Re: [Opendnssec-user] Problems adding largish # of zones

2015-12-17 Thread Yuri Schaeffer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, > My initial reaction is that this will make OpenDNSSEC into the > local network villain, and will create a "thundering herd" of TCP > connections on startup, possibly overwhelming the upstream auth > name server (which in our case also does ot

Re: [Opendnssec-user] Problems adding largish # of zones

2015-12-17 Thread Havard Eidnes
Hi, I'll try to digest the rest of your message more properly, but this is just my initial feedback: > So to cut to the chase. Based on my testing, on short term your > troubles should go away by increasing the number of this define in > tcpset.h > > #define TCPSET_MAX 50 > > Make this something

Re: [Opendnssec-user] Problems adding largish # of zones

2015-12-17 Thread Yuri Schaeffer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi HÃ¥vard, > Thanks for enduring my rant. :) Looking forward to see what you > find. Thanks again for bringing this to our attention and your analysis. My grip on the problem has grown the last few days. Although I do not have a proper fix I do know

[Opendnssec-user] ods-signer SEGV on zone deletion

2015-12-17 Thread Havard Eidnes
Hi, my struggles with OpenDNSSEC continues. I recently had to delete 9 zones from our OpenDNSSEC installation. I did this via ods-ksmutil zone delete --zone It worked OK for the first 8 zones, but for the last one I got "connection refused", and in the kernel log (where I've already turned