Re: Logging issue with bind

2012-02-16 Thread Jeremy C. Reed
On Fri, 17 Feb 2012, Mark Andrews wrote: > > Do: > > > > rndc querylog > > or "querylog yes;" But the previous email showed rndc status had: query logging is ON ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: Logging issue with bind

2012-02-17 Thread Jeremy C. Reed
On Fri, 17 Feb 2012, Andrea Gozzi wrote: > All further tests haven't produced any results. Any related log messages in your other named logging about it. (Maybe some isc_stdio_open error for example?) Why were the permissions of your log file rwxrwxrwx? (Why executable? Why writable by other?)

Re: www.glb.hud.gov

2012-04-19 Thread Jeremy C. Reed
t just means to use the default which is still enabled. To test use "dig +cd". Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Convice Bind to listen on IP alias with a range of IPs.

2012-04-30 Thread Jeremy C. Reed
On Mon, 30 Apr 2012, Augie Schwer wrote: > I must be doing something wrong, because what I want to do doesn't > seem that difficult. > > I have a range of IPs bound to a local interface: > > lo:1 Link encap:Local Loopback > inet addr:10.0.0.1 Mask:255.255.255.224 > > And I want

Re: Host command timing out sporadically

2012-05-02 Thread Jeremy C. Reed
On Wed, 2 May 2012, Paul Marais wrote: > I'm having an issue where my postfix server is having trouble with some > lookups. > When I type 'host ', 80% of the time I get decent reply speed, but > for 20% I get a 5 second delay, or even a timeout. > > My nameserver is configured to only allow rec

Re: Operation cancelled Error

2012-05-24 Thread Jeremy C. Reed
e way, to set some comparison maximum baseline you can try having resperf query the built-in zones. (It won't be real recursive work, but should show you some potential maximum qps.) Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/m

Re: Bind 9.9.x operation with dnssec

2012-06-01 Thread Jeremy C. Reed
On Fri, 1 Jun 2012, Alan Batie wrote: > When it comes to the DS records registered at the registrar, I'm not > sure where that comes from: the only way I can see to get it is to do a > DS query from the nameserver (and at least one document basically said > that). First, I'd like to know where it

Re: Compiling and testing on Fedora

2012-06-20 Thread Jeremy C. Reed
I don't immediately recognize the issue. But hopefully the detailed named debugging output is saved. Look for the "*.run" (maybe named.run) files. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-us

Re: Dig 9.9.1 AD-bit

2012-08-02 Thread Jeremy C. Reed
On Thu, 2 Aug 2012, Marco Davids (SIDN) wrote: > Dig 9.9.1 is setting the AD-bit in queries by default. > > Does anyone know why? 3205. [func] Upgrade dig's defaults to better reflect modern nameserver behaviour. Enable "dig +adflag" and

Re: Version statement...

2012-08-18 Thread Jeremy C. Reed
How are you testing it? Where do you see the wrong version? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-use

Re: Zone Transfer issue on BIND9

2012-08-24 Thread Jeremy C. Reed
On Fri, 24 Aug 2012, sn...@email.it wrote: > ***MASTER server (FreeBSD 9.0-RELEASE-p3 (i386)|| BIND 9.8.3-P2)*** > view "internal" { > match-clients { !key TSIG-KEY; internal; datacentre; }; ... > view "dmz" { > match-clients { !key TSIG-KEY; internal; datacentre; }; A client

Re: Zone Transfer issue on BIND9

2012-08-24 Thread Jeremy C. Reed
On Fri, 24 Aug 2012, sn...@email.it wrote: > view "internal" { ... > zone "1.16.172.in-addr.arpa" IN { > type master; > file "/etc/namedb/master/1.16.172.in-addr.arpa.ext.zone"; Previous zone file names in this same view were called "int". Why the filenam

Re: Problem with ACL in named.conf

2012-08-29 Thread Jeremy C. Reed
On Thu, 30 Aug 2012, GS Bryan wrote: > also-notify { "alladdr"; }; This uses an ip_addr instead of an address_match_list. Some versions of named-checkconf will tell you "expected IP address". > /etc/named.conf:111: masters "alladdr" not found I can't reproduce your problem. What versio

Re: Issue with Minumum Value for named9

2012-09-21 Thread Jeremy C. Reed
On Fri, 21 Sep 2012, Robert JR wrote: > i have the minimum value in my dns server as 60 mins, and my TTL is 60 > Seconds , but still when users hit a non exist record , the other dns hold > the negative cache for 60 secs instead of 60 mins .. ? why ?  > > $TTL 60 > @ IN SOA NS1.TEST.BIZ. Abuse.TE

Re: How to prevent BIND from resolving addresses in logs

2012-09-27 Thread Jeremy C. Reed
On Thu, 27 Sep 2012, Spumonti Spumonti wrote: > I just installed BIND 9.9.1-P3 from source and while looking through > the query log files I noticed that IP addresses were being resolved: > > > 27-Sep-2012 12:01:56.512 client 192.168.5.10#44863 (host.foo.com): > query: www.ibm.com ... That i

Re: Disable log message

2012-10-18 Thread Jeremy C. Reed
On Thu, 18 Oct 2012, Jack Tavares wrote: > I am running bind9.8.x built from source and I see this message in the logs > built with '--prefix=/blah' '--sbindir=/blah' '--sysconfdir=/blah' > '--localstatedir=/var' '--exec-prefix=/usr' '--libdir=/usr/lib' > '--mandir=/usr/share/man' '--with-opens

Re: squash 'client query (cache) denied' syslog entries

2012-10-18 Thread Jeremy C. Reed
On Thu, 18 Oct 2012, David Dowdle wrote: > Some of my external facing nameservers are under attack, and the biggiest > fallout, is the machines goign into iowait from logging all the client query > denied syslog messages. > > note: yes, recursion is turned off on these machines. > > The current

Re: BIND 9.9.1-P4 is now available

2012-10-25 Thread Jeremy C. Reed
like the one above are misleading and even the named may be working correctly but it is slow.) Jeremy C. Reed ISC___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lis

Re: Need to improve named performance

2012-11-12 Thread Jeremy C. Reed
On Mon, 12 Nov 2012, Ed LaFrance wrote: > Currently I'm not using query logging, it's not in my options at all. I think "rndc querylog" was used to enable it (even if no corresponding logging configuration). You can use it again to toggle it off. "rndc status" will show if query logging is on

Re: another performance tuning question

2012-11-30 Thread Jeremy C. Reed
On Fri, 30 Nov 2012, Adamiec, Lawrence wrote: > I got similar results when running against the master server. Then why so many lost? >   Queries sent:         11000 queries >   Queries completed:    8968 queries >   Queries lost:         2032 queries ... >   Percentage completed:  81.53% >   Per

Re: Strange Issue

2012-12-12 Thread Jeremy C. Reed
shows no errors.  There are also no > errors in the logs. > > Any ideas? You may want to verify you are querying the correct name server? (and enable extra logging for that) Also it may be easier for others to point out problems if you show the actual configurations, data, reproducable

BIND 10 - 1.0.0 Beta Release

2012-12-20 Thread Jeremy C. Reed
encies between two libraries in the same directory. (Trac #2475, git 834fa9e8f5097c6fd06845620f68547a97da8ff8) Thanks again to those who contributed bug reports, code, and reviews. Jeremy C. Reed ISC Release Engineer -BEGIN PGP SIGN

what do you use for logging?

2013-01-17 Thread Jeremy C. Reed
documentation for each of its 933 possible log identifiers!) Thanks! Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: Performance impact of a large ACL list.

2013-02-04 Thread Jeremy C. Reed
On Mon, 4 Feb 2013, Augie Schwer wrote: > Does anyone have any experience using a large ( 1k ) entry ACL list? > Was there any performance degradation? > > I haven't implemented my ACL yet, but it has quickly ballooned up, and I am > hoping to get some advice from others in a similar situation.

BIND 10 - 1.0.0 Release Candidate

2013-02-14 Thread Jeremy C. Reed
logging into Trac) at: http://bind10.isc.org/ Please feel free to participate and share your feedback on the BIND 10 mailing lists: https://lists.isc.org/mailman/listinfo/bind10-users https://lists.isc.org/mailman/listinfo/bind10-dev Jeremy C. Reed ISC Release

Re: "make test" fails on Fedora 10

2013-03-27 Thread Jeremy C. Reed
On Wed, 27 Mar 2013, Luther, Dan wrote: > For the tests, BIND starts up with an empty group descriptor: > >   > > I:issuing command '/home/luther/bind-9.9.2-P2/bin/named/named -m > record,size,mctx -T clienttest -c named.conf -d 99 -g >named.run 2>&1 &echo > $!' I guess you are talking about -g

Re: "make test" fails on Fedora 10

2013-03-27 Thread Jeremy C. Reed
On Wed, 27 Mar 2013, Luther, Dan wrote: > Working with the BIND 9.9.2-P2 compile, I just spent several minutes > tracking the source of this down with some judicious use of ?print? in the > ?bin/tests/system/start.pl? script and viewing the ?*.run? output. It really > comes down to file permission

Re: This list's prefix

2013-06-05 Thread Jeremy C. Reed
On Wed, 5 Jun 2013, Narcis Garcia wrote: > It's not the only mailing list where I'm subscribed. > Could please the administrator setup a prefix for messages' subject? > > For example: > [bind-u] Please just have your MUA or your mail filtering client look at the following header (and add the su

Re: Notice: BIND Security Jul2013 CVE2013-4854

2013-07-27 Thread Jeremy C. Reed
le via FTP) Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: auto-dnssec maintain and no key: no error message?

2013-07-30 Thread Jeremy C. Reed
On Tue, 30 Jul 2013, Stephane Bortzmeyer wrote: > Of course, there is no signature: > > % dig +multi @localhost SOA auto.rd.nic.fr Add +dnssec ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: the location of dig and named

2013-08-28 Thread Jeremy C. Reed
On Wed, 28 Aug 2013, Nidal Shater wrote: > when I typed dig  or named ,,, what is the location of the executable > program dig and named is ? Maybe one of these will help: command -v dig type dig which dig whereis dig command -v named type named which named whereis named There are many othe

Re: Upgrade Bind documentation

2013-10-24 Thread Jeremy C. Reed
the tarball). I am working on a chart listing the major features introduces and any incompatible changes to be aware of for all of our releases. But it is not ready yet. Jeremy C. Reed ISC___ Please visit https://lists.isc.org/mailman/listinfo/bind-use

Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2013-11-21 Thread Jeremy C. Reed
On Wed, 20 Nov 2013, /dev/rob0 wrote: > Chapter 6 is the comprehensive configuration reference. What I'd like > to see is more (and plain-language, consistent) hyperlinking. The > basic idea is that any named.conf setting could be found at an > anchor: > > Bv9ARM.ch06.html#that-setting Yes th

Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2013-11-21 Thread Jeremy C. Reed
On Thu, 21 Nov 2013, /dev/rob0 wrote: > The daunting part is that I'm not sure what this will do: > > some-named.conf-setting > > ... > See > > ... because at this point, it looks like the only anchors are in > section headers. Perhaps more code will have to be added to properly > deal with

Re: caps compiling error

2013-11-26 Thread Jeremy C. Reed
Please see https://kb.isc.org/article/AA-01060/0/Building-BIND-9.9.4-9.8.6-and-9.6-ESV-R10-on-RHEL-and-CentOS-with-libcap-dev-installed.html ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users ma

Re: BIND10 : how do I import zone files stored in mysql to BIND10 ?

2013-12-16 Thread Jeremy C. Reed
sc.org/docs/developers/cpp/dc/d2c/sqlite3__accessor_8cc_source.html Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: BIND10 : how do I import zone files stored in mysql to BIND10 ?

2013-12-16 Thread Jeremy C. Reed
ne.sqlite3"} Try: config show data_sources/classes/IN[0]/params to see where you should put your database file. > I will also try digging code meanwhile .. Have fun Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listin

Re: R: DNS with several ip adessess

2014-01-02 Thread Jeremy C. Reed
On Thu, 2 Jan 2014, wbr...@e1b.org wrote: > When were views added to BIND? We started using using multiple > servers in BIND 4, and I don't recall views being available back then, > but I didn't configure the servers, just maintained the zones. Views were introduced in BIND 9.0.0 (September 20

Re: GeoIP in 9.10 RC2

2014-04-30 Thread Jeremy C. Reed
> So the the IPv4 Country DB is recognized and loaded, but digs from US to > that server still result in queries from the ALL view, which is the last > view in the config file and the test View above is the first View in teh > config file. You may want to try the geoiplookup (provided by GeoIP sof

Re: GeoIP in 9.10 RC2

2014-04-30 Thread Jeremy C. Reed
On Wed, 30 Apr 2014, Ali Jawad wrote: > view "US" { > >        match-clients { US; }; For now please change to: match-clients { geoip country US; };___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind

Re: Issues in configuring Bind 9.10 in CentOS 6.3 with --open-ssl

2014-05-02 Thread Jeremy C. Reed
On Fri, 2 May 2014, Gaurav Kansal wrote: > checking for OpenSSL library... using OpenSSL from /usr/lib and /usr/include > > checking whether linking with OpenSSL works... no > > configure: error: Could not run test program using OpenSSL from > > /usr/lib and /usr/include. > > Please check the

Re: RRL active by default?

2014-05-02 Thread Jeremy C. Reed
On Thu, 1 May 2014, Lawrence K. Chen, P.Eng. wrote: > Does compiling in RRL mean its active, even without a rate-limit {} > control block? Only for the built-in Chaos "_bind" view (for id.server, authors.bind, hostname.bind, and version.bind). ___ Ple

RE: Issues in configuring Bind 9.10 in CentOS 6.3 with --open-ssl

2014-05-02 Thread Jeremy C. Reed
On Fri, 2 May 2014, Gaurav Kansal wrote: > Config.log doesn't showing any useful data to troubleshoot this. > configure:15338: checking for OpenSSL library > > configure:15436: error: "/usr/include/openssl//include/openssl/opensslv.h" > not found You looked at config.log after you did a differe

Re: RRL active by default?

2014-05-02 Thread Jeremy C. Reed
> On 05/02/14 09:23, Jeremy C. Reed wrote: > > Only for the built-in Chaos "_bind" view (for id.server, authors.bind, > > hostname.bind, and version.bind). On Fri, 2 May 2014, Lawrence K. Chen, P.Eng. wrote: > Awww...I found messages about version.bind. My work

Re: bin 9.10 verbose logging

2014-05-03 Thread Jeremy C. Reed
On Sat, 3 May 2014, Noel Butler wrote: > U, since upgrade 9.9.5 to 9.10 every request to the name server is > spewing copious amounts of debug type data (thankfully I only upgraded the > one server) > >   > >  named[23250]: received packet from 207.66.8.132#53 (no opt): ;; > ->>HEADER<<- opc

Re: AIX and 9.9.5 compiling

2014-05-09 Thread Jeremy C. Reed
Currently, some of the systems that we automatically build and run various tests on include: FreeBSD 4.11 i386 FreeBSD 6.3 i386 FreeBSD 8.4 i386 FreeBSD 10.0-CURRENT i386 Fedora 18 Linux 3.8.1-201.fc18.x86_64 x86_64 Fedora 19 Linux 3.11.6-200.fc19.x86_64 x86_64 HPUX B11.11 HPPA2.0w (HP 9000/800

Re: Error when using GeoIP

2014-07-01 Thread Jeremy C. Reed
> geoip-directory "/usr/share/GeoIP/GeoIP.dat"; Should be a directory. > > in zones > > > acl "US" { > >   geoip country US; > > }; > > > > view "US" { > >      match-clients { US; };  //Once I add this it throws the error below > *** > >      include "/etc/named.rfc1912.zones"; >

Re: Error when using GeoIP

2014-07-01 Thread Jeremy C. Reed
On Tue, 1 Jul 2014, Ali Jawad wrote: > [root@uk etc]# ls -lart /usr/share/GeoIP/  > > -rw-r--r--   1 root root 1206078 Jul  1 10:08 GeoIP.dat > > > > The output from the logs is  > > Jul  1 14:38:56 uk named[1795]: using "/usr/share/GeoIP" as GeoIP directory > > Jul  1 14:38:56 uk named[1795

Re: Cannot get "allow-query-on" to work

2014-07-02 Thread Jeremy C. Reed
> I am using Ubuntu 12.04.4, BIND 9.8.1-P1, and just added: > allow-query-on { 127.0.0.1; }; Please upgrade your BIND. There was a bug in allow-query-on that was fixed since 9.8.6rc2. Please note that currently allow-query-on is only used for "zone" configurations. Use allow-cache-on if restrict

Re: test bind before moving to production

2014-07-03 Thread Jeremy C. Reed
On Thu, 3 Jul 2014, brian wrote: > I'm new to bind. I want to be able to test the dns server on my local > machine before launching it by putting the domain names (ie example.com) in > my browser and browsing the site. > > > Both the dev and production machines are CentOS. I assume I'll need to

Re: both recursive-only BIND9 went deaf until rebooted

2014-08-13 Thread Jeremy C. Reed
On Wed, 13 Aug 2014, lcon...@go2france.com wrote: > fbsd 8.2 VM with BIND 9.9.5 > > fbsd 10.0-RELEASE VM with BIND 9.10.0-P2 > > the older machine had uptime of 400+ days, the new machine only a couple weeks > > 24 hour query logging shows several million queries/day > > At about the same time

Re: Runtime disable RRL

2014-08-19 Thread Jeremy C. Reed
to disable the code, but you can disable the rate limiting with: rate-limit { responses-per-second 0; }; If your tests involve builtin CHAOS, see https://lists.isc.org/pipermail/bind-users/2014-May/093107.html Jeremy C. Reed ISC ___ Plea

Re: no servers found

2014-08-21 Thread Jeremy C. Reed
In the virtual server, use dig @a.b.c.d with the IP address of the DNS servers you want to use to see if that works. If you are running named in that same virtual server, try dig @127.0.0.1. If that works, then just change your resolv.conf to point to only that nameserver 127.0.0.1 __

Re: no servers found

2014-08-21 Thread Jeremy C. Reed
On Thu, 21 Aug 2014, Adamiec, Lawrence wrote: > Using dig @My-NAME-SERVER works.  I am not running named on the virtual > server using dig @ 127.0.0.1 does not work. Okay. Then change your /etc/resolv.conf to contain just the "nameserver " and IP of that name server (and a couple others if you w

Re: geoip asnum matching

2014-08-21 Thread Jeremy C. Reed
On Thu, 21 Aug 2014, Dietrich Oberhausen wrote: > I've got an issue with bind 9.10 and GeoIP asnum based matching. > As far as I can tell I need to match not only the AS number but also > the org name? > > This works: > match-clients { geoip asnum "AS8767 M-net Telekommunikations GmbH, > Germ

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
Yes, I think is a make problem. I reported same issue a couple weeks ago. (Internal BUg #36993). To workaround, use gmake. We can provide a patch very quick. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this l

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
On Fri, 12 Sep 2014, Mathieu Arnold wrote: > Yes, you can't use bmake if you try to build the python bits, I had to > force gmake in the port: It looks to be a bug in the NetBSD bmake used by FreeBSD. I cannot find a bug report for it in FreeBSD. I opened one for NetBSD: http://gnats.netbsd.org/

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
On Fri, 12 Sep 2014, Jeremy C. Reed wrote: > It looks to be a bug in the NetBSD bmake used by FreeBSD. I cannot find > a bug report for it in FreeBSD. I opened one for NetBSD: > http://gnats.netbsd.org/49198x http://gnats.netbsd.org/49198 (My system types a random "x" on its

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
On Fri, 12 Sep 2014, Mark Andrews wrote: > Try collapsing the multiple .SUFFIXES into a single entry. That doesn't work (for me). ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Re: bind-9.10.0-P2 memory leak?

2014-09-12 Thread Jeremy C. Reed
On Tue, 9 Sep 2014, Thomas Schulz wrote: > What version did you upgrade from? I am seeing bind 9.9.5 and 9.9.6 > grow without any evidence that it will ever stop. See my mail to this > list with the subject "Re: Process size versus cache size." Mine is > growing slower than yours, but it is now up

Re: bind-9.10.0-P2 memory leak?

2014-09-12 Thread Jeremy C. Reed
> Can you copy and paste the "out of memory error" you are seeing? Is it > still growing? Does it appear to work? I see your other thread answers some. https://lists.isc.org/pipermail/bind-users/2014-July/093618.html ___ Please visit https://lists.isc.

Re: bind-9.10.0-P2 memory leak?

2014-10-13 Thread Jeremy C. Reed
On Mon, 13 Oct 2014, Thomas Schulz wrote: > I restarted bind 9.9.6 with a max-cache-size of 30M. We have 3 views. > The inital process size was 36 MB. The process grew to 184 MB. It grew > to 596 MB without the max-cache-size being set and was still growing > when I restarted it. BUT when I now d

Re: Dumping the statistics channel

2014-11-03 Thread Jeremy C. Reed
On Mon, 3 Nov 2014, Thomas Schulz wrote: > I have been asked to dump the statistics to help document a suspected > memory leak in named. When I look at the statistics with Firefox, I see > a nicely formatted set of statistics. If I then dump the statistics to > a file with wget and then use Firefo

Re: BIND9 Return different IP address based on subnet

2014-12-27 Thread Jeremy C. Reed
On Sat, 27 Dec 2014, Christian Kette wrote: > I have some questions. Q1: Why do I get the IP address "192.168.2.100" for > "DEV.home.lan" from both the 192.168.2.0/24 and the 192.168.10.0/24 network? The view that matches first is used. > #include "/etc/bind/named.conf.default-zones"; ... > Q2:

BIND DNSSEC Guide draft

2014-12-31 Thread Jeremy C. Reed
de/dnssec-guide.html http://users.isc.org/~jreed/dnssec-guide/dnssec-guide.pdf The docbook source for the guide is at GitHub: https://github.com/isc-projects/isc-dnssec-guide/ Happy New Year! Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/ma

Re: DNSSEC

2015-01-17 Thread Jeremy C. Reed
On Sat, 17 Jan 2015, John wrote: > is there a separate DNSSEC mailing list? You may use this bind-users list to discuss DNSSEC. There are other lists for DNSSEC managed outside of ISC and not specific to BIND, such as: Dnssec-deployment.org (but I cannot access their mailman webpage currently

Re: Finding authoritative server and last update

2015-02-03 Thread Jeremy C. Reed
On Tue, 3 Feb 2015, Robert Moskowitz wrote: > I am trying to find out which comcast server is authoritative for > > 4.254.253.50.in-addr.arpa > > and when the zone file for the ptr rr was last updated. > > I was told a week ago that the ptr would be updated, but I am still > not seeing any cha

Re: Finding authoritative server and last update

2015-02-03 Thread Jeremy C. Reed
By the way, it looks like the SOA MNAME has a misspelling typo in it. I wonder if that is on purpose to foil automated/unintelligent spammers. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users m

Re: compile and install from source

2015-03-30 Thread Jeremy C. Reed
On Sun, 29 Mar 2015, INVALID_ADDRESS wrote: > named_conf="/etc/namedb/named.conf" # Path to the configuration file ... > So I changed the path (in /etc/rc.conf) to /usr/local/sbin/named > > But now I get: > > $ /etc/rc.d/named start > Starting named. > /etc/rc.d/named: WARNING: failed to star

Re: zone not updating

2015-03-30 Thread Jeremy C. Reed
On Mon, 30 Mar 2015, Lucio Crusca wrote: > @ IN NS ns0.virtual-bit.com. > @ IN NS ns1.virtual-bit.com. ... > propagating, but still nothing changed. If you query the NS for the > www record, it replies with the new and correct IP address > (136.243.232.141), but if

Re: Native pkcs#11 and auto-dnssec feature

2015-04-08 Thread Jeremy C. Reed
> My question is about auto-dnssec feature that maintain zone by > internally signing RRs. How this feature will work without a PIN since > BIND needs access to private key when it needs to resign automatically > and i did't find a way to provide the PIN throught configuration files > ? Hi, D

Re: "#service named restart" fails with a weird message

2015-06-19 Thread Jeremy C. Reed
On Fri, 19 Jun 2015, Samad Agha wrote: > Error in named configuration: > /etc/named.conf:3: missing ';' before '}' Look on line 3 > /etc/named.conf:11: missing ';' before '}' Look on line 11 > options { > directory "/var/named"; >     allow-recursion {207.151.36.0/24; 206.117.117.

Re: make test fails without Net::DNS::Nameserver

2015-07-14 Thread Jeremy C. Reed
On Tue, 14 Jul 2015, Maria Iano wrote: > I don't see this mentioned anywhere else, although I'm suprised by that > so maybe I'm missing something. When I build bind-9.10.2-P2 I find > that "make test" fails for reclimit with "Couldn't start server ans2" if > I don't have Net::DNS::Nameserver insta

Re: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > '--enable-newstats' '--with-libxml2' '--enable-fullreport' 'CFLAGS=-O2 Unrelated to your problem, but the --enable-newstats configure switch is not used for BIND 9.10. > 1. Cannot seem to start named and it seems that it is looking for s

RE: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > I know it using rndc is a good practice but is there an option to > specify in named.conf to disable it? It is disabled by default because there is no complete command channel configuration in the first place, but this will make it so it d

RE: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > Thanks Jeremy > > > Logging section from named.conf > > logging { > channel "named-log" { > file "/usr/local/named-jail9.10.3P4/var/adm/named.log" > versions 3 size 30m; ... > category "general" { "named-

Re: Bind 9.11.0a1

2016-04-21 Thread Jeremy C. Reed
On Thu, 21 Apr 2016, ap...@yandex.ru wrote: > Would be great to hear smth about question #2. I've tried to use rndc > trace with various levels of debugging and still edns subnet is not > shown anywhere. > > 2) I have looked through sources and bind 9.11 guide, but have not > > found the way t

Re: Cannot get BIND logs to write to the correct file.

2016-05-02 Thread Jeremy C. Reed
ding to a new version of Red Hat Linux > as well as a new version of BIND on a different server. > > Any help is greatly appreciated! What am I doing wrong here? Hi Sean, Also use a "category" configuration. For example: category defaul

Re: Nsupdate usage scenario

2016-05-02 Thread Jeremy C. Reed
What about using a specific zone file just for the purpose of the single A record you want to maintain using dynamic updates? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-

Re: Nsupdate usage scenario

2016-05-02 Thread Jeremy C. Reed
Also for the generated master file, have a look at "masterfile-style full;" option. Have a look at the named-compilezone -j with -s full or -s relative so you can compare outputs. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to un

Re: RES: RHEL, Centos, Fedora rpm 9.10.4-P1

2016-06-22 Thread Jeremy C. Reed
On Wed, 22 Jun 2016, Leonardo Oliveira Ortiz wrote: > Someone had success to build it? I got make test errors... What was the error? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing l

Re: Questions on how to setup Reverse DNS in bind 9

2016-07-18 Thread Jeremy C. Reed
On Sun, 17 Jul 2016, Spork Schivago wrote: > So, in the /var/named directory, I create a file > called: 0.117.238.104.in-addr.arpa > > The contents of 0.117.238.104.in-addr.arpa are as follows: > $TTL 1D > @       IN SOA  ns1.jetbbs.com. spork.jetbbs.com. ( >                                      

Re: logging query results

2008-12-01 Thread Jeremy C. Reed
On Mon, 1 Dec 2008, wes wrote: > The result I'm looking for is "10.1.1.44" and this string does not appear in > any of the logs at all. Search for 10.in-addr.arpa. instead. ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailm

RE: Question about Subdomain Delegation

2008-12-01 Thread Jeremy C. Reed
nameserver at 146.145.231.234 doesn't know "lab" is delegated. nameserver at 146.145.231.234 doesn't know "ns2" Your ns1 and ns2 have conflicting information. nameserver at 72.44.181.38 can't be reached. ___ bind-users mailing list bind-users@lists.is

what versions of BIND and operating systems?

2008-12-19 Thread Jeremy C. Reed
OS X 10.1, 10.3.8 Jeremy C. Reed ISC Sales & Support Engineer ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: External Resolution

2008-12-24 Thread Jeremy C. Reed
On Wed, 24 Dec 2008, Linux Addict wrote: > Folks, I have BIND 9 running. For some reason, the external resolution is > not working. I can telnet to root servers on port 53. Recursion is on. What > are the other requiremnts for the server to reesolve the external records. > Please help!! Tell us m

Re: Using 2 CPUs with BIND

2008-12-29 Thread Jeremy C. Reed
On Mon, 29 Dec 2008, Mike Diggins wrote: > > > When I start BIND on my Solaris 10 SPARC dual CPU (V210) system 9.4.2-P2, > > > I don't get the message "using 2 CPUs", but that's what I want. I > > > compiled it with './configure --prefix=/usr/local/bind --enable-threads' > > > and start it with '/

Re: includes in zone files

2008-12-29 Thread Jeremy C. Reed
On Mon, 29 Dec 2008, Mike Zupan wrote: > Is there anyway in a zone file for a master to include another file for more > zone information? $INCLUDE filename See "Other Zone File Directives" in chapter 6 of the ARM. And read example in chapter 4 of the ARM. __

Re: Initial Setup of Master/Slave Bind servers

2008-12-29 Thread Jeremy C. Reed
one files on the slave so that updates are > replicated? No. Maybe check your logs on both servers to see if there are any complaints about this. Or provide us with real details and maybe we can help troubleshoot. Jeremy C. Reed ISC Sales & Support Engineer _

Re: Using 2 CPUs with BIND

2008-12-29 Thread Jeremy C. Reed
What is your syslogger configuration for /var/adm/messages, /var/log/named, and /var/log/named.info ? ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: openssl alert when 9.8i installed?

2009-01-02 Thread Jeremy C. Reed
and ran "make" and BIND successfully compiled...just wondering if there's a > problem or not? Both. It probably still works, but the warning should encourage you to use the version with security fixes. Jeremy C. Reed ISC Sales & Support Engineer ___

Re: installing 9.6 on freebsd7 configure problems

2009-01-02 Thread Jeremy C. Reed
; Jan 2 15:57:48 ns1 named[1096]: exiting (due to fatal error) > > shouldn't the "open" statement be pointing at "/etc/namedb/named.conf" and if > so, what did I do wrong? Or do I have to manually edit a path somewhere? Jeremy C. Reed ISC Sales & Support E

Re: Was BIND 9.4.3 announced on bind-announce / bind-users ?

2009-01-02 Thread Jeremy C. Reed
eived the usual notification from ISC. Was this just me, or was there > a more general problem? (This was shortly after the grand ISC mailing > list reorganisation on 14 November, after all ...) I also don't see the announcement(s). I have reported this internally and we will make sure this is

Re: statistics-channels No such URL

2009-01-03 Thread Jeremy C. Reed
On Sat, 3 Jan 2009, Jonathan Petersson wrote: > So I did find the reason: > Jan 3 09:45:04 localhost named[5038]: statistics-channels specified > but not effective due to missing XML library > > anything besides: > [r...@localhost bind-9.6.0]# rpm -qa | grep libxml2 > libxml2-2.7.2-2.fc10.i386 >

Re: Fresh (non cached) dig

2009-01-05 Thread Jeremy C. Reed
the AA bit is set in the reply. > > Even quite old versions of BIND will not set the AA bit in the response > > if the answer is from the cache, in this case. > > Thanks for this Chris. I never knew that. And Todd, that is just what the > doctor ordered! Do some tests with da

Re: Ever growing jnl files

2009-01-07 Thread Jeremy C. Reed
On Wed, 7 Jan 2009, Mike Eggleston wrote: > On Wed, 07 Jan 2009, Nicholas F Miller might have said: > > > We have a few dynamic zones that are provisioned using Addhost. When > > addhost adds records to the zone every night it will run "nsupdate < > > update.file". The update.file will contai

Re: Named goes deaf

2009-01-09 Thread Jeremy C. Reed
On Wed, 7 Jan 2009, Scott Haneda wrote: > Hello, running BIND 9.4.2-P2 on OS X 10.5, this is just what comes with OS X Consider upgrading to 9.4.3-P1. It has some improvements with port allocation that may help you. ___ bind-users mailing list bind-use

Re: [openSuSE 11.1] the working directory is not writable

2009-01-12 Thread Jeremy C. Reed
On Fri, 9 Jan 2009, Lothar Behrens wrote: > Jan 9 11:55:53 vmhost named[11970]: starting BIND 9.5.0-P2 -t /var/ > lib/named -u named Chrooting to /var/lib/named > Jan 9 11:55:53 vmhost named[11970]: the working directory is not > writable > > My working directory is /var/lib/named and the per

Re: Current named statistics format documentation

2009-01-13 Thread Jeremy C. Reed
See http://ftp.isc.org/www/bind/arm95/Bv9ARM.ch06.html#id2593348 (Sorry that is for a different version of BIND, but it does cover more statistics info.) If you need any specific clarifications, please let us know. ___ bind-users mailing list bind-user

Re: SERVFAIL issues

2009-01-15 Thread Jeremy C. Reed
> Is this intermittent SERVFAIL issue resolved in 9.5.1-P1? 9.5.1 has many improvements that solve various SERVFAIL issues seen in the 9.5.0-P1/P2 code and includes /dev/poll, kqueue, or epoll on supported systems. ___ bind-users mailing list bind-user

  1   2   >