Re: Answers for www.dnssec-failed.org with dnssec-validation auto;

2024-04-17 Thread Ondřej Surý
Let me guess - you are running on RHEL (without SHA-1 support) and dnssec-failed.org is signed with RSA/SHA-1…--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.On 17. 4. 2024, at 19:02, John

Re: named 100% utilization

2024-04-30 Thread Ondřej Surý
you can reproduce the issue with latest 9.18 version, you'll need to install debug symbols and it's possible to use `perf record` to capture the data where named spends time, but even simple eu-stack -p can give you hints if you take couple snapshots. Cheers, -- Ondřej Surý (He/Him

Re: RFC8482: Implementation through HINFO record

2024-05-20 Thread Ondřej Surý
y. Ondřej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 20. 5. 2024, at 16:03, Amaury Van Pevenaeyge > wrote: > > Hello everyone, > > How is it p

Re: named fails to start with bind-9.18.0

2024-05-20 Thread Ondřej Surý
ion about what you are actually doing. This old essay is still true: https://www.chiark.greenend.org.uk/~sgtatham/bugs.html Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. &

Re: Make dig and nslookup DNSSEC aware?

2024-05-22 Thread Ondřej Surý
d forget that nslookup ever existed, just used dig (or delv). Ondřej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman/listinfo/bind-users t

Re: Counters for DNS transports?

2024-05-22 Thread Ondřej Surý
Hi Havard, this has been planned, but unfortunately other stuff got into the way. It is still on our roadmap though. Ondřej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours

Re: Building bind 9.19.24 on Openwrt w/ MUSL

2024-06-02 Thread Ondřej Surý
Hi Philip, we'll need more. Ideally fill an issue, follow the bug template and attach config.log as a bare minimum. -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 1.

Re: MDLZ user activation

2024-06-06 Thread Ondřej Surý
Hi Nick, I did put the user who sent the message on the moderation queue. Ondřej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman

Re: Question about ISC BIND COPR repositories for 9.16->9.18 ESV transition

2024-06-17 Thread Ondřej Surý
because of how the repositories are structured or named?The repositories are provided for the convenience and you can still build your own binaries or packages if those are not convenient for you.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel

Re: Question about ISC BIND COPR repositories for 9.16->9.18 ESV transition

2024-06-18 Thread Ondřej Surý
is released, and we'll probably stick with Michał's plan to do the bump around 9.20.1 or 9.20.2 release, probably mid 9.20.1-9.20.2 release cycle as you suggested. This way the upgrade will be phased as you are suggesting below. Thanks for the feedback. Ondrej -- Ondřej Surý (He/

Re: Debian download source on ISC website

2024-06-19 Thread Ondřej Surý
. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 19. 6. 2024, at 9:19, Dominic Preston wrote: > > Hello, > > When browsing for Debian download sou

Re: can I provide invalid HTTPS values for testing?

2024-06-19 Thread Ondřej Surý
, -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 20. 6. 2024, at 3:40, Stephen Farrell wrote: > >  > Hiya, > > Apologies if this is a repeat, I spent a bit of

Re: can I provide invalid HTTPS values for testing?

2024-06-20 Thread Ondřej Surý
eduroam at TCD didn’t work for me last week ;))). Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 20. 6. 2024, at 15:29, Stephen Farrell wrote: > >  &

Re: Debian download source on ISC website

2024-06-21 Thread Ondřej Surý
The authoritative source is bind.debian.net that can be redirected. But the primary reason is that I already have the infrastructure ready and I also maintain BIND 9 packages directly in Debian, so the contents mirror what ends up in Debian. Ondrej -- Ondřej Surý — ISC (He/Him) My working

Debian 10 Buster LTS end-of-life

2024-07-01 Thread Ondřej Surý
Hi folks, as some of you might be using the Debian repositories, the Debian 10 Buster reached end-of-life by the end of June 2024 and the BIND repositories for Debian 10 will be also removed. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be

Re: bind 9.18 few system tests failing

2024-07-03 Thread Ondřej Surý
Hi, I find it hard to believe that IBM can't test it themselves on any Linux really, but yes, all system tests pass correctly on all supported platforms. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligat

Re: netstat showing multiple lines for each listening socket

2024-07-08 Thread Ondřej Surý
That's correct. Since BIND 9.16, `named` binds to individual addresses instead of "any" because it needs to send responses back from the same address and it's just easier this way. Cheers, -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may

Re: zone_journal_compact: could not get zone size: not found

2024-07-08 Thread Ondřej Surý
You need to ask FreeIPA people and your vendor (but my guess is that the dyndb plugin provided by RH doesn’t provide this method).--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.On 8. 7

Re: zone_journal_compact: could not get zone size: not found

2024-07-09 Thread Ondřej Surý
t. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 9. 7. 2024, at 9:34, Kees Bakker wrote: > > Indeed the LDAP plugin does not provide the getsize m

Re: Accepting TCP connection failed: socket is not connected

2024-07-11 Thread Ondřej Surý
It means what it says - the networking layer reports that the TCP socket is no longer connected at the time named is accepting the connection. It means that the client gave up between the 3-way handshake completion and accepting the connection. Ondrej -- Ondřej Surý — ISC (He/Him) My working

Re: Accepting TCP connection failed: socket is not connected

2024-07-12 Thread Ondřej Surý
There’s no issue. The message is already logged at INFO level. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 12. 7. 2024, at 10:07, sami.ra...@sofrecom.com wr

Re: New BIND releases are available: 9.18.28, 9.20.0

2024-07-23 Thread Ondřej Surý
Hi Adam, this was discussed a month ago: https://lists.isc.org/pipermail/bind-users/2024-June/108638.html and we were basically asked to make the bumps in the repositories to not follow the releases. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be

Re: New BIND releases are available: 9.18.28, 9.20.0

2024-07-24 Thread Ondřej Surý
max-types-per-name for their particular environment. Cheers, Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 24. 7. 2024, at 4:18, James Stegemeyer wr

Re: named hangs when trying to sign a large zone after upgrading to 9.18.28

2024-07-25 Thread Ondřej Surý
ossible to debug the issue. I would suggest you fill an issue in our GitLab (gitlab.isc.org <http://gitlab.isc.org/>) and we can continue there. Also please include the information about previous BIND 9 version. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your work

Removal notice force BIND 9.21+: OpenSSL Engines

2024-08-06 Thread Ondřej Surý
s already present in BIND 9.20 and it is the preferred way how to interact with PKCS#11 Hardware Security Modules. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Vi

Re: Confirm BIND is correctly validating dmdc.osd.mil

2024-08-09 Thread Ondřej Surý
This could be a result of KeyTrap mitigations.The number of DS records is weird, but as long as there’s a valid path from root and no conflicting keytags, this looks fine to me.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated

Re: encountering "too many records" loading authoritative zone even when AXFR report shows nothing exceeding max-records-per-type

2024-08-13 Thread Ondřej Surý
9. Either BIND 9.18.28 or BIND 9.20.0 - both are freely available from our site. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 13. 8. 2024, at 13:18, Irwin T

Re: Problems compiling BIND 9.18.28 on Solaris 11.4

2024-08-14 Thread Ondřej Surý
libssl.so/> (development version) is not supported as it is impossible to get right when mixing libraries from different directories. I would suggest uninstalling the system development OpenSSL libraries (keeping just the shared libs) and trying again. Ondrej -- Ondřej Surý (He/Him) ond...

Re: I want to know why I suddenly can't resolve names.

2024-08-18 Thread Ondřej Surý
Since you are asking for a cause.The cause is that you failed to follow operational advice and kept using DLV after it has been discontinued. This is entirely on you.ISC is keeping dlv.isc.org operational only as a courtesy, and there is absolutely no SLA.Ondrej--Ondřej Surý — ISC (He/Him)My

Re: I want to know why I suddenly can't resolve names.

2024-08-18 Thread Ondřej Surý
Additionally, you fail to run supported version of BIND 9.Support for DLV had been removed from BIND 9.16.0 and even BIND 9.16 had reached end-of-life as of this year (after four and something years of support).Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be

Re: I want to know why I suddenly can't resolve names.

2024-08-18 Thread Ondřej Surý
Ok, let me state that clearly again. There is no guarantee that dlv.isc.org will be operational in the next second, next minute, next day, next month or next year. Stop using it right now, we are not going to send any notices because you failed to act. Ondrej -- Ondřej Surý — ISC (He/Him) My

Removal notice: Response Policy Server (BIND 9.21+)

2024-08-20 Thread Ondřej Surý
upport for DNSRPS/FastRPZ will be deprecated as of BIND 9.20 and removed in BIND 9.21/9.22. 1. Since then Farsight Security has been acquired by DomainTools. 2. https://bind9.readthedocs.io/en/latest/reference.html#namedconf-statement-dnsrps-enable. Cheers, -- Ondřej Surý (He/Him) ond...@isc.org

Re: Removal notice: Response Policy Server (BIND 9.21+)

2024-08-21 Thread Ondřej Surý
everyone. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 21. 8. 2024, at 9:26, Paul Vixie wrote: > >  > It worked with any policy source not just Farsight. Ho

Upcoming version change in RPM and DEB repositories - 2024-08-28

2024-08-21 Thread Ondřej Surý
' repository will be upgrade from BIND 9.20 branch (9.20.1) to BIND 9.21 branch (9.21.0) Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists

Re: 9.18 horrendous

2024-08-23 Thread Ondřej Surý
We welcome any bug reports, but such language is not welcome here. The mailing list is not meant for insulting developers. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours

Re: 9.18 horrendous

2024-08-23 Thread Ondřej Surý
the list and banned. I would rather spent my energy on the users who treat other with respect than work around someone’s “anger”. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working ho

Reminder: Rules of this list

2024-08-23 Thread Ondřej Surý
ble for others to help you. — cut here — If you actively participate in this mailing list we expect you to read, understand and adhere to these rules. Thank you, Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to rep

Enough is enough (Re: 9.18 horrendous)

2024-08-24 Thread Ondřej Surý
”) to the personal addresses you don’t get any redemption. Cool off, apologize, and we can start afresh. I’ve recently unbanned someone who took that path. Have a nice weekend, Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel

Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
container can read the configuration and zone files. NOTES: - replace 9.20 with 9.18 for the Extended Support Version, use 9.21 for the development version - expose port 853 for DoT with ephemeral certificate - expose port 443 for DoH with ephemeral certificate on /dns-query Ondrej -- Ondřej Surý (He/Him

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
Sure, it’s not secret: https://gitlab.isc.org/isc-projects/bind9-docker Branches with history… Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27. 8. 2024, at 14

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
But I think you are right. The default logging goes to the syslog and there's no syslog in the container. I'm thinking about appending -L /var/log/bind/default.log to the CMD part of the docker (so it can be easily overridden). Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
> On 27. 8. 2024, at 18:47, Ondřej Surý wrote: > > But I think you are right. The default logging goes to the syslog and there's > no syslog > in the container. I'm thinking about appending -L /var/log/bind/default.log > to the CMD > part of the docker (so it c

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
ut I get it - the base alpine:latest is only 3 MB, that's quite a difference. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27. 8. 2024, at 19:38, Peter DeVries wrote: > > For what it's worth this is how we build our dockers, with a

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Ondřej Surý
into this in the future, but I feel this is good enough for *now*. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27. 8. 2024, at 20:12, Marc wrote: > > I d

Re: Upcoming version change in RPM and DEB repositories - 2024-08-28

2024-08-28 Thread Ondřej Surý
applies to both DEB and RPM repositories. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 21. 8. 2024, at 17:49, Ondřej Surý wrote: > > Hi, > >

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-09-02 Thread Ondřej Surý
ut if you throw the symbols away, any coredump will become useless. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman/listinfo/bind

Re: Sporadic Timeouts after upgrading to bind9.20

2024-09-04 Thread Ondřej Surý
Klaus, is that recursive or authoritative? Anything unusual like RPZ or catz? Try snapshoting the call stack with eu-stack and save the one when the timeout happens. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to

Re: Question about parameter settings query-source-v6 address { none; };

2024-09-05 Thread Ondřej Surý
Hi Klaus, this exact configuration is described in the KB: https://kb.isc.org/v1/docs/en/aa-00206 But my recommendation is actually to use a dual-stack proxy in front of `named -4` and use the PROXYv2 protocol to interact with named. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and

Re: bind918 malfunction?

2024-09-05 Thread Ondřej Surý
It’s impossible to answer your question as you haven’t provided absolutely no information about your problem. Perhaps if you provide detailed information about nature of the problem, your DNS configuration, and your network configuration, we might be able to help you. Ondrej -- Ondřej Surý

Re: bind918 malfunction?

2024-09-05 Thread Ondřej Surý
I’m on my phone, so this is a long shot, but you can try disabling the qname minimization. -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 5. 9. 2024, at 19:45, Peter wr

Re: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Ondřej Surý
Yup, you need dbgsym packages? https://ubuntu.com/server/docs/debug-symbol-packages https://wiki.ubuntu.com/DebuggingProgramCrash#Installing_dbgsym_packages_from_a_PPA -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply

Re: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Ondřej Surý
Yes, just replace RPZ with “processing the incoming transfers”.Sounds like 12 should work in your case.We should have a fix ready in couple of weeks.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal

Re: bind918 malfunction?

2024-09-06 Thread Ondřej Surý
Try using running `named -d 9 (plus other existing args)` to see why there are 31+ queries. There must be something wonky going on. -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours

Re: bind918 malfunction?

2024-09-06 Thread Ondřej Surý
Now the question remains - why? I don’t really see a reason for this behavior from where I tested it, so what is the traffic between your recursor and the Internet during the time this happens? Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different

Re: bind918 malfunction?

2024-09-06 Thread Ondřej Surý
before) would help in your case? I am guessing the resolver is being used for a limited set of clients and the chance of this specific abuse is quite low. https://bind9.readthedocs.io/en/v9.18.29/notes.html#notes-for-bind-9-18-29 Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your

Re: bind918 malfunction?

2024-09-07 Thread Ondřej Surý
. It would help us to look how we can change the limits in a way that it doesn’t hurt legitimate traffic, but limit the impact of malicious actors. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your

Re: Lookup failures

2024-09-10 Thread Ondřej Surý
snippet you posted? Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 11. 9. 2024, at 3:21, Steven Shockley wrote: > > Hi, I'm running BIND 9.18

Re: ISC-BON 9.20.1 - Almalinux 9

2024-09-12 Thread Ondřej Surý
Can you provide logs that you actually installed isc-bind and not just isc-bind-bind package? Because what you are reporting sounds exactly like this: https://lists.isc.org/pipermail/bind-users/2022-June/106321.html Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours

Re: ISC-BON 9.20.1 - Almalinux 9

2024-09-12 Thread Ondřej Surý
Then I guess you have to look why the selinux policy hasn’t been installed.My first instinct would be to purge isc-bind package and re-install it again.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your

Re: configure error for bind-9.20.1

2024-09-16 Thread Ondřej Surý
you sent is: well, it's broken for you. Cheers, -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 16. 9. 2024, at 13:35, Sakuma, Koshiro wrote: > > He

Re: configure error for bind-9.20.1

2024-09-16 Thread Ondřej Surý
/configure invocation is wrong, LIBURCU_CFLAGS and LIBURCU_LIBS need to be correct CFLAGS and LIBS, but you should be setting PKG_CONFIG_PATH instead. However, my recommendation would be to use the prepackaged RPMs for RHEL 9 provided by ISC. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My wo

Re: Is -DISC_SOCKET_MAXEVENTS still needed in BIND 9.16?

2020-02-20 Thread Ondřej Surý
#endif /* TUNE_LARGE */ #endif /* ifndef ISC_SOCKET_MAXEVENTS */ Ondrej -- Ondřej Surý ond...@isc.org > On 20 Feb 2020, at 09:02, Anand Buddhdev wrote: > > Hi BIND developers, > > We build our own RPMs of BIND, and ever since the 9.9 builds, we have > been setting -DISC_SO

Re: CDS-deletion record "CDS 0 0 0 00" is failing with bind-9.14.9 and bind-9.14.8

2020-02-20 Thread Ondřej Surý
in a form of merge request in our gitlab instance (you need to ask for a permission to fork the project) or as a patch. This seems to be fairly trivial bug that might be a good start if anybody wants to help fix bugs in BIND 9. Cheers, Ondrej -- Ondřej Surý ond...@isc.org __

Re: Bind 9.11.13 - inline re-signing stops

2020-02-20 Thread Ondřej Surý
1. https://www.systutorials.com/docs/linux/man/1-gcore/ 2. https://kb.isc.org/docs/aa-00340 Ondrej -- Ondřej Surý ond...@isc.org > On 19 Feb 2020, at 08:36, Matthew Richardson > wrote: > > Dear Ondrej, > > I would be delighted to assist with a core dump. > > Howeve

Re: Advice on balancing web traffic using geoip ACls

2020-02-24 Thread Ondřej Surý
As far as we know the bug is present in all current BIND releases. We are still investigating the issue, but things are looking positive thanks to Vikor Dukhovni’s help with debugging his coredump. Ondřej -- Ondřej Surý — ISC > On 24 Feb 2020, at 11:08, Jukka Pakkanen wrote: > > 

Re: bind 9.16 vs. 9.14 tcp client connections

2020-03-05 Thread Ondřej Surý
/-/merge_requests/3163.patch ISC will be issuing a proper Operational Notification later this week and the fix will be included in BIND 9.16.1 due in March. Sorry for the inconvenience. Thanks, Ondrej -- Ondřej Surý ond...@isc.org > On 5 Mar 2020, at 10:11, Arsen STASIC wrote: > > Hi, > >

Re: bind-users Digest, Vol 3393, Issue 1

2020-03-16 Thread Ondřej Surý
documentation that generally applies to most Linux distros. Ondřej -- Ondřej Surý — ISC > On 17 Mar 2020, at 06:15, ShubhamGoyal wrote: > >  > Dear sir, >I tried whatever you said > but it is not working. > please give me more solutions > > >

Re: BIND 9.16.1 on CentOS 6

2020-03-18 Thread Ondřej Surý
Hi Anand, yes, it is. The broken code was introduced in the glibc 2.26, and generally RedHat/CentOS/Fedora/Debian libc6 already has the required patches. Ubuntu 18.04 (and derivatives) is the only major Linux distribution that doesn’t have the patch yet. Ondrej -- Ondřej Surý ond...@isc.org

Re: New releases of BIND are available: 9.11.17, 9.16.1, and 9.17.0

2020-03-23 Thread Ondřej Surý
Oh, right. I was hoping Bionic would have a fix by the time we release new BIND 9. The fixed package should be building right now. Ondrej -- Ondřej Surý ond...@isc.org > On 23 Mar 2020, at 11:47, FUSTE Emmanuel > wrote: > > Hello, > > 9.16.1 had been pushed into ISC sta

Re: New releases of BIND are available: 9.11.17, 9.16.1, and 9.17.0

2020-03-23 Thread Ondřej Surý
Hi Emmanuel, I made a mistake in the package, so bind9 (1:9.16.1-2+ubuntu18.04.1+isc+3) would be the correct version to use on Ubuntu bionic. If you experience any reproducible locks and crashes, we would be interested in having tcpdump that causes the lockup. Thanks, Ondrej -- Ondřej Surý ond

Re: Compile error Bind 9.16.1 on MacOS 10.14.6

2020-03-24 Thread Ondřej Surý
Hi Larry, it seems like your macOS SDK is incomplete or something like this. Both clock_gettime() and CLOCK_REALTIME are available since Mac OSX 10.12. Please make sure you have up-to-date Xcode and matching Command Line Utils for Xcode. Ondrej -- Ondřej Surý ond...@isc.org > On 24 Mar 2

Re: Machine friendly alternative to nsupdate

2020-04-01 Thread Ondřej Surý
I would recommend dnspython as a start. The API is very non-Python, but once you get hang of it, it’s not that bad. Ondrej -- Ondřej Surý ond...@isc.org > On 1 Apr 2020, at 15:21, Petr Bena wrote: > > like a "proper DNS library" you talk about, is there any such a thin

Re: DNSSEC - many doubts

2020-04-02 Thread Ondřej Surý
> On 2 Apr 2020, at 17:58, Warren Kumari wrote: > > If you are running an older machine and older kernel, the > /dev/random source is blocking Then just use /dev/urandom, both random and urandom are CSPRNG. Ondrej -- Ondřej Surý ond...@isc.org signature.asc Description: Message

Re: checkzone from stdin?

2020-04-08 Thread Ondřej Surý
to 9.16 branch since the codebases don’t differ much yet. Ondrej -- Ondřej Surý — ISC > On 8 Apr 2020, at 20:58, Matthew Pounsett wrote: > >  > > It looks to me like named-checkzone isn't able to read a zone file from > stdin. > > % cat example.com.db | named-c

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Ondřej Surý
e systemd unit [GL #1193] -- Ondřej Surý Wed, 28 Aug 2019 21:35:44 +0200 $ cat named.service [Unit] Description=BIND Domain Name Server Documentation=man:named(8) After=network.target Wants=nss-lookup.target Before=nss-lookup.target [Service] EnvironmentFile=-/etc/default/named ExecStart=/usr

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Ondřej Surý
`. Also it is the name used by RPM based systems and Arch Linux and Gentoo, so it was also made to make BIND 9 packages in Debian/Ubuntu more unified with rest of the Linux world. Ondrej -- Ondřej Surý ond...@isc.org > On 15 Apr 2020, at 08:51, Klaus Darilion wrote: > > Hello! > &

Re: bind v9.16.2 build, inconsistent GeoIP2 configuration options usage ?

2020-04-15 Thread Ondřej Surý
Hi, you are right this is a bit confusing, but you need to specify both: --enable-geoip (as the feature independent of used libraries) --with-maxmindsb (where to find the libraries) Ondrej -- Ondřej Surý — ISC > On 15 Apr 2020, at 22:07, PGNet Dev wrote: > > cosmetic con

Re: bind 9.16.2 on centos6

2020-04-19 Thread Ondřej Surý
upgrades now. Ondřej -- Ondřej Surý — ISC > On 18 Apr 2020, at 22:45, Carl Byington via bind-users > wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Centos6, although old, is still supported, so it would be nice to get > 9.16.2 running on that. This is my f

Re: Bind9 shared cache

2020-04-19 Thread Ondřej Surý
help with bootstrapping, but once you reach a state where most of the answers are already in the cache there’s no or negative benefit from it. I believe that in most scenarios the increased complexity in not worth the benefit gained. Ondrej -- Ondřej Surý — ISC > On 19 Apr 2020, at 12

[dev] Change in the build system - please test

2020-04-21 Thread Ondřej Surý
4 If there’s an issue you found and it’s small, try to look at the list of existing issues and add it if it fits, or just add a comment on the issue #4. If the problem is reasonable big and contained, feel free to open new issue for it (and probably link it in the comment in issue #4). Thank you,

Re: NAT and Question Section Mismatch

2020-04-21 Thread Ondřej Surý
inspect` that might be at fault. Ondrej -- Ondřej Surý ond...@isc.org > On 21 Apr 2020, at 21:14, John Wiles wrote: > > The only ip inspect lines that I could find in the current config are: > > ip inspect dns-timeout 7200 > ip inspect name CCP_HIGH dns > > John >

Re: Cannot build on macOS 10.15 (Catalina)

2020-04-28 Thread Ondřej Surý
runtime problem you need to configure dynamic linker to find the libuv library. (Or use rpath linker option.) Actually both problems stems from the fact that you installed libuv into nonstandard location. I would suggest to use homebrew or macports to install the dependencies. Ondrej -- Ondřej

Re: Cannot build on macOS 10.15 (Catalina)

2020-04-28 Thread Ondřej Surý
t; ever work well.) On Linux, just put the path to /etc/ld.so.conf.d/local.conf and that should do the trick. I don’t know how to configure the dynamic linker on macOS. Ondrej -- Ondřej Surý ond...@isc.org signature.asc Description: Message signed with OpenPGP _

Re: Cannot build on macOS 10.15 (Catalina)

2020-04-28 Thread Ondřej Surý
LIBUV_LIBS="-L$/dependencies/libuv/lib“ JFTR this part of the line is wrong as it actually doesn’t contain the library itself (just LDFLAGS). You should really use the pkgconfig. Ondrej -- Ondřej Surý ond...@isc.org > On 28 Apr 2020, at 19:36, Eddy Hahn wrote: > >

Re: Cannot build on macOS 10.15 (Catalina)

2020-04-28 Thread Ondřej Surý
ersions of libxml2 and zlib) Ondrej -- Ondřej Surý ond...@isc.org > On 28 Apr 2020, at 22:12, Eddy Hahn wrote: > > > OK. Before I did not give you the full picture because I did not want to be > to verbose :-) > > It should have been > > export SERVERPLUS_DI

Re: How to define a name with an empty RRset?

2020-04-29 Thread Ondřej Surý
Hi, to create a empty non-terminal (ENT) you should do: non-empty.an-empty-name.example.com. IN TXT Ondrej -- Ondřej Surý ond...@isc.org > On 29 Apr 2020, at 12:22, Alessandro Vesely wrote: > > Hi all, > > the doc says each node has a set of resource information, which may

Transparency Report: Code of Conduct

2020-05-04 Thread Ondřej Surý
might not be the best way to de-escalate the conflict. Thank you for keeping this place civil, Ondrej -- Ondřej Surý — ISC___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users

Re: How to disable recursion on ONE domain? (Bind-9.11.14)

2020-05-15 Thread Ondřej Surý
Hi Chris, when your vpn comes up, you need to issue: rndc flushtree command to the BIND 9 instance. Ondrej -- Ondřej Surý ond...@isc.org > On 15 May 2020, at 14:16, Chris Palmer via bind-users > wrote: > > There is much discussion about recursion but I can't find anythin

Re: How to disable recursion on ONE domain? (Bind-9.11.14)

2020-05-15 Thread Ondřej Surý
rver-names { "192.168.1.1"; }; }; and named -g reports: 15-May-2020 15:25:00.015 network unreachable resolving '192.168.1.1/A/IN': 2001:503:c27::2:30#53 15-May-2020 15:25:00.015 network unreachable resolving '192.168.1.1//IN': 2001:503:c27::2:30#53 Chee

Re: How to disable recursion on ONE domain? (Bind-9.11.14)

2020-05-15 Thread Ondřej Surý
differently when there’s already cached content? I suggest you run test BIND instance with -d 99 to see what’s happening. Ondřej -- Ondřej Surý — ISC > On 15 May 2020, at 18:22, Chris Palmer wrote: > > Hi Ondřej > > At first glance your suggestion looked like what I had done.

Re: nlabels == name->labels

2020-05-18 Thread Ondřej Surý
Unfortunately, we still need usable coredump with debugging symbols (the symbols could be external) Just a staring into the code hasn’t brought anything fruitful, unfortunately, and believe me, we tried. Ondrej -- Ondřej Surý — ISC > On 18 May 2020, at 21:27, Kevan Benson wr

Re: install issue with bionic packaging -- bind9/bionic 1:9.16.3-1+ubuntu18.04.1+isc+2

2020-05-20 Thread Ondřej Surý
rts to your apt sources.list to solve the missing dependency. Ondrej -- Ondřej Surý ond...@isc.org > On 20 May 2020, at 12:32, Marcel de Riedmatten wrote: > > Hi all > > Can't seems to find a better place to voice an issue with the > installation of the latest packagin

Re: install issue with bionic packaging -- bind9/bionic 1:9.16.3-1+ubuntu18.04.1+isc+2

2020-05-20 Thread Ondřej Surý
Hi Marcel, I think I figured it out how to build without any additional extra dependencies, so the next update of the bind9 package for Ubuntu will not require to have -backports enabled. Thanks for the valuable feedback. Ondrej -- Ondřej Surý ond...@isc.org > On 20 May 2020, at 13:29, Mar

Re: Upgrade from 9.14 to 9.16 - transfer-source with low source port no longer works.

2020-05-26 Thread Ondřej Surý
patch for reserved port") on some of them. There are > currently no plans to make such a combination of settings work again. Ondrej -- Ondřej Surý ond...@isc.org > On 26 May 2020, at 11:38, Ingeborg Hellemo wrote: > > FreeBSD 11.3-RELEASE-p3 > > This morning I upgraded

Re: Upgrading from BIND 9.14.9 to 9.16.3

2020-05-27 Thread Ondřej Surý
rary with a focus on asynchronous I/O. If that doesn’t work, you really need to look into config.log, it has all or most of the information needed to properly debug the issue. Ondrej -- Ondřej Surý ond...@isc.org > On 27 May 2020, at 17:57, DeCaro, James John (Jim) CIV DISA FE (USA) via > bind-user

Re: [Non-DoD Source] Re: Upgrading from BIND 9.14.9 to 9.16.3

2020-05-27 Thread Ondřej Surý
Jim, you need to read up on how to setup the system dynamic linker to add extra directories with libraries. Searching for “library path Solaris” shows this as one of the first links: https://docs.oracle.com/cd/E19205-01/819-5262/aeude/index.html Ondrej -- Ondřej Surý — ISC > On 27 May 2

Re: automating DS Record submit to parent with 'new' kasp/dnssec-policy support in bind?

2020-05-27 Thread Ondřej Surý
Please submit a feature request to our GitLab instance. I can’t guarantee that we will get to it in the timeframe you need, but the mails tend to get lost. Ondrej -- Ondřej Surý — ISC > On 27 May 2020, at 19:35, PGNet Dev wrote: > > On 5/26/20 4:50 PM, Mark Andrews wrote: >> T

Re: [Non-DoD Source] Re: Upgrading from BIND 9.14.9 to 9.16.3

2020-05-28 Thread Ondřej Surý
Jim, I would like to point out that ISC does provide a commercial support on BIND 9 as a way to provide funding to develop BIND 9 as open source software. Please let me know if you are interested in hearing more and I can connect you to the sales team. Cheers, Ondrej -- Ondřej Surý — ISC

Re: nsupdate - adding large/split TXT record (2048 bit DKIM key)

2020-06-01 Thread Ondřej Surý
I think it’s reasonable for nsupdate to do the chunking on itself. Patches are always welcome, but if you can start by creating issue for us, it would be very much welcome. I can’t offer you any timeframe, but at least it won’t get lost. Ondrej -- Ondřej Surý ond...@isc.org > On 1 Jun 2020,

<    1   2   3   4   5   6   7   >