Domain no longer fully secure after move

2022-12-14 Thread Sandro
Hi, I'm trying to understand what exactly is wrong with DNSSEC for my domain, penguinpee.nl, before contacting involved parties. I recently (last weekend) moved the domain to a new registrar. The keys are now managed by the registrar directly. At least I don't see an option providing my own

Re: DoT forwarding from BIND9

2022-12-14 Thread Petr Menšík
Hi Vicky. Excellent, thank you for the issue link. Is backport to 9.18 decided already? Would it appear on minor updates in 9.18.x line? I see comment it needs some missing feature. Is that temporary issue or already decided? It seems to be important prerequisite for Zero Trust initiative

Re: DoT forwarding from BIND9

2022-12-14 Thread Victoria Risk
> On Dec 14, 2022, at 10:12 AM, Petr Menšík wrote: > > Hello, > > I tried to find a way how to configure queries forwarding over encrypted > channel. But unlike zone transfer and notifications, I have not found a way > to configure query forwarding over DNS over TLS even in latest 9.18.9

DoT forwarding from BIND9

2022-12-14 Thread Petr Menšík
Hello, I tried to find a way how to configure queries forwarding over encrypted channel. But unlike zone transfer and notifications, I have not found a way to configure query forwarding over DNS over TLS even in latest 9.18.9 version. Have I looked wrong? Is there some important limit why

Re: dig +norecurse behaviour changed with 9.16.33

2022-12-14 Thread Ondřej Surý
I think it would be useful if you read the documentation on the feature before we continue this thread. Guessing what the feature is or isn’t does not help helpful discussion.8. Configuration Reference — BIND 9 9.18.9 documentationbind9.readthedocs.ioThanks,--Ondřej Surý — ISC (He/Him)My working

Re: dig +norecurse behaviour changed with 9.16.33

2022-12-14 Thread Veronique Lefebure
Hi Ondrej, Thanks for your reply (and sorry for the delay on this on my side). Yes, I am aware of the new default for the `minimal-responses` option: we have set it to "no". But anyway, if I am not wrong, the minimal-response option controls whether or not the NS records are returned, right ?