update-policy wildcard grant

2020-04-01 Thread Jim Popovitch via bind-users
Hello! I started on #bind, moved on to the ARM, and now I am here. Here is what I want: update-policy {grant webserver-tsig-key wildcard _acme-challenge.* TXT;}; This is what I get: ~$ named-checkconf /etc/bind/named.conf:73: '_acme-challenge.*' is not a wildcard What

Re: Localhost view is not working for me SOLVED!

2020-04-01 Thread Marc Chamberlin via bind-users
ing and see what source and destination your queries > are using.  Make fake queries to unique names just to be sure which > queries you are looking at. > That's the best that I can suggest. > > -- > Bob Harold > > > On Mon, Mar 30, 2020 at 1:07 PM Marc Chamberlin via bind-use

Re: update-policy wildcard grant

2020-04-01 Thread Jim Popovitch via bind-users
On Thu, 2020-04-02 at 09:27 +1100, Mark Andrews wrote: > > On 2 Apr 2020, at 06:53, Jim Popovitch via bind-users < > > bind-users@lists.isc.org> wrote: > > > > Hello! > > > > I started on #bind, moved on to the ARM, and now I am here. > > > >

Re: checkzone from stdin?

2020-04-08 Thread Grant Taylor via bind-users
for the detailed explanation. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

DHCPD - BIND DDNS: dnssec-keygen hmac-md5 removed

2020-04-10 Thread moo can via bind-users
Hello, For educational purpose I need to setup an DDNS between DCHPD and BIND. Everywhere, debian, zytrax, freeipa, veritas ... use dnssec-keygen.Zytrax: dnssec-keygen -a HMAC-SHA512 -b 512 -n HOST keyname Veritas: dnssec-keygen -a HMAC-MD5 -b 128 -n HOST example.com. Debian: dnssec-keygen -a

Re: AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Jim Popovitch via bind-users
les. :) -Jim P. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Jim Popovitch via bind-users
On Wed, 2020-04-15 at 14:21 +0200, Reindl Harald wrote: > > Am 15.04.20 um 14:17 schrieb Jim Popovitch via bind-users: > > On Wed, 2020-04-15 at 10:35 +0200, Klaus Darilion wrote: > > > Thanks for answer! > > > > > > So actually it is just a cosmet

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Dennis Clarke via bind-users
and not a package, and daemon name is `named`. Also it is the name used by RPM based systems and Arch Linux and Gentoo, so it was also made to make BIND 9 packages in Debian/Ubuntu more unified with rest of the Linux world. An even more beautiful name would have been "iscbind" : beta$

bind 9.16.2 on centos6

2020-04-18 Thread Carl Byington via bind-users
. Using that, bind 9.16.2 builds to an rpm and installs, but crashes on startup. (gdb) bt #0 0x0033772324f5 in raise (sig=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:64 #1 0x003377233cd5 in abort () at abort.c:92 #2 0x7f2f5fba9cc4 in uv_async_send () from /usr/lib64/libuv.so.1

Re: bind 9.16.2 on centos6

2020-04-18 Thread Carl Byington via bind-users
GP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl6bdZAACgkQL6j7milTFsFmnwCfZC0IxRYScs3qNSxDJ67q31qH 8n4AnRUFgWKhTeachVnl/yihhaz+sm6v =Qnan -END PGP SIGNATURE- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsub

Re: bind 9.16.2 on centos6

2020-04-19 Thread Carl Byington via bind-users
rsion: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl6ceawACgkQL6j7milTFsFUzQCggH9/2MypmkUS1ZIpnbfaE85D ayQAn0dRzHOeNqgwAfKiTdfoWvYLbPo1 =pKY4 -END PGP SIGNATURE- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from thi

Re: [dev] Change in the build system - please test

2020-04-21 Thread Xavier Humbert via bind-users
t.groumpf.org. 2020041901 7200 7200 604800 10800 ;; Query time: 0 msec ;; SERVER: ::1#53(::1) ;; WHEN: Tue Apr 21 18:12:44 CEST 2020 ;; MSG SIZE  rcvd: 113 [xavier@numenor bin]$ ../sbin/named -V BIND 9.17.1-dev (Development Release) running on FreeBSD amd64 12.1-STABLE FreeBSD 12.1-STABLE r3597

RE: NAT and Question Section Mismatch

2020-04-21 Thread Carl Byington via bind-users
/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Vim Syntax, New Release for ISC Bind named.conf 5.16

2020-04-22 Thread Grant Taylor via bind-users
On 4/22/20 12:32 PM, Steve Egbert wrote: Hello, Bind-Users, Hi, This is my 2nd post (in 19 years). Welcome. I'm announcing the release of ISC Bind v9.16 named.conf syntax file for Vim editor. Thank you! The color scheme is derived from default Vim highlights using your own

RHEL, Centos, Fedora rpm 9.16.2

2020-04-23 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. geoip support is not available, since geoip2 is not available in the epel repositories. libuv is in the EL7 epel repository; for EL6 a link is

validating ... bad cache hit

2020-04-24 Thread Havard Eidnes via bind-users
later, a rash of entries pointing to the same bad cache hit. The last entry after this pattern was some 10 minutes later. Looking at the code in BIND 9.14.10 (BIND 9.16.2 doesn't appear to be significantly different in this regard), there appears to be a "cache of bad records" impleme

Re: validating ... bad cache hit

2020-04-24 Thread Havard Eidnes via bind-users
NSSEC) last re-signed the zone 06:51 this morning, and then next on 08:51. So I'm still quite confused as to why this happened. Regards, - Håvard ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: DoH plugin for BIND

2020-05-02 Thread Paul Kosinski via bind-users
mangle it, you have no business about the content of my traffic" ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: DoH plugin for BIND

2020-05-02 Thread Paul Kosinski via bind-users
> with my internet connection" > > > Even if your ISP allows it, chances are that other mail servers will reject > > it > > that's a completl different story > > > On 5/2/20 3:30 PM, Paul Kosinski via bind-users wrote: > >> H

Re: DoH plugin for BIND

2020-05-05 Thread Browne, Stuart via bind-users
On 6/5/20, 02:21, "bind-users on behalf of Chuck Aurora" wrote: On 2020-05-02 14:35, Reindl Harald wrote: > Am 02.05.20 um 21:31 schrieb Chuck Aurora: >> On 2020-05-02 13:23, Erich Eckner wrote: >>> Will there be client-side DoT/DoH suppor

What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
te in the sense that external can be a zone on a VPS server and the internal being an isolated VM in the lab. More specifically, external public and internal private are NOT even remotely the same system thus can't use views or multiple instances of BIND. E: "." ({a..m}.root-

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
rant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
On 5/6/20 1:28 PM, Grant Taylor via bind-users wrote: The only way that I see how to make this work is to anycast the names and IPs of the name servers that lab1.example.net is delegated to.  One anycast instance being external publicly accessible and the other anycast instance being internal

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
isit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
a n00b, because obviously my understanding of it differs from what your understanding seems to be. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
nse of NXDOMAIN. Something that I think is cleaner for the Internet at large. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
anything that's not IPX. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.is

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
at least equivalent answers so the routes are not a security issue. Agreed. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
n the labs. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org

Re: What is the proper way to delegate to a private / hidden sub-domain?

2020-05-06 Thread Grant Taylor via bind-users
ing I was missing that didn't require anycast for proper delegation. But I'm not seeing anything else. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinf

Re: DNS Queries Using API - BIND9

2020-05-10 Thread Vadim Pavlov via bind-users
main issue that bind does’t provide an authentication method. So in any case you somehow should manage the access to the DNS server vice versa it will became open resolver and will be used for DDoS attacks. I would recommend you a few options here: - Use a trial for any “paid” solutions. E.g

Re: DNS Queries Using API - BIND9

2020-05-10 Thread Vadim Pavlov via bind-users
will be using it just in browsers). Vadim > On May 10, 2020, at 23:26, Daniel Stirnimann > wrote: > > > > On 11.05.20 08:18, Vadim Pavlov via bind-users wrote: >> The main issue that bind does’t provide an authentication method. So in >> any case you somehow shoul

Re: DNS Queries Using API - BIND9

2020-05-10 Thread Vadim Pavlov via bind-users
o...@gmail.com>> wrote: > Hmm- Any docs on configuring DOH Proxy? > > On Mon, May 11, 2020 at 11:56 AM Daniel Stirnimann > mailto:daniel.stirnim...@switch.ch>> wrote: > > > On 11.05.20 08:18, Vadim Pavlov via bind-users wrote: > > The main issue that bind does’t p

TSIG DDNS and windows clients

2020-05-12 Thread Pete Fry via bind-users
All I've inherited a BIND environment and i'm trying to understand a few things as currently we are experiences an issue related to DDNS. we have site 1 hostA site 2 hostB We have a HArecord, and we want HostA or HostB to be able to update the HArecord (i.e. failover cl

Re: TSIG DDNS and windows clients

2020-05-13 Thread Grant Taylor via bind-users
tinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

How to disable recursion on ONE domain? (Bind-9.11.14)

2020-05-15 Thread Chris Palmer via bind-users
There is much discussion about recursion but I can't find anything that matches this use case... - In-house Bind-9.11.14 server, master for some local zones, recursion enabled; not accessible from external networks - Two views for in-house networks - Intermittent VPN access from in-

Re: How to disable recursion on ONE domain? (Bind-9.11.14)

2020-05-15 Thread Chris Palmer via bind-users
On 15/05/2020 13:34, Ondřej Surý wrote: Hi Chris, when your vpn comes up, you need to issue: rndc flushtree command to the BIND 9 instance. Ondrej -- Ondřej Surý ond...@isc.org On 15 May 2020, at 14:16, Chris Palmer via bind-users wrote: There is much discussion about recursion but I

Re: How to disable recursion on ONE domain? (Bind-9.11.14)

2020-05-15 Thread Chris Palmer via bind-users
at into the VPN config so people didn't have to do it manually. Is there any way to stop the recursion for that domain happening in the first place though? Thanks, Chris On 15/05/2020 13:34, Ondřej Surý wrote: Hi Chris, when your vpn comes up, you need to issue: rndc flushtree command to the

RHEL, Centos, Fedora rpm 9.16.3

2020-05-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. geoip support is not available, since geoip2 is not available in the epel repositories. libuv is in the EL7 epel repository; for EL6 a link is

KASP Inactive/Retired timestamps

2020-05-19 Thread Gregory Shapiro via bind-users
After the fantastic ISC DNSSEC webinar series last month, I began using KASP for my DNSSEC signed zones. I have noticed an odd behavior with regards to the files BIND keeps in keys/ (K*.key, K*.private, and K*.state). For inactive/retired keys, every BIND restart updates the dates in those

Yet another GSS-TSIG thread for BIND9 with AD

2020-05-23 Thread Vinícius Ferrão via bind-users
) 192.168.1.5: DC #1 (Server 2019) 192.168.1.6: DC #2 (Server 2019) BIND 9 version: bind-9.11.13-3.el8.x86_64 bind-license-9.11.13-3.el8.noarch bind-libs-9.11.13-3.el8.x86_64 bind-export-libs-9.11.13-3.el8.x86_64 bind-utils-9.11.13-3.el8.x86_64 bind-libs-lite-9.11.13-3.el8.x86_64 All machines are configured

Re: Does 'make uninstall' work?

2020-05-28 Thread G.W. Haywood via bind-users
how do you guys upgrade your compiled bind? I don't normally bother with 'make uninstall' for anything at all. You could simply make a copy of the existing 'named' binary in a safe place and when you run 'make install' it will (if you configured things same as last

9.16.3 make tests on centos 8

2020-05-31 Thread Carl Byington via bind-users
SIGNATURE- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more

Deconstructing the Great Firewall of China

2020-06-05 Thread Paul Kosinski via bind-users
A very interesting article on how China uses DNS (among other things) to "control" Internet usage. https://blog.thousandeyes.com/deconstructing-great-firewall-china/ ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubsc

Re: Yet another GSS-TSIG thread for BIND9 with AD

2020-06-12 Thread Vinícius Ferrão via bind-users
42.767 client @0x7f2c580a1ca0 192.0.2.11#55332: update 'local.example.com/IN’<http://local.example.com/IN’> denied On 24 May 2020, at 02:39, Tim Maestas mailto:tmaesta...@gmail.com>> wrote: On Sat, May 23, 2020 at 12:19 PM Vinícius Ferrão via bind-users mailto:bind-users@lists.isc

bind 9.11 resolving PTR record only after a few tries, +trace always, no CNAME involved?

2020-06-13 Thread Steffen Breitbach via bind-users
Hi everyone! I am having issues with my bind server setup. When I try to resolve the PTR for 130.248.154.166 or 172.82.233.25, I will get the proper result only after a few tries so. After that, resolving will work. Resolving with 'dig +trace' will yield the proper result on the fi

Re: BIND Masters and slaves

2020-06-14 Thread Vinícius Ferrão via bind-users
python-go-more-software-adopts-race-neutral-terminology The BIND 9.11 Administrator Reference Manual at https://kb.isc.org/docs/aa-01493 still refers to masters and slaves. Is this ARM the most recent version? Are there any discussions about changing terms? Anyway, when one is talking abut BDSM

Re: BIND Masters and slaves

2020-06-15 Thread G.W. Haywood via bind-users
Hi there, On Mon, 15 Jun 2020, bind-users-requ...@lists.isc.org wrote - and wrote, and wrote: ... [all sniped] ... Please guys[1], stop it. -- 73, Ged. [1] The masculine embraces the feminine where the context permits. ___ Please visit https

RHEL, Centos, Fedora rpm 9.16.4

2020-06-17 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. geoip support is not available, since geoip2 is not available in the epel repositories. libuv is in the EL7 epel repository; for EL6 a link is

Re: Deconstructing the Great Firewall of China

2020-06-23 Thread Paul Kosinski via bind-users
ski via bind-users wrote: > > A very interesting article on how China uses DNS (among other things) > > to "control" Internet usage. > > > > https://blog.thousandeyes.com/deconstructing-great-firewall-china/ > > > The term "DNSSEC" appears ju

Re: Steps to reload zone files automatically?

2020-07-01 Thread G.W. Haywood via bind-users
Hi there, On Wed, 1 Jul 2020, Harshith Mulky wrote: Is there an automatic way we could use reloading the zone files rather than using rndc reload or named restart? It should be trivial to implement this, but I'm not sure that I'd want to do it on a server of mine. We are running

Re: issue in bind installation

2020-07-06 Thread Grant Taylor via bind-users
On 7/6/20 10:00 PM, ShubhamGoyal wrote: I am installing bind latest version with additional feature , it gave me "configure: error librpz.so and dlopen needed for dnsrps" error. I am searching for that error but i did not find the solution. please help me! Are you compiling from s

Re: bind-users Digest, Vol 3492, Issue 1

2020-07-06 Thread Grant Taylor via bind-users
On 7/6/20 10:42 PM, ShubhamGoyal wrote: i am working in Centos 8 with bind version 9.17.2 and  i am install from source package It sounds like you're missing some dependencies. Read the documents that come with BIND source code and make sure you have all the dependencies. Seeing as ho

Re: Request for review of performance advice

2020-07-07 Thread Browne, Stuart via bind-users
Just one quick one before I run off to lunch with regards to section 2: - Try to avoid crossing NUMA boundaries. At high throughput, the context switching and far memory calls kills performance. Stuart From: bind-users on behalf of Victoria Risk Date: Wednesday, 8 July 2020 at 11:58 To

Re: Bind 9.16.x won't start from systemd

2020-07-08 Thread G.W. Haywood via bind-users
Hi there, On Wed, 8 Jul 2020, Adrian van Bloois wrote: When I try to start bind 9.16.x from systemd it fails not being able to find something. When I start it straight from the CMD-line like: sudo /usr/local/sbin/named There is no problem and it works fine. What could be the problem

Re: Request for review of performance advice

2020-07-09 Thread Havard Eidnes via bind-users
e big enough. If on BSD, monitor for "dropped due to full socket buffers" count in "netstat -s" output, and tune accordingly. Note that this may be a symptom of mis-tuning of other parts of BIND, causing excessive CPU usage, which may contribute to this

Re: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Grant Taylor via bind-users
don't know what the current state of affairs is. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the d

Re: scripts-to-block-domains

2020-07-13 Thread Grant Taylor via bind-users
ds. -- Grant. . . . unix || die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscrip

Re: scripts-to-block-domains

2020-07-14 Thread Grant Taylor via bind-users
| die smime.p7s Description: S/MIME Cryptographic Signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at

Re: AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-07-18 Thread Dennis Clarke via bind-users
GreyBeard and suspenders optional ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for mo

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-07-20 Thread Dennis Clarke via bind-users
e world. -- Dennis Clarke RISC-V/SPARC/PPC/ARM/CISC UNIX and Linux spoken GreyBeard and suspenders optional ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software

RHEL, Centos, Fedora rpm 9.16.5

2020-07-22 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCXxiM4BUcY2FybEBmaXZl

Calculate the size of a DNS record in the cache

2020-07-28 Thread Mik J via bind-users
u for sharing your thoughts ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for

intermittent failures and queries sent over TCP

2020-08-18 Thread David Newman via bind-users
bind 9.11.5.P4 on Debian 10 Greetings. I recently had to migrate a nameserver from FreeBSD to Debian. It works fine most of the time but I've noticed a few intermittent resolution failures. After "gmail.com" failed to resolve I took a packet capture using tcpdump to listen to th

RHEL, Centos, Fedora rpm 9.16.6

2020-08-20 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCXz7EtRUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsHXUwCffZxEKWp

Re: srv lookup in record

2020-08-25 Thread Grant Taylor via bind-users
n.mesos I see how we as humans can probably correlate the three. But I don't see how BIND will do it. server.local. CNAMEserver.test.marathon.mesos. That seems like a simple enough alias. Simple enough that I think that it's existence can largely be ignored and focus on the I

Re: srv lookup in record

2020-08-25 Thread Grant Taylor via bind-users
c.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: rpmbuild problem with 9.11.22 on Centos

2020-08-29 Thread Carl Byington via bind-users
GP SIGNATURE- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.i

"forward first" set on a master zone not working as expected

2020-09-02 Thread Taylor Vierrether via bind-users
o have internal entries in the BIND zone file for host1.sub.example.com <http://host1.sub.example.com/> and host2.sub.example.com <http://host2.sub.example.com/>. That part is working fine. However, there is a publicly available DNS entry for sub.example.com <http://sub.example.

Re: Response Policy Zone: disabling "leaking" of lookups

2020-09-02 Thread Carl Byington via bind-users
--BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX1BhpBUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsFe7gCfVN8JVwC8eQ5RExIYVJkOVf3Ywc4A n1pCBkinzCzqBH9IYlXfp5sNeNh1 =Zfin -END PGP SIGNATURE- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: RHEL, Centos, Fedora rpm 9.16.6

2020-09-04 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2020-08-20 at 12:20 -0700, PGNet Dev wrote: > Are they otherwise unrelated? Mine are intended as an in-place replacement/update from the bind versions in RHEL/Centos 7 and 8. The same file layout, etc. This is as close as I can come t

Re: queries for IPV6 records on IPV4-only machine.

2020-09-07 Thread Greg Rivers via bind-users
raries to ask for both A and records. The fact that you have constrained your named to use only IPv4 transport does not change that behavior. -- Greg ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this

Re: queries for external hostnames inside my domain?

2020-09-07 Thread Browne, Stuart via bind-users
You might want to look at the requestor machine's "search" domains. If the stub resolver starts appending search domains when it doesn't get a response it can use. Stuart On 8/9/20, 09:51, "bind-users on behalf of L. A. Walsh" wrote: Notice: This em

Re: Do not cache certain domains

2020-09-10 Thread Carl Byington via bind-users
QL6j7milTFsFijgCeP/0k4923K9ha21b8SfFardvTYJYA njg5U3NImciTSJEZn1eMzsgtNuAY =4J6o -END PGP SIGNATURE- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid sup

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-10 Thread Jim Popovitch via bind-users
#x27;t find an > answer - at least, not one I understood. > So basically, while most of our users do direct queries and don't have this > issue - some of our larger subscribers RSYNC the rbldsnd-formatted files, and > then they typically run rbldnsd on the same server as the

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-10 Thread Jim Popovitch via bind-users
On Thu, 2020-09-10 at 13:50 -0400, Jim Popovitch via bind-users wrote: > On Thu, 2020-09-10 at 11:56 -0400, Rob McEwen wrote: > > I manage an anti-spam DNSBL and I've been running into an issue in recent > > years - that I'm FINALLY getting around to asking about. I just

RHEL, Centos, Fedora rpm 9.16.7

2020-09-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX2ToIhUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsFmPQCghTw5xsvqr08dX5zn1

Djbdns dnscache - binds for multiple IPs

2020-09-30 Thread Karol Nowicki via bind-users
Does somebody has experience  with setup /etc/dnscache/env/IP to configure multiple Ips of network interfaces ?  Thanks  Wysłane z Yahoo Mail do iPhone ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

How can I launch a private Internet DNS server?

2020-10-15 Thread Jason Long via bind-users
te.Is Internet DNS server just possible for providers? Thank you. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at

Re: How can I launch a private Internet DNS server?

2020-10-15 Thread Jason Long via bind-users
therwise it may only be suitable for the website, with a Dynamic DNS service that can regularly update the records as your IP changes. This means that you'll have to use someone else's DNS servers to host your records. You can run BIND locally and make it an authoritative name server

Re: How can I launch a private Internet DNS server?

2020-10-15 Thread Jason Long via bind-users
000, Jason Long via bind-users wrote a message of 1594 lines which said: > in the panel of it, I can enter my DNS server IP addresses. I assume you refer to the panel of your domain name registrar. If so, it would be useful to know which is the label near the field where you enter the IP address.

Re: How can I launch a private Internet DNS server?

2020-10-15 Thread Jason Long via bind-users
nternet DNS server for my goal is "Authoritative DNS" ? -- Michael De Roover ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions.

Re: How can I launch a private Internet DNS server?

2020-10-15 Thread Jason Long via bind-users
secondary section aren't needed two IP one for web and one for DNS , if you want all can be done with 1 IP be sure you have 80 443 53tcp 53udp open from internet to your server. ____ From: bind-users on behalf of Jason Long via bind-users

Re: How can I launch a private Internet DNS server?

2020-10-16 Thread Paul Kosinski via bind-users
With regard to using chroot, hasn't named/BIND long had the "-u" (user) and "-t" (directory) options to accomplish the same thing more easily? On Fri, 16 Oct 2020 12:47:35 -0500 Chuck Aurora wrote: > /me catching up on earlier parts of this thread, > > On 2

RHEL, Centos, Fedora rpm 9.16.8

2020-10-23 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. Thanks to Espen Stefansen for spec updates, this should work on EL8 systems with ipa-client. -BEGIN PGP SIGNATURE

Re: getting a later-version of BIND on various linux OS's

2020-11-09 Thread Jim Popovitch via bind-users
On November 9, 2020 7:18:03 AM UTC, Rob McEwen wrote: >Several weeks ago, Mark Andrews gave me an excellent suggestion about a >particular BIND feature, but it is a somewhat recent feature that >started to exist on a version of BIND that isn't yet distributed in the >

Re: NXDOMAIN problems

2020-11-17 Thread G.W. Haywood via bind-users
. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users

Two copies of recent posts

2020-11-22 Thread Paul Kosinski via bind-users
49.20.1.60]) by iment0.iment.com (Postfix) with ESMTP id 7B3C3607948F for ; Sun, 22 Nov 2020 18:48:18 -0500 (EST) Received: from lists.isc.org (localhost [127.0.0.1]) by lists.isc.org (Postfix) with ESMTP id B380C67F367; Sun, 22 Nov 2020 23:47:27 + (UTC) X-Origina

Re: Two copies of recent posts

2020-11-22 Thread Jim Popovitch via bind-users
On Sun, 2020-11-22 at 21:56 -0500, Paul Kosinski via bind-users wrote: > I've been getting two identical copies of recent posts to this list... Me too, but it's because of people hitting reply-all thinking that they are replying to the list and the poster. People really need to ve

Re: Two copies of recent posts

2020-11-23 Thread Jim Popovitch via bind-users
On Mon, 2020-11-23 at 08:13 +0100, Reindl Harald wrote: > > Am 23.11.20 um 04:58 schrieb Jim Popovitch via bind-users: > > On Sun, 2020-11-22 at 21:56 -0500, Paul Kosinski via bind-users wrote: > > > I've been getting two identical copies of recent posts to this list...

Re: Two copies of recent posts

2020-11-24 Thread Paul Kosinski via bind-users
ew seconds later by lists.isc.org (again!) with two *different* ESMTP IDs: B380C67F367 and E414B67F36E. This suggests to me that lists.isc.org is being a bit too diligent in delivering its email. On Sun, 22 Nov 2020 22:58:07 -0500 Jim Popovitch via bind-users wrote: > On Sun, 2020-11-22 a

Re: Two copies of recent posts

2020-11-24 Thread Jim Popovitch via bind-users
il. > I just received 2 copies of your post, with 2 different ESMTP IDs... because you sent it to 2 different recipients. That same thing would happen if you sent it to bind-users@lists.isc.org and bind-users@lists.isc.org. -Jim P. ___ Please visit

Re: Two copies of recent posts

2020-11-25 Thread Paul Kosinski via bind-users
Yes indeed: I sent the last email (and this one) to bind-users and CC-ed to you. That explains why there are two different ESMTP IDs. The question is, have you, like I have, received two copies of any emails (from lists.isc.org) where there *identical* ESMTP IDs in their associated sequences

RHEL, Centos, Fedora rpm 9.16.9

2020-11-26 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX8APLhUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsEA5gCfSJPL0ftRp

Re: Bind: named can't listen while using VRF

2020-12-14 Thread Grant Taylor via bind-users
On 12/14/20 9:50 PM, Mark Andrews wrote: In theory all that should be needed is "ip vrf exec [ NAME ] named …" What I've done with l3mdev makes me think that if BIND is run in the master network namespace, it should be able to bind (no pun intended) to IPs across VRFs if th

RHEL, Centos, Fedora rpm 9.16.10

2020-12-17 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX9uRhRUcY2FybEBmaXZl

Re: BIND through COPR after CentOS

2020-12-18 Thread G.W. Haywood via bind-users
Hi there, On Fri, 18 Dec 2020, Leroy Tennison wrote: ... switching from an rpm world to a deb world ... Not an enormous change but significant. Indeed. I'd suggest that if it's just about BIND, it's easier to grab the source and build it. That way you don't ever

Re: Quick dynamic DNS?

2020-12-23 Thread Grant Taylor via bind-users
already acting as an unbound/piHole server, if that helps. Are you wanting to do some sort of zone transfer from the rPI to BIND? Is home.example.com public or private? Can the world query it? I used to use a dynamic DNS service, but I figure I have the tools available to do this all myself. What

Re: Quick dynamic DNS?

2020-12-24 Thread Grant Taylor via bind-users
e documentation domains / IPs / networks used properly. I tip my hat to you. As I said, it is authoritative for example.com. ACK Yep. No, I just want my bind server to get updated with the external IP of my home connection when it changes and update the A pointer. Okay. IMHO that'

<    3   4   5   6   7   8   9   10   11   12   >