.html If I was a NetSol customer, I would ask them, "Why not?" -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: _

Re: Monitoring Zonefiletransfer

2014-02-18 Thread /dev/rob0
ly always reach expireation time. and i get a lot > of critical messages and a few hours/minutes before expireation it > does the update. Not enough here to know what's going on. > i hope you can guide me a bit and tell me if this is what i want xD -- http://rob0.nodns4.us/ Offl

Re: Difference between BIND 9.8 and 9.9

2014-02-19 Thread /dev/rob0
h to consider. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lis

Re: disabling stateful firewalls for DNS traffic

2014-03-01 Thread /dev/rob0
is the best approach to use on or for machines which are primarily recursive nameservers, and it probably would not hurt authoritative servers, either. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: __

Re: disabling stateful firewalls for DNS traffic

2014-03-02 Thread /dev/rob0
On Mon, Mar 03, 2014 at 09:48:20AM +0800, Drunkard Zhang wrote: > 2014-03-02 3:04 GMT+08:00 /dev/rob0 : snip > > root@tp:~# iptables-save snip > > # Generated by iptables-save v1.4.20 on Sat Mar 1 12:42:55 2014 > > *raw > > :PREROUTING ACCEPT [96:19019] > >

Re: Audit the consistency of zone files on DNS servers

2014-03-15 Thread /dev/rob0
t though! ;o) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: What do you do when the Root records are wrong?

2014-04-03 Thread /dev/rob0
my.com Which ones? Are they authoritative for .net? > Network solutions say they can't do anything... -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman

Re: How to setup a backup NameServer?

2014-04-28 Thread /dev/rob0
s master) are among them. The BIND 9 ARM is a very good resource. Chapter 6 is the main reference part, but you might find useful examples in Chapter 4. https://kb.isc.org/article/AA-00845/ -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: _

Re: How to setup a backup NameServer?

2014-04-29 Thread /dev/rob0
not exist, and are unlikely to be in high demand. You're probably going to have to do/hire some custom programming, or else rethink the solution. I suspect the latter is your best bet. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___

Re: Zone transfer doesn't work when I set allow-update statement

2014-04-29 Thread /dev/rob0
h "named-journalprint ". > > > > If you want to dump the current version of the zone to disk so > > you can look at the whole thing, use "rndc sync ". > > > > (That's assuming this is a fairly recent BIND. If it doesn't > > support sy

Re: a note on 9.10.0rc2: eleven, twelve; dig and delv(e)

2014-04-30 Thread /dev/rob0
fair to leave the name with the one which has been using it longer. And while "Eleven, twelve; dig and delve" is a cool way to name the new tool, the name "delve" also seems to fit for a search engine's tool. ISC might have the bigger userbase, but there it is. Rel

Re: RRL active by default?

2014-05-02 Thread /dev/rob0
" you might try. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: bin 9.10 verbose logging

2014-05-04 Thread /dev/rob0
-severity in the default_log file will quickly show you which category + severity is causing the noise. Then, you can define another channel to deal with those as you consider necessary / best. Refer to ARM chapter 6 for details: bind-9.10.0/doc/arm/Bv9ARM.ch06.html#id2574892 -- http://rob0.nod

Re: logging via named.conf

2014-05-31 Thread /dev/rob0
logging ? "category default" covers everything not specifically listed. When other categories are listed in the logging stanza, those are removed from "category default". -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject:

Re: Slave zero-TTL on CNAMES

2014-06-05 Thread /dev/rob0
Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Slave zero-TTL on CNAMES -> no ip nat service alg udp dns

2014-06-05 Thread /dev/rob0
go even killed zone transfers at least from > "large" zones at all as well as PTR answers from the NAT behind > containing the public IP > > thanks and sorry for the noise No problem, it's not noise. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "

Re: Why the heck my NS are not working

2014-07-21 Thread /dev/rob0
> in-zone contents. The "in" servers give a referral to snip -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

rndc (was: Re: Reload BIND ...)

2014-07-31 Thread /dev/rob0
e it. :) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: rndc

2014-07-31 Thread /dev/rob0
-- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://

Re: rndc (and now nsupdate too)

2014-07-31 Thread /dev/rob0
On Thu, Jul 31, 2014 at 05:56:08PM +0200, Reindl Harald wrote: > Am 31.07.2014 um 17:41 schrieb /dev/rob0: > > On Thu, Jul 31, 2014 at 01:32:03PM +0200, Reindl Harald wrote: > >> i am doing reloads of named with "killall -HUP named" just > >> because i disable

Re: Metazones or Something Else?

2014-08-05 Thread /dev/rob0
mply have the web form do the "rndc addzone" remotely. Lots of choices, not easy to say what's best. Except that addzone (and delzone also) works at runtime, not requiring a separate "rndc reconfig" to load (or remove) zones. -- http://rob0.nodns4.us/ Offli

Re: Root servers

2014-08-14 Thread /dev/rob0
t; ; on server FTP.INTERNIC.NET > ; -OR-RS.INTERNIC.NET > ; > ; last update:Feb 04, 2008 > ; related version of root zone: 2008020400 That's old, but not so old as to prevent you from reaching an actual root server.

Re: Root servers

2014-08-15 Thread /dev/rob0
ND version. If the OS is so old to be have a 2008020400 hint file, it probably means no updates have been done along the way. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: DNS reverse sub delegation NXDOMAIN problem, Class C

2014-08-19 Thread /dev/rob0
That said, sure, typically you're going to host such internal-only zones on a server that also does recursion. That's not required, however. The recursive server could have stub or static-stub zones, or even an alternate root zone, which points to the authoritative server. Pedantr

Re: A record of domain name must be name server ?

2014-09-08 Thread /dev/rob0
st have either or both A and records for those NS names. Here is the same zone without the XXX and with all relative names: > @ IN SOA ns1 root.ns1 ( > 2014090801 ; serial > 2h ; refresh > 10m; retry > 1w ; expiry >

Re: Two domains reporting errors

2014-09-10 Thread /dev/rob0
oad as any zone name. You might want to use some fully-qualified names on the RHS, such as "root.covisp.net." as the SOA RNAME. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: slave fail to ixfr from master

2014-09-14 Thread /dev/rob0
aster and slave, if this wasn't enough to get it figured out. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscri

Re: DNSSEC

2015-01-17 Thread /dev/rob0
ob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.i

Re: Disable DNSSEC Validation for selected Domains

2015-01-17 Thread /dev/rob0
; Documentations etc... I wouldn't be surprised if they are not even > aware of the problem, yet. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/

Re: Bind in FreeBSD 10

2015-01-22 Thread /dev/rob0
rsion (ESV), so it's likely to outlive 9.10. If you're after long-term stability, ESV might be important to you. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit ht

Re: Setup our OWN DNS Server

2015-01-30 Thread /dev/rob0
lly, of course, this mailing list has a lot of experienced people, willing to help you out if you get stuck. Good luck! -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.

Re: Share RPZ Zones between views

2015-02-20 Thread /dev/rob0
GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: dynamic update of split view acl

2015-02-28 Thread /dev/rob0
the serial of view1.zone and view2.zone, but > 204.57.0.0/24 is still matched by view1. Is there any way to > accomplish this? Right. So you redo your acl statements and do "rndc reconfig". The acls are simply there to make it easier to manage. The real answer is reconfig. That wil

Re: Too many connections on the same IP

2015-03-04 Thread /dev/rob0
ork > interface. This could explain, why your second IP is still > responding. There is a single conntrack table for the system, and all entries therein are based on packet header information: source and destination IP address (and ports if applicable.) We really don't have enough info

Re: unable-resolving

2015-03-09 Thread /dev/rob0
can't find www.twitter.com: Server failed Two suggestions: first, get rid of nslookup. Use dig and share the dig query and result with the list. Second, check your logs for the exact time of these SERVFAIL responses you're seeing. Sometimes these will be logged. -- http://rob0

Re: forwarder and cache

2015-03-16 Thread /dev/rob0
e SOA), the NXDOMAIN result is cached. For more help show your actual dig commands and results. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/

Re: Single slave zone definition for two view (cache file name problem)

2015-03-17 Thread /dev/rob0
a good workaround for that. But there are tools like make(1) which can do this for you? I would suggest a script to generate the common.zones file from whatever you're using for the "common" view. Maybe someone else will have a better suggestion? -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread /dev/rob0
that would be to have some kind of variable in the named.conf syntax to refer to the name of the current view. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread /dev/rob0
On Wed, Mar 18, 2015 at 06:11:56PM +0300, Konstantin Stefanov wrote: > On 18.03.2015 17:41, /dev/rob0 wrote: > > On Wed, Mar 18, 2015 at 11:48:40AM +0300, Constantin Stefanov wrote: > >> I see why it may lead to problems. > >> > >> But in fact the confi

Re: BIND not loading into memory on first transfer

2015-03-27 Thread /dev/rob0
pened, and while this sounds more reasonable, I am not sure that the zone transfer actually does take place if named is unable to open a temporary file to write. (What would be the point in talking to the master when you know you are unable to handle the data?) -- http://rob0.nodns4.us/ Offl

Re: behavior of dnssec-enable in relation to dnssec-validation

2015-03-27 Thread /dev/rob0
ation Enable DNSSEC validation in named. Note dnssec-enable also needs to be set to yes to be effective. ... " This does not seem to be the case. I think bug, whether it's the documentation or the behavior. > misinterpreting the apparent behavior? something else? -- http:

Re: com.google how did they do that

2015-04-01 Thread /dev/rob0
nd more coming. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-u

Re: Getting an error on a very simple DNS configuration

2015-04-08 Thread /dev/rob0
e which covers compiling from source and running a simple named for recursion: https://kb.isc.org/article/AA-00768/ -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit http

Re: [bind-users] Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2015-05-10 Thread /dev/rob0
nobody's done it yet. Oops, sorry. When I suggested it I was unemployed, and now [thankfully] am not. $Dayjob keeps me busy, but now I have more clue about the docbook, so I'll try to do what I can. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" i

Re: file descriptor exceeds limit

2015-06-19 Thread /dev/rob0
ply to Cathy...more detail on that > there. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: file descriptor exceeds limit

2015-06-19 Thread /dev/rob0
f conntrack for UDP DNS upstream, unless you're using DNAT > (yuck.) Oh ... hahaha ... I missed the @cisco.com, so I don't suppose you're using Linux on your upstream routers. :) The same idea applies regardless of implementation, of course. -- http://rob0.nodns4.us/ Offli

Re: dynamic zone file "style"

2015-07-08 Thread /dev/rob0
> single file. And, luckily, it uses the "full" style :) So this > should be fine for me. > > But before I try to re-invent the wheel: > Does anyone know if there is already a parser for multiple > zone_files/zone_dumps/zone_transfers? I'm trying to filter all DNS >

Re: About CVE-2015-5477 ("An error in handling TKEY queries can cause named to exit with a REQUIRE assertion failure")

2015-07-28 Thread /dev/rob0
another server. But if you're thinking it's okay because you're going to deny the query, no! This happens before named gets to that point. Your nameserver must be closed to ALL potentially hostile queries. -- http://rob0.nodns4.us/ Offlist GMX mail is seen

Re: ERROR : - writeable file 'data/udalgurijudiciarygov.hosts': already in use: /etc/nicnet2007.govdomain:15424 - loading configuration: failure

2015-08-04 Thread /dev/rob0
t everything per zone.) > To hold us/me over until they decide if its going to be > BlueCat or Infoblox that replaces everything. IIUC both of those are BIND under the hood. :) > Sadly, I missed both presentations due to other issuesmore sad > because I found my "named.

correction

2015-08-04 Thread /dev/rob0
On Tue, Aug 04, 2015 at 07:14:38AM -0500, /dev/rob0 wrote: > It would require some reworking of things, but you might be > interested in the new BIND 9.10 feature of "in-view" zone option. > This lets you literally include a zone from another view. See > BIND 9 ARM chap

Re: bind 9.8 named_stats parser

2015-08-04 Thread /dev/rob0
gt; If not I will need to deploy by my self ... then of > course will share it. There too, if you're doing things the old way on abandoned old software versions, I wouldn't expect to find much interest. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/r

Re: configuration error in lists.isc.org

2015-08-06 Thread /dev/rob0
s. Some of them use it for such things as killfiling. But thank you for bringing this issue up. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Can I run two name servers on one host with two IP addresses?

2015-08-20 Thread /dev/rob0
r service here.) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.o

Re: DNSSEC secondary (free)

2015-08-20 Thread /dev/rob0
ut 3.1 forevers. Does anyone know if exploration was successful? > experience, but we’ve been considering using them for the same > purpose, and they seem to have a good community reputation). -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0&q

Re: More On Split Horizon & Slaves

2015-08-22 Thread /dev/rob0
y, so that the slave knows > which view is which, but I am not clear on how to do this when both > views are in the same namespace. https://kb.isc.org/article/AA-00296/0 https://kb.isc.org/article/AA-00851/0 -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/ro

Re: Installing bind is not very clear for me

2015-09-04 Thread /dev/rob0
nvolved a compromise of any kind? I cannot say with authority that BIND9 has never had a compromise, but I am confident in saying I have never seen one. https://www.isc.org/blogs/summer_security_vulnerabilities/ is a recent blog posting which discusses this in det

Re: Installing bind is not very clear for me

2015-09-04 Thread /dev/rob0
On Fri, Sep 04, 2015 at 05:27:18PM +, Mike Hoskins (michoski) wrote: > On 9/4/15, 1:12 PM, "bind-users-boun...@lists.isc.org on behalf > of /dev/rob0" r...@gmx.co.uk> wrote: > > >On Thu, Sep 03, 2015 at 11:02:23PM +0200, Reindl Harald wrote: > >>

Re: Install BIND 9.9.7-P2 to fix vulnerability CVE-2015-5477

2015-09-07 Thread /dev/rob0
sion. I would suggest that you invest some time in learning Red Hat basic administration skills, and with it some shell basics, and you will become able to diagnose and fix these problems on your own. Good luck. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0&q

Re: Caching and upper case issue with BIND 9.9.7-P3

2015-09-26 Thread /dev/rob0
r choices: rndc flush rndc flushtree example.com -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: Bind and views

2015-10-07 Thread /dev/rob0
;s the right one? If you want to share a zone in more than one view, do as Mark suggested: upgrade to 9.10.3 and use "in-view". You probably ought to consider upgrading anyway, because of recent security patches. > Important: i need the views binded to differents ips. -- h

Re: root hints operation

2015-11-16 Thread /dev/rob0
> Will someone take a moment and confirm, or correct, my > understanding of how root hints work in BIND? I think this should answer your questions: https://www.isc.org/blogs/h-root-will-change-its-addresses-on-1-december-2015-what-does-this-mean-for-you/ -- http://rob0.nodns4.us/

Re: Database driven ACL

2016-02-29 Thread /dev/rob0
7;s what you meant about "reading/writing into a text file".) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscr

Re: Multiple A records and reverse DNS

2016-03-18 Thread /dev/rob0
irly easy in Linux, albeit not particularly well documented. For other OSs, I wouldn't know. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailma

Re: about NS server authorize

2016-03-21 Thread /dev/rob0
can help you. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: *Reminder of the* L-Root IPv6 address renumbering

2016-03-21 Thread /dev/rob0
ed upthread: > New hints files will be available at the following URLs once > the change has been formally executed on March 23, 2016: > > * http://www.internic.net/domain/named.root > * http://www.internic.net/domain/named.cache -- h

Re: Recursive bind becomes unresponsive with high load

2016-04-01 Thread /dev/rob0
= 512 > net.ipv4.neigh.default.gc_thresh2 = 1024 > net.ipv4.neigh.default.gc_thresh3 = 2048 > net.ipv4.tcp_max_syn_backlog = 4096 > net.ipv4.tcp_fin_timeout = 30 > net.ipv4.tcp_tw_recycle = 1 -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in

Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-24 Thread /dev/rob0
messages 1, bytes 178) > > cd > grep -rlni acme . > (empty) > > What am I failing to do to make this update persistent across flush/restart, > as intended? What is deleting your journal? It's not named doing that. Why was the journal not written to the z

  1   2   >