Re: [dns-operations] DNSSEC problem with 174.in-addr.arpa

2013-11-18 Thread Anand Buddhdev
ecord, so it patiently kept waiting and logging this fact. We informed ICANN, and they fixed the operational issue in their provisioning system that was blocking the update. We expect to update the DS records of all zones this week. Regards, Anand Buddhdev RIPE NCC ___

[dns-operations] BIND, Knot and NSD behaviour on zone expiry

2014-02-10 Thread Anand Buddhdev
resumably because they couldn't synchronise the zone with the master. Knot seems to think that it's okay to serve the zone as long as it can query the master, even if the master's serial number is different. Is Knot's behaviour acceptable? Regards, Anand Buddhdev ___

Re: [dns-operations] DNS load-balancing/failover using an ASR 9xxx (few questions)

2014-08-15 Thread Anand Buddhdev
On 15/08/2014 00:00, Nat Morris wrote: > BGP sessions between the ASR 9 and each DNS server in the cluster, > ExaBGP running on them announcing their loopback/service /32 + /128 > address(es). > > Health check scripts on each service to probe for service ability, > retract the announcement up

[dns-operations] DNSSEC validation failures for .KE

2015-03-31 Thread Anand Buddhdev
/ Their current DS record points to a key that has the revoke bit set, but it is no longer signing the DNSKEY rrset. Regards, Anand Buddhdev RIPE NCC -BEGIN PGP SIGNATURE- Comment: GPGTools - http://gpgtools.org iEYEARECAAYFAlUahw8ACgkQi+U8Q0SwlCtKAQCfX3kq7G+YN4oKbQuQBbI6bybV

Re: [dns-operations] DNSSEC validation failures for .KE

2015-03-31 Thread Anand Buddhdev
On 31/03/15 13:53, Stephane Bortzmeyer wrote: > There are other problems: > > * 10 (!) DNSKEY which seems too many I saw 9 when I looked. This seems to be getting worse. > * lame delegations to mzizi.kenic.or.ke mzizi.kenic.or.ke was answering earlier, but is now giving SERVFAIL as well. Anan

Re: [dns-operations] [Security] Glue or not glue?

2015-05-04 Thread Anand Buddhdev
On 04/05/15 09:11, Stephane Bortzmeyer wrote: Bonjour Stéphane, > A new edition of the DNS security guide by ANSSI (French cybersecurity > agency) recommends to prefer delegations with glue because glueless > delegations "may carry additional risks since they create a > dependency". Is there any

Re: [dns-operations] com. Glue

2015-05-19 Thread Anand Buddhdev
On 19/05/15 23:12, Jim Popovitch wrote: Hi Jim, > Hello, > > I'm stuck in the middle with $registrar saying glue exists, and > intodns, et.al., saying no glue exists. I would appreciate any > insight into why there is no glue appearing for speedyiguana.com (a > mailman dev/test system that i u

Re: [dns-operations] .MW inconsistent zone updates?

2015-06-25 Thread Anand Buddhdev
ach .MW's masters: 23-Jun-2015 19:05:26.224 general: zone mw/IN/main: refresh: retry limit for master 196.45.188.5#53 exceeded (source 0.0.0.0#0) 23-Jun-2015 19:05:56.225 general: zone mw/IN/main: refresh: retry limit for master 41.221.99.135#53 exceeded (source 0.0.0.0#0) Re

Re: [dns-operations] Verifying that a recursor is performing DNSSec validation

2015-07-17 Thread Anand Buddhdev
On 17/07/15 07:51, Frank Bulk wrote: > I've completed writing the first iteration of a NAGIOS-oriented Perl script > that does the checks I've described. It was actually more painful to get > the Net:DNS:DNSsec Perl module installed than anything else. I haven't seen your script, of course, so I

Re: [dns-operations] IPv6 only for nameservers

2019-12-30 Thread Anand Buddhdev
On 30/12/2019 10:38, Yonah Peng wrote: Hi Yonah Peng, > As IPv4 addresses were exhausted today, if we have deployed the > nameservers with IPv6 addresses only, can they be resolvable by world wide? If your domain's authoritative name servers have only IPv6 addresses, then your domain will not be

Re: [dns-operations] Surprising behaviour by certain authoritative name servers

2020-01-07 Thread Anand Buddhdev
8af1379 specify that www.heaven.af.mil will have address 1.2.3.4 until time 400038af1379 (2000-02-19 22:04:31 UTC) and will then switch to IP address 1.2.3.7." Regards, Anand Buddhdev ___ dns-operations mailing list dns-operations@lists.dns

Re: [dns-operations] Outages last night?

2020-04-03 Thread Anand Buddhdev
On 03/04/2020 11:43, Greg Choules via dns-operations wrote: > Good morning all. > Did anyone else experience service outages around 22:20 to 22:30 (UTC) > yesterday? Yes. No. Maybe. If you ask a more specific question about which service you're talking about, it might be easier to answer. > Just

[dns-operations] DNSSEC Validation Failures for RIPE NCC Zones

2020-05-22 Thread Anand Buddhdev
experienced some failures if they had cached signatures made by the old ZSKs. We apologise for any operational problems this may have caused. We are looking at the issue with the developers of our Knot DNS signer to prevent such an occurrence in the future. Regards, Anand Buddhdev RIPE NCC

[dns-operations] NXDOMAIN for a-dns.pl and e-dns.pl

2020-06-01 Thread Anand Buddhdev
Hi, Anyone from the Polish ccTLD around? The .PL delegation contains a-dns.pl and e-dns.pl, but when the name server addresses of .PL are queried for A and records for these names, I get NXDOMAIN responses. ; <<>> DiG 9.16.3 <<>> +trace +nodnssec a-dns.pl a ;; global options: +cmd .

Re: [dns-operations] Possibly-incorrect NSEC responses from many RSOs

2021-03-01 Thread Anand Buddhdev
On 01/03/2021 18:55, Viktor Dukhovni wrote: Hi Viktor, > Cool, but at first blush the feature appears to have a bug in BIND 9.16.12: > > # dig +noall +ans +nocl +nottl +nosplit +norecur -t rrsig .org > @ | awk '{print $2}' | uniq -c >1 RRSIG > > # dig +noall +ans +nocl +nottl +

Re: [dns-operations] validating zones before distribution to secondaries

2021-05-04 Thread Anand Buddhdev
ustom commands when changes are detected. It can also listen for NOTIFY messages and act immediately on zone changes. You could use it to run your custom checks before distributing your zones. https://github.com/fanf2/nsnotifyd Regards, Anand Buddhdev ___

Re: [dns-operations] K-root in CN leaking outside of CN

2021-11-08 Thread Anand Buddhdev
already said this, but I'd like to make it clear that the K-root server was NOT emitting false responses for Facebook and WhatsApp. The responses were being modified by something between the server and its clients. Regards, Anand Buddhdev RIPE NCC On 08/11/2021 08:45, Davey Song wrote:

[dns-operations] Changes to Time-to-Live (TTL) values in reverse DNS zones

2022-04-11 Thread Anand Buddhdev
records will be imported with the TTLs as published by the origin RIR. Regards, Anand Buddhdev RIPE NCC ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Re: [dns-operations] Stale .GN and .LR zone data in some instances of "ns-{gn, lr}.afrinic.net"

2022-08-30 Thread Anand Buddhdev
On 30/08/2022 18:42, Randy Bush wrote: Hi Randy, Viktor, another day of no response from afrinic, and i guess i should ask the iana to remove them from the NS RRset for GN and LR. anyone have a way to get afrinic dns folk's attention? Try the address dns-mast...@afrinic.net. This is the addr

Re: [dns-operations] New addresses for b.root-servers.net

2023-06-03 Thread Anand Buddhdev
On 03/06/2023 23:09, Doug Barton wrote: Hi Doug, [snip] Since the host records are the interesting bit, we do absolutely need to make sure that we can sanity check them somehow. I'm not sure Chris' suggestion to essentially "vote" on which host records are the right ones based on the results

Re: [dns-operations] in-addr.arpa. "A" server "loopback network" misconfiguration

2023-06-22 Thread Anand Buddhdev
On 22/06/2023 16:48, Matthew Pounsett wrote: Hi Matt, Which of the below would you suggest? SOA rname:ns...@iana.org WHOIS Administrative: i...@iab.org WHOIS Technical: tld-cont...@iana.org I would have started with the IANA addresses, since they publish the z

Re: [dns-operations] Old version of dig on macOS

2023-12-18 Thread Anand Buddhdev
On 18/12/2023 19:48, Weinberg, Matt via dns-operations wrote: Hi Matt, The latest patched versions of macOS Ventura (13.6.3) and Sonoma (14.1.2) both include an old version of the dig client: % dig -v DiG 9.10.6 I only noticed the issue when I attempted to retrieve the ZONEMD record of the ro

[dns-operations] Minimalistic DNS server for SOA and AXFR

2012-07-16 Thread Anand Buddhdev
Hello DNS gurus, I'm writing a minimalistic DNS server (in python, using the dnspython module), whose purpose will simply be to provide AXFR for a fixed set of zones. The clients will be BIND and/or NSD. It will send NOTIFY messages to the clients, and provide (some) responses. As far as I c

Re: [dns-operations] Minimalistic DNS server for SOA and AXFR

2012-07-17 Thread Anand Buddhdev
e XFR). So I can get away with implementing just AXFR over TCP, and nothing else (including returning AXFR in response to IXFR). Regards, Anand On 16/07/2012 16:49, Anand Buddhdev wrote: > Hello DNS gurus, > > I'm writing a minimalistic DNS server (in python, using the dnspython > module

Re: [dns-operations] Minimalistic DNS server for SOA and AXFR

2012-07-17 Thread Anand Buddhdev
On 17/07/2012 15:33, Mark Andrews wrote: > Actually named does do SOA queries over TCP before AXFR. Hi Mark, On my MacOS X laptop (which comes with BIND 9.7.3-P3), I didn't see SOA queries over TCP. I saw a SOA query over UDP, followed by an AXFR request over TCP. Besides TC in a UDP response, w

Re: [dns-operations] Minimalistic DNS server for SOA and AXFR

2012-07-17 Thread Anand Buddhdev
On 17/07/2012 21:38, Jaap Akkerhuis wrote: Hi Bert, > Anand, > > Sorry to be obtuse, and of course, nothing on the internet needs a reason. > > But inquiring minds want to know. WHY are you inventing yet another > nameserver when we have so many fine ones available alrea

Re: [dns-operations] Reverse DNSSEC--delegating to a child

2012-07-24 Thread Anand Buddhdev
gistration. Karen should be able to use the ARIN web interface to upload DS records. ARIN will then publish the NS+DS records in the 151.in-addr.arpa zonelet on its FTP server, and the RIPE NCC will pick it up and insert the delegation information into 151.in-addr.arpa. Regards, Anand Buddhdev RIPE

Re: [dns-operations] Name server turning off RD bit in response - just curious

2012-08-07 Thread Anand Buddhdev
On 07/08/2012 13:40, Faasen, Craig wrote: > RD is set to 1 in the query, but is 0 in the response. > Which is not compliant with RFC 1035: "RD Recursion Desired - this > bit may be set in a query and is copied into the response." > > Out of curiosity, any idea why a name server would want to chan

Re: [dns-operations] Anycast and views match-destination

2012-08-18 Thread Anand Buddhdev
On 18/08/2012 12:00, sasa sasa wrote: Hello sasa sasa (please use your real name; it's polite), > So I use match-destination in BIND views on a server with multiple interfaces. > > If I want to configure one of these interfaces to be part of an > anycast network, should I change match-destinatio

[dns-operations] Comparing TCP and UDP response times of root name servers

2012-10-17 Thread Anand Buddhdev
welcome. Regards, Anand Buddhdev RIPE NCC ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

[dns-operations] Multi-master setups

2013-05-17 Thread Anand Buddhdev
any of you do this? Aside from this idea, are there any other clever ideas people have implemented? Regards, Anand Buddhdev ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operation

[dns-operations] Discarding bad records from an AXFR

2013-07-30 Thread Anand Buddhdev
ou all think is the correct behaviour? Or are both correct? PS. I realise that Knot's behaviour could break a DNSSEC-signed zone, but then, no sane signer will sign a zone with out-of-zone records, so that the process of signing a zone would force the operator to clean up their zone. Regards,

[dns-operations] Registrars with a "registry lock" service

2025-01-08 Thread Anand Buddhdev
hibited", "serverRenewProhibited", "serverTransferProhibited" and "serverUpdateProhibited" lines. These ensure that the domain cannot be deleted, transferred, or modified without a manual check by the registry. Is anyone aware of registrars that provide this service? Regards,

Re: [dns-operations] Potentially blacklisted on h.root-servers.net, e.in-addr-servers.arpa

2025-04-09 Thread Anand Buddhdev
Roy Arends has already provided a contact for H-root. For e.in-addr-servers.arpa, contact APNIC . Regards, Anand Buddhdev RIPE NCC On Wed, 9 Apr 2025 at 11:22, Thomas Mieslinger via dns-operations < dns-operati...@dns-oarc.net> wrote: > > > > -- Forwarded message