Missing n in man page for rndc(8)?

2022-05-03 Thread Larry Rosenman
:( Where should I report this? Or is here sufficient? -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l...@lerctr.org US Mail: 5708 Sabbia Dr, Round Rock, TX 78665-2106 -- Visit https://lists.isc.org/mailman/listinfo/bind-users

Re: DNSSEC: Why aren't the old keys going hidden?

2022-05-01 Thread Larry Rosenman
id [-alg algorithm]] [-when time] published | withdraw)) zone [class [view]] s/withdraw/withdrawn/ withdraw garners a syntax error :( Thanks for the inbound clue-by-four. -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l

DNSSEC: Why aren't the old keys going hidden?

2022-05-01 Thread Larry Rosenman
I have 2 domains where I switched from Alg 8 to Alg 13, but the old keys don't seem to be going away. Attached are the state files, and the rndc dnssec -status outputs. Ideas? -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l

Re: DNSSEC

2022-04-25 Thread Larry Rosenman
nt-ds-ttl 3600; parent-propagation-delay 300; nsec3param iterations 0 salt-length 0; }; If I can help, let me know. -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l...@lerctr.org US Mail: 5708 Sabbia Dr, Round Rock,

Re: Reading secondary PTR files

2022-04-20 Thread Larry Rosenman
Technology Shared Services The University of Tennessee 103c5 Kingston Pike Building 2309 Kingston Pk. Knoxville, TN 37996 Phone: 974-1599 -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l...@lerctr.org US Mail: 5708 Sabbia Dr, Round

Re: Why does DNSVIZ complain about the NS RRSET here?

2022-04-18 Thread Larry Rosenman
Query time: 217 msec ;; SERVER: 216.82.192.149#53(pdns06.thin-nology.com) (UDP) ;; WHEN: Tue Apr 19 07:55:29 AEST 2022 ;; MSG SIZE rcvd: 452 % [snip] -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l...@lerctr.org US Mail: 5708 Sab

Why does DNSVIZ complain about the NS RRSET here?

2022-04-16 Thread Larry Rosenman
.ip6.arpa. [omitted] ;; Query time: 676 msec ;; SERVER: 1.0.0.1#53(1.0.0.1) ;; WHEN: Sat Apr 16 09:52:06 CDT 2022 ;; MSG SIZE rcvd: 414 -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l...@lerctr.org US Mail: 5708 Sabbia Dr, Round Rock

Re: dnssec: ds showing hidden 3+ days after key roll

2022-02-10 Thread Larry Rosenman via bind-users
! Is that little nuance documented? (The need for KSK and ZSK to be aligned on type of key) -- Larry Rosenman http://www.lerctr.org/~ler Phone: +1 214-642-9640 E-Mail: l...@lerctr.org US Mail: 5708 Sabbia Dr, Round Rock, TX 78665-2106 -- Visit https://lists.isc.org/mailman

Re: dnssec: ds showing hidden 3+ days after key roll

2022-02-10 Thread Larry Rosenman
Matthijs Mekking wrote: Hi Larry, There has been several bug fixes for dnssec-policy since its introduction. What version of 9.17 are you running? I can't tell what causes the ds to stay in the hidden state. The timings in the state file should allow it to move to the next state. If you were a

dnssec: ds showing hidden 3+ days after key roll

2022-02-08 Thread Larry Rosenman
- dnskey: omnipresent - ds: hidden - key rrsig: omnipresent ler in thebighonker in namedb on  master [!] as 慄 ❯ Is it normal to see the ds as hidden? It IS published, and I told rndc that. Any insight appreciated. -- Larry Rosenman http