Re: Deprecated DSCP support

2024-02-29 Thread Wolfgang Riedel via bind-users
_keywords=yes&area=default > 2. https://docs.libuv.org/en/v1.x/udp.html > > On 28. 02. 24 13:50, Balazs Hinel (Nokia) via bind-users wrote: >> Hi, >> I am working on a product in Nokia, and we currently use BIND provided by >> Rocky Linux 8 with security patches. Recen

Re: Deprecated DSCP support

2024-02-29 Thread Greg Choules via bind-users
r manufacturers are available), match all port 53, set DSCP to an appropriate value for *your* network and prioritise/police as appropriate in the core. Cheers, Greg On Thu, 29 Feb 2024 at 09:00, Wolfgang Riedel via bind-users < bind-users@lists.isc.org> wrote: > Hi Folks, > > OK

Re: fixed rrset ordering - is this still a thing?

2024-02-29 Thread Matt Nordhoff via bind-users
on't mind if you remove it. > Thanks, > Ondřej -- Matt Nordhoff -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more i

Re: fixed rrset ordering - is this still a thing?

2024-02-29 Thread Matt Nordhoff via bind-users
ther nameservers do support fixed order, but I personally don't > use it and don't mind if you remove it. > > > Thanks, > > Ondřej -- Matt Nordhoff -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this soft

Re: Deprecation notice force BIND 9.20+: "rrset-order fixed" and "sortlist"

2024-03-01 Thread Greg Choules via bind-users
ings like > performance and load to consider. Might your tweaked responses just > send clients to a nearby but tragically overloaded server? > > My preference would be to let those people whose job it is to think > about this stuff - which, reading this list, clearly they do - get

RE: fixed rrset ordering - is this still a thing?

2024-03-01 Thread Mike Mitchell via bind-users
ections take too long and there must be a network error. Mike Mitchell -Original Message- From: bind-users On Behalf Of Ondrej Surý Sent: Thursday, February 29, 2024 4:40 PM To: BIND Users Mailing List Subject: fixed rrset ordering - is this still a thing? EXTERNAL Hey, BIND 9 suppor

Re: fixed rrset ordering - is this still a thing?

2024-03-01 Thread Nick Tait via bind-users
On 02/03/2024 03:42, Mike Mitchell via bind-users wrote: Our networking team is in the habit of entering the IP address of every network interface on a router under one name. The very first address entry is their out-of-band management interface. "rrset-order fixed" is used on th

Re: fixed rrset ordering - is this still a thing?

2024-03-01 Thread Greg Choules via bind-users
uffix, so it's a simple matter of combining them. On Fri, 1 Mar 2024 at 21:11, Nick Tait via bind-users < bind-users@lists.isc.org> wrote: > On 02/03/2024 03:42, Mike Mitchell via bind-users wrote: > > Our networking team is in the habit of entering the IP address of every >

Re: fixed rrset ordering - is this still a thing?

2024-03-01 Thread Nick Tait via bind-users
e could be included in the "example.com" zone. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.

Bind9 "split zones"

2024-03-04 Thread Taavi Ansper via bind-users
work. I have a feeling the forwarding only works specific zones.  and you can't combine two of the same "names" into one. Am I correct and in order for PTR records to work I need to get them into a single file? -- Taavi Ansper taavi.ans...@cyber.ee -- Visit https://list

Re: Bind9 "split zones"

2024-03-04 Thread Greg Choules via bind-users
ers" statement because " sub.example.com" has been delegated away. - Do you really want to be forwarding to your hidden primary anyway? - Why are two different servers both authoritative for "100.168.192.in-addr.arpa"? That's asking for trouble. Hope that he

Re: Bind9 "split zones"

2024-03-04 Thread Taavi Ansper via bind-users
t; will follow the "forwarders" statement because "sub.example.com <http://sub.example.com>" has been delegated away. - Do you really want to be forwarding to your hidden primary anyway? - Why are two different servers both authoritative for "100.168.192.in-addr.arpa"?

Re: opendnssec -> inline-signing

2024-03-07 Thread Nick Tait via bind-users
"| I couldn't help noticing that when you ran dnssec-dsfromkey you referenced this directory: /usr/home/dns/Fixed Nick. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Cont

Re: DNSSEC deployement in an isolated virtual environment

2024-03-16 Thread Greg Choules via bind-users
into > account and it works in my virtual environment? I think I know how DNSSEC > works, but if you also have any clarification to offer, I'd be delighted to > hear from you. My BIND server runs on an Ubuntu22.04 Jammy Jellyfish VM. > > Thanks in advance for your help. >

AW: Crafting a NOTIFY message from the command line?

2024-03-21 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Arsen > STASIC > Gesendet: Donnerstag, 21. März 2024 08:47 > An: Petr Špaček > Cc: bind-users@lists.isc.org > Betreff: Re: Crafting a NOTIFY message from the command line? > > * Petr Špaček [2024-0

RHEL, Centos, Rocky, Fedora rpm 9.18.25

2024-03-22 Thread Carl Byington via bind-users
. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCZf3WuxUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsHr2gCfYw4U1U1itN4N0USVhyfg1325YjMA nRpCW3TjF6RFMPWZgReI3QC9W2pt =LxDT -END PGP SIGNATURE- -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: transfert master slave

2024-03-25 Thread Greg Choules via bind-users
slave, it still receives updates from the master. The > transfer on the master is as follows: > > allow-transfer {192.168.56.157;}; > > also-notify {192.168.56.157;}; > > notify explicit;" > > > > PS. BIND version : 9.16.48 > > > > Regards Sami > &g

Re: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records

2024-03-26 Thread Jan Schaumann via bind-users
chase CNAMEs. Fortunately, nowadays we have a proper solution for this problem (which -- bringing it back on-topic :-) -- bind supports): SVCB / HTTPS records (RFC9460). However, adoption of those records is still lacking, with clients behaving inconsistently and services not offering them widely yet.

AW: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records

2024-03-26 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Jan > Schaumann via bind-users > Gesendet: Dienstag, 26. März 2024 14:44 > An: bind-users@lists.isc.org > Betreff: Re: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records > > Karl Auer

Re: Some Authoritative-Only BCPs

2024-03-28 Thread Greg Choules via bind-users
d this, > > zone "." { > type primary; > file "primary/empty-zone.db"; > allow-query { none; }; > }; > > Which seems to do the trick, but is that the cleanest way? Any problems > with that approach that I haven't considered? > > Oh, on

Re: Some Authoritative-Only BCPs

2024-04-02 Thread Greg Choules via bind-users
there is no reason for this server to do outbound DNS, > >> except > >> to its hidden masters, so it just keeps trying and cluttering the > >> firewall > >> logs. What's the best way to stop this behavior? Is there a > >> configuration > >> opt

Re: Answers for www.dnssec-failed.org with dnssec-validation auto;

2024-04-17 Thread Nick Tait via bind-users
;ll see something interesting when the problem happens? Nick. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

RHEL, Centos, Rocky, Fedora rpm 9.18.26

2024-04-17 Thread Carl Byington via bind-users
. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCZiAhLBUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsH/TwCfRECCzSbMwWY4o32rzDT1X3b8kxMA nj9AgWAaoXYHW7AtfK7Ii57mrHkp =iSyg -END PGP SIGNATURE- -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: RFC8482: Implementation

2024-04-22 Thread Greg Choules via bind-users
s? > > Thanks in advance > -- > Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support > subscriptions. Contact us at https://www.isc.org/contact/ for more > information. &g

Re: Observation: BIND 9.18 qname-minimization strict vs dig +trace

2024-04-26 Thread Havard Eidnes via bind-users
rver which actually advertises itself as authoritative > for 85.191.131.in-addr.arpa Yep. Both of the resolveable NSes ns102.click-network.com and fs838.click-network.com claim authority over 191.131.in-addr.arpa, which they don't have according to the parent zone DNS delegations. Reg

Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-04-27 Thread Walter H. via bind-users
phic Signature -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists

Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-04-27 Thread Walter H. via bind-users
On 27.04.2024 16:54, Lee wrote: On Sat, Apr 27, 2024 at 9:50 AM Walter H. via bind-users wrote: # host dnssec-analyzer.verisignlabs.com dnssec-analyzer.verisignlabs.com is an alias for dnssec-analyzer-gslb.verisignlabs.com. dnssec-analyzer-gslb.verisignlabs.com has address 209.131.158.42

Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-04-28 Thread Walter H. via bind-users
|Try these four | | | |fail01.dnssec.works| |fail02.dnssec.works| |fail03.dnssec.works| |fail04.dnssec.works| and then with   +cd and note the difference; On 28.04.2024 08:17, Walter H. via bind-users wrote: On 27.04.2024 16:54, Lee wrote: On Sat, Apr 27, 2024 at 9:50 AM Walter H. via bind

Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-04-29 Thread Walter H. via bind-users
On 29.04.2024 22:19, Lee wrote: On Sun, Apr 28, 2024 at 2:18 AM Walter H. via bind-users wrote: something that I replied to and got this in response: Error Icon Message blocked Your message to Walter.H@[..snip..] has been blocked. See technical details below for more information. The

Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-05-01 Thread Walter H. via bind-users
On 01.05.2024 01:33, Mark Andrews wrote: On 1 May 2024, at 03:32, Lee wrote: On Mon, Apr 29, 2024 at 11:40 PM Walter H. wrote: On 29.04.2024 22:19, Lee wrote: On Sun, Apr 28, 2024 at 2:18 AM Walter H. via bind-users wrote: something that I replied to and got this in response: Error Icon

Re: SRV on multiple subdomains

2024-05-16 Thread Greg Choules via bind-users
configure a generic target for all subdomains as each entity > has its own target for SRV entries. > > -----Message d'origine- > > De : bind-users bind-users-boun...@lists.isc.org De la part de Matus > UHLAR - fantoms > Envoyé : mardi 14 mai 2024 15:58 > À : bind-u

Re: CIDR notation for RPZ rpz-ip ?

2024-05-17 Thread Nick Tait via bind-users
isit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailma

RHEL, Centos, Rocky, Fedora rpm 9.18.27

2024-05-18 Thread Carl Byington via bind-users
. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCZkjq8RUcY2FybEBmaXZl LXRlbi1zZy5jb20ACgkQL6j7milTFsGcdACfW7MPuExfZza+zn/jNlBlDQSXg7UA nigu6WsOkIztjyHDY/KuJmx6TCEf =z8Wr -END PGP SIGNATURE- -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: Make dig and nslookup DNSSEC aware?

2024-05-22 Thread Havard Eidnes via bind-users
y from the "knot" name server is able to do DoT and DoH (the latter only if configured to use libnghttp2), and in my case that was the shorter path to the goal of having a CLI tool to do DoT and DoH testing. Regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-user

Re: Make dig and nslookup DNSSEC aware?

2024-05-22 Thread Havard Eidnes via bind-users
That's what a validating recursive resolver does; watch for the 'ad' flag from one such instead? Regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions.

Counters for DNS transports?

2024-05-22 Thread Havard Eidnes via bind-users
, "via TCP/53" and "via TLS" or "via HTTPS". Is this a missing feature? I've not checked, but does perhaps BIND 9.19.x have an improvement over 9.18 in this aspect? Regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: Make dig and nslookup DNSSEC aware?

2024-05-22 Thread Havard Eidnes via bind-users
> Doesn't dig already offer DoT using +tls and DoH using +https? You're right, it does. I need to sort out my $PATH... Regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with

Re: Counters for DNS transports?

2024-05-22 Thread Havard Eidnes via bind-users
> I frontend DoH and DoT traffic with nginx and use that for > analytics/statistics. Thanks, but I think that violates the KISS principle. Regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this so

Re: Counters for DNS transports?

2024-05-22 Thread Havard Eidnes via bind-users
t's also on my wishlist, FWIW. :) Best regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.

Debugging TSIG signed nsupdate problems

2024-05-24 Thread Erik Edwards via bind-users
7;s are working correctly. -Erik OpenPGP_signature.asc Description: OpenPGP digital signature -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/

Re: Debugging TSIG signed nsupdate problems

2024-05-24 Thread Erik Edwards via bind-users
9, upgrades were seamless. Really wondering how to get debug level logs on this module. On 5/24/24 11:31 AM, John Thurston wrote: named-conf -px OpenPGP_signature.asc Description: OpenPGP digital signature -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: Debugging TSIG signed nsupdate problems

2024-05-26 Thread Erik Edwards via bind-users
5519 ED448 DS algorithms: SHA-1 SHA-256 SHA-384 HMAC algorithms: HMAC-MD5 HMAC-SHA1 HMAC-SHA224 HMAC-SHA256 HMAC-SHA384 HMAC-SHA512 TKEY mode 2 support (Diffie-Hellman): yes TKEY mode 3 support (GSS-API): yes default paths:   named configuration:  /etc/named.conf   rndc configuration:   /etc/rndc.conf

Re: Debugging TSIG signed nsupdate problems - Specifically a logging question

2024-05-27 Thread Erik Edwards via bind-users
asking about the logging function itself._ Should the trace level of 99 generate more information in the logs for the update function than I am observing? -Erik OpenPGP_signature.asc Description: OpenPGP digital signature -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubsc

Re: Debugging TSIG signed nsupdate problems - Specifically a logging question

2024-05-28 Thread Erik Edwards via bind-users
ng for. You did look at the descriptions of all of the categories? https://bind9.readthedocs.io/en/stable/reference.html#namedconf-statement-category OpenPGP_signature.asc Description: OpenPGP digital signature -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this lis

Re: issue with forwarder zones

2024-05-29 Thread Greg Choules via bind-users
:48, Cuttler, Brian R (HEALTH) via bind-users < bind-users@lists.isc.org> wrote: > My bad - I'd mailed this mistakenly to an individual and not the list. > > --- > > I am currently running BIND 9.18.18-0ubuntu0.22.04.2-Ubuntu. > > I am sometimes seeing that I don

Problem with a certain domain

2024-05-31 Thread Thomas Barth via bind-users
minimization due to 'ncache nxdomain' -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Problem with a certain domain

2024-05-31 Thread Havard Eidnes via bind-users
ame does not exist (which is obvious), and nothing exists below that node either. See RFC 8020. Regards, - Håvard -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at h

Re: Problem with a certain domain

2024-06-01 Thread Thomas Barth via bind-users
named.conf.local logging { channel my_syslog { syslog daemon; severity notice; }; channel my_file { file "/var/log/named/messages"; severity info; print-time yes; }; category default { my_file; }; } -- Visit https://lists.isc.org/mailman

Re: Problem with a certain domain

2024-06-01 Thread Thomas Barth via bind-users
https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/ma

Building bind 9.19.24 on Openwrt w/ MUSL

2024-06-01 Thread Philip Prindeville via bind-users
else had problems with autoconf and cross-compilation w/ MUSL? I wanted to do a bump on bind to pick up this fix: https://gitlab.isc.org/isc-projects/bind9/-/issues/3152 Thanks, -Philip -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the dev

Re: Problem with a certain domain

2024-06-03 Thread Thomas Barth via bind-users
domain and bind9 for everything else? Because dig @9.9.9.9 s1._domainkey.mg-esp-prod-eu-eu.mallorcazeitung.es always works with a good response. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support

Re: Problem with a certain domain

2024-06-03 Thread Thomas Barth via bind-users
of bad configuration? -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users

Re: Problem with a certain domain

2024-06-03 Thread Paul Kosinski via bind-users
Could you send the email from another account (which doesn't use your DNS server)? It's not too hard to set up a free account with services like Outlook, Yahoo or (if desperate) Gmail. On Mon, 03 Jun 2024 18:46:40 +0200 Thomas Barth via bind-users wrote: > Hello, > > I

Re: Problem with a certain domain

2024-06-04 Thread Nick Tait via bind-users
On 4/06/2024 12:44 am, Thomas Barth via bind-users wrote: unfortunately, today I had to restart bind9 for the third time in an attempt to send a newsletter to get rid the communication error, although with a query response of 1800 msecs. Is it possible to configure bind9 so that a public DNS

Re: Problem with a certain domain

2024-06-04 Thread Thomas Barth via bind-users
Am 2024-06-04 09:50, schrieb Matus UHLAR - fantomas: On 03.06.24 18:46, Thomas Barth via bind-users wrote: Should I perhaps ask the mail user to unsubscribe from this website due to troubles of bad configuration? yeah I guess you should, their DNS servers are pretty much messed up: A

Re: Problem with a certain domain

2024-06-04 Thread Greg Choules via bind-users
stand what the problem is first and to do that, gather data (pcaps and logs) that can be used to paint a picture of what's really happening. Cheers, Greg On Tue, 4 Jun 2024 at 13:01, Thomas Barth via bind-users < bind-users@lists.isc.org> wrote: > Am 2024-06-04 09:50, schrieb Mat

Re: Problem with a certain domain

2024-06-04 Thread Thomas Barth via bind-users
e 0x3a41 A s1._domainkey.mg-esp-prod-eu-eu.mallorcazeitung.es SOA ns1.epi.es I therefore suspect that the delay will be even greater tomorrow again when the newsletter arrives, so that the "communication error" will occur again. -- Visit https://lists.isc.org/mailman/listinfo/bind-u

dnssec-policy default - where/how to determine what all its settings are?

2024-06-06 Thread Michael Paoli via bind-users
en looking at Debian BIND9 packages: bind9 1:9.18.24-1 bind9-doc 1:9.18.24-1 and also ISC BIND 9.18.24 source and 9.18.27 source and documentation. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid

Re: dnssec-policy default - where/how to determine what all its settings are?

2024-06-06 Thread Michael Paoli via bind-users
isc.org/isc-projects/bind9/-/blob/main/doc/misc/dnssec-policy.default.conf > > On Thu, Jun 6, 2024 at 8:19 AM Michael Paoli via bind-users > wrote: >> >> dnssec-policy default - where/how to determine what all its settings are? >> Documentation >> doc/bind9-do

Re: MDLZ user activation

2024-06-06 Thread Nick Tait via bind-users
e link), or the email below is bogus and they have exploited the list MTA to distribute spam? Can anyone shed any light on this? Happy to share all the mail headers if that helps? Thanks, Nick. On 07/06/2024 04:19, gustavojavi...@gmail.com wrote: Hi Nick Tait via bind-users, A new MDLZ a

Re: Problem with a certain domain

2024-06-07 Thread Thomas Barth via bind-users
ei...@newsletter.mallorcazeitung.es piano.io Spamassassin Doc "Use this (whitelist_from_rcvd) to supplement the whitelist_from addresses with a check against the Received headers. The first parameter is the address to whitelist, and the second is a string to match the relay's rDNS. &q

Re: MDLZ user activation

2024-06-07 Thread Nick Tait via bind-users
the mailing list archive: https://www.mail-archive.com/bind-users@lists.isc.org/msg34359.html Ged, I'll forward the email headers to you privately, but I trust you'll find that they support the explanation offered below. Thanks again everyone who took the time to respond. :-) Nick.

named -C, ...: Re: dnssec-policy default - where/how to determine what all its settings are?

2024-06-07 Thread Michael Paoli via bind-users
ation to reflect that: > https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/9092/diffs > > Petr Špaček > Internet Systems Consortium > > On 06. 06. 24 21:01, Michael Paoli via bind-users wrote: > > Ah, thanks! > > > > Yeah, that's what I

Re: SERVFAIL error during the evening

2024-06-26 Thread Greg Choules via bind-users
ing the DNS traffic, so I bypassed the > firewall, but the result is the same. How can we ensure that this is a > network-level issue? > > download link: > > https://we.tl/t-M77os84duE > > Regards > > Sami > > -Message d'origine- > De : bind-users

Re: rolling my own hints file

2024-06-26 Thread Greg Choules via bind-users
l you need. Cheers, Greg On Wed, 26 Jun 2024 at 15:58, Cuttler, Brian R (HEALTH) via bind-users < bind-users@lists.isc.org> wrote: > Running Bind 9.18.18 on Ubuntu 22.04 > > > > We would like to use root servers within our organization rather than the > actual root servers.

Re: rolling my own hints file

2024-06-26 Thread Greg Choules via bind-users
t; Thank you – I think you’ve given me exactly what was needed. > > > > Brian > > > > *From:* Greg Choules > *Sent:* Wednesday, June 26, 2024 12:29 PM > *To:* Cuttler, Brian R (HEALTH) > *Cc:* bind-users > *Subject:* Re: rolling my own hints file > >

Re: forward option in dns server

2024-06-27 Thread Greg Choules via bind-users
so I think It makes bind9 forward queries directly to root servers. > What do you think ? > According your opinion this Bind9 server should have to forward requests > to one or more dns server by forward option? > > -- > Visit https://lists.isc.org/mailman/listinfo/bind-users

Re: forward option in dns server

2024-06-27 Thread Greg Choules via bind-users
point, fetching data from wherever it needs to (e.g. AD DNS) - >> using non-recursive queries - and using that data to construct answers for >> its clients. >> >> I hope that helps. >> Cheers, Greg >> >> On Thu, 27 Jun 2024 at 12:02, Renzo Mareng

Re: forward option in dns server

2024-06-27 Thread Greg Choules via bind-users
;> >>> >>> Il giorno gio 27 giu 2024 alle ore 13:24 Greg Choules < >>> gregchoules+bindus...@googlemail.com> ha scritto: >>> >>>> Hi Renzo. >>>> Firstly, please can we see your BIND configuration and have the actual >>>>

Re: forward option in dns server

2024-06-27 Thread Greg Choules via bind-users
selves. >>>>> >>>>> >>>>> There is no forward option to AD DNS. Forward is enable from AD DNS to >>>>> A.B.C.D. bind9 server. >>>>> >>>>> >>>>> >>>>> >>>>> All clients

Re: forward option in dns server

2024-06-28 Thread Greg Choules via bind-users
t;> statistics-file “….. named_stats.txt"; >>>>>>> >>>>>>> memstatistics-file “…. named_mem_stats.txt"; >>>>>>> >>>>>>> recursing-file “… named.recursing"; >>>>>>> >>>>>

Re: forward option in dns server

2024-06-28 Thread Greg Choules via bind-users
;>>>>>>>> >>>>>>>>> category default { named_debug; }; >>>>>>>>> >>>>>>>>> }; >>>>>>>>> >>>>>>>>> >>>>>>>

Re: rolling my own hints file

2024-07-01 Thread Greg Choules via bind-users
y detrimental? > If it is, its “dot” rather than “at”? > > @ 518400 IN A xx.yy.zz..7 > > @ 518400 IN A xx.yy.zz..8 > > . 518400IN NS @ > > > > Thank you. > > Brian > > > > *From:* bind-users * On Behalf Of *Cuttler, > Brian R (HEALTH)

netstat showing multiple lines for each listening socket

2024-07-08 Thread Thomas Hungenberg via bind-users
:530.0.0.0:* 1234/named udp0 0 127.0.0.1:530.0.0.0:* 1234/named We wonder what is causing this and if this is intended behaviour? - Thomas  -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: netstat showing multiple lines for each listening socket

2024-07-08 Thread Thomas Hungenberg via bind-users
s. Robert Wagner ____ From: bind-users on behalf of Thomas Hungenberg via bind-users Sent: Monday, July 8, 2024 4:52 AM To: bind-users@lists.isc.org Subject: netstat showing multiple lines for each listening socket This email originated from outside of TESLA Do not c

zone_journal_compact: could not get zone size: not found

2024-07-08 Thread Kees Bakker via bind-users
CentOS 8-Stream. Does anyone have a clue what it can be? Or how to find out? There are close to zero hits when I searched for this on the internet. How to debug this? (How to debug this in a production environment, ha ha) -- Kees -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: zone_journal_compact: could not get zone size: not found

2024-07-08 Thread Greg Choules via bind-users
its files? - How much RAM does the server have and how much of that is BIND using? I would recommend reading the ARM section on the journal. The log message itself comes from "zone.c" Cheers, Greg On Mon, 8 Jul 2024 at 12:18, Kees Bakker via bind-users < bind-users@lists.isc.org>

Re: zone_journal_compact: could not get zone size: not found

2024-07-08 Thread Kees Bakker via bind-users
ssage before upgrading CentOS. One system is still at CentOS 8-Stream. The message isn't shown on that one. Cheers, Greg -- Kees On Mon, 8 Jul 2024 at 12:18, Kees Bakker via bind-users wrote: Hi, At the moment I have three FreeIPA systems (replicas), recently installed with

Re: zone_journal_compact: could not get zone size: not found

2024-07-08 Thread Kees Bakker via bind-users
he ARM section on the journal. The log message itself comes from "zone.c" Cheers, Greg On Mon, 8 Jul 2024 at 12:18, Kees Bakker via bind-users wrote: Hi, At the moment I have three FreeIPA systems (replicas), recently installed with CentOS 9-Stream. All three of t

Re: zone_journal_compact: could not get zone size: not found

2024-07-09 Thread Kees Bakker via bind-users
ethod). -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. On 8. 7. 2024, at 16:48, Kees Bakker via bind-users wrote:  Running gdb showed that the "not found" comes from thi

Re: netstat showing multiple lines for each listening socket

2024-07-09 Thread Thomas Hungenberg via bind-users
n a small embedded system with a single CPU, it creates *four* threads per socket. Hmmm... - Thomas -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www

Re: netstat showing multiple lines for each listening socket

2024-07-10 Thread Thomas Hungenberg via bind-users
e set to 3 with four CPUs. Also, the parameter "-U" usually does not show up in the ps output if not specified. So in your case it looks more like named is specifically started with "-U4"? - Thomas -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

strange reply dumped URGENT

2024-07-12 Thread Herman Brule via bind-users
ly -- alpha_one_x86/BRULE Herman Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and server management IT, OS, technologies, research & development, security and business department dns.pcapng Description: application/pcapng -- Visit https://lists.isc.org/mailma

Re: strange reply dumped URGENT

2024-07-12 Thread Herman Brule via bind-users
urity and business department On 7/12/24 14:28, Marco Moock wrote: Am 12.07.2024 um 14:13:03 Uhr schrieb Herman Brule via bind-users: bind to my proxy from IPv4 to IPv6 zone Why don't you simply run multiple authoritative servers, some only accessible by IPv6, some dual-stack? They are indep

Re: strange reply dumped URGENT

2024-07-12 Thread Herman Brule via bind-users
pany, not accessible for the customer. In which way is this router involved in DNS resolution? -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc

Re: strange reply dumped URGENT

2024-07-12 Thread Herman Brule via bind-users
o for ore.org.bo/a) ;; QUESTION SECTION: ;ore.org.bo. alpha_one_x86/BRULE Herman Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and server management IT, OS, technologies, research & development, security and business department On 7/12/24 15:00, Marco Moock wrote: Am

Re: strange reply dumped URGENT

2024-07-12 Thread Herman Brule via bind-users
4 19:01, Mark Andrews wrote: On 13 Jul 2024, at 04:38, Herman Brule via bind-users wrote: Because the customer are into IPv6 zone Well all zones should be served by both IPv4 servers and IPv6 servers. IPv6 is nearly 30 years old now. There are sites that are IPv6 only because th

Re: strange reply dumped URGENT

2024-07-14 Thread Herman Brule via bind-users
0 AEST 2024 ;; MSG SIZE rcvd: 88 [ant:~/git/bind9] marka% Mark alpha_one_x86/BRULE Herman Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and server management IT, OS, technologies, research & development, security and business department On 7/12/24 19:01, Mark Andrew

Re: Building bind 9.19.24 on Openwrt w/ MUSL

2024-07-14 Thread Philip Prindeville via bind-users
j Surý — ISC (He/Him) > > My working hours and your working hours may be different. Please do not feel > obligated to reply outside your normal working hours. > >> On 1. 6. 2024, at 23:19, Philip Prindeville via bind-users >> wrote: >> >> Hi, >> &

Re: strange reply dumped URGENT

2024-07-15 Thread Herman Brule via bind-users
;; Query time: 264 msec ;; SERVER: 45.225.75.8#53(45.225.75.8) (UDP) ;; WHEN: Mon Jul 15 09:48:10 AEST 2024 ;; MSG SIZE rcvd: 88 [ant:~/git/bind9] marka% Mark alpha_one_x86/BRULE Herman Main developer of Supercopier/Ultracopier/CatchChallenger, Esourcing and server management IT, OS, technolog

Re: 9.16.27 - Cache Prefetch

2024-07-23 Thread Greg Choules via bind-users
which apparently caused some issues. Is there any new alternative in > later versions? > > Thanks, > Gabe > -- > Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support >

Re: Deleting a key

2024-08-07 Thread Peter DeVries via bind-users
The DS for the new key is only rumored. I believe you want a `rndc dnssec -checkds -key 48266 published` and maybe another to withdraw the 50277 key. Peter -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with

Adding Extra Text to EDNS EDE Responses in BIND 9.19.24

2024-08-12 Thread Robert Paolucci via bind-users
liance on the contents of this information is strictly prohibited. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.

Re: I want to know why I suddenly can't resolve names.

2024-08-19 Thread Greg Choules via bind-users
c-lookaside” entry, I assume that the dlv key is >> not used, so why did I get the error log for the dlv key expire this time? >> I thought the solution was to delete “dnssec-lookaside”, but it was not >> there originally. >> I would like to know how to deal with it. >>

Re: Behavior of 'forward only' zone

2024-08-20 Thread Greg Choules via bind-users
you should, not just because you can. > > John Thurston907-465-8591john.thurs...@alaska.gov > Department of Administration > State of Alaska > > -- > Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the develop

Re: Removal notice: Response Policy Server (BIND 9.21+)

2024-08-21 Thread Paul Vixie via bind-users
ly outside your normal working hours. -- bind-announce mailing list bind-annou...@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-announce -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with pa

Re: Removal notice: Response Policy Server (BIND 9.21+)

2024-08-21 Thread Paul Vixie via bind-users
ttps://lists.isc.org/mailman/listinfo/bind-announce -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mai

views-based RPZ

2024-08-23 Thread Carlos Horowicz via bind-users
configured, or even be set to "unlimited"  ? Thanks in advance Carlos Horowicz Planisys -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://w

Re: 9.18 horrendous

2024-08-23 Thread Dennis Clarke via bind-users
. Expect to be banned and canceled by the childish little minds that feel they are entitled to control the narrative. -- Dennis Clarke RISC-V/SPARC/PPC/ARM/CISC UNIX and Linux spoken -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the

views-based RPZ

2024-08-23 Thread Carlos Horowicz via bind-users
configured, or even be set to "unlimited" ? Thanks in advance Carlos Horowicz Planisys -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.o

<    1   2   3   4   5   6   7   8   9   10   >