Problem with DDNS update to BIND 9.16.27 from ISC DHCPv6

2022-06-07 Thread Mirsad Goran Todorovac
Hello all, I have a problem that my DHCPv6 DDNS update which works reliably with IPv4 doesn't work at all when we implemented the dual-stack operation. There is not even a warning, notice or error in the log. No syntax errors in the config /etc/dhcp/dhcpd6.conf file. We are running Debian 10

DHCPv6 DDNS update problem

2022-06-07 Thread Mirsad Goran Todorovac
Hello all, I have a problem that my DHCPv6 DDNS update which works reliably with IPv4 doesn't work at all when we implemented the dual-stack operation. There is not even a warning, notice or error in the log. No syntax errors in the config /etc/dhcp/dhcpd6.conf file. We are running Debian 10

Re: DNSSEC transition from manually signed zone to dnssec-policy "standard" failed

2022-06-05 Thread Mirsad Goran Todorovac
. It would prevent people from using Internet on all of our locations. Windows 10 just doesn't know how to use the second nameserver in DHCP list, if first is not performing well. The system became unusable campus-wide ... Mirsad On 6/4/2022 12:36 PM, Bjørn Mork wrote: Mirsad Goran Todorovac

Re: DNSSEC transition from manually signed zone to dnssec-policy "standard" failed

2022-06-03 Thread Mirsad Goran Todorovac
stfromrdataset: error reading /var/cache/bind/keys/Kalu.hr.+013+43987.private: file not found Hope these pointers help. - Matthijs On 01-06-2022 23:14, Mirsad Goran Todorovac wrote: Dear All, I have tried to switch from manually signed DNSSEC zone to dnssec-policy "standard", and

DNSSEC transition from manually signed zone to dnssec-policy "standard" failed

2022-06-01 Thread Mirsad Goran Todorovac
Dear All, I have tried to switch from manually signed DNSSEC zone to dnssec-policy "standard", and BIND9 server started behaving odd. Here is the manual signing conf: include "/etc/bind/keys/domac.alu.hr-tsig.key"; zone "alu.hr" in {     type master;     file

Re: BIND9 TSIG from Windows Server 2016 DNS Server Zone

2022-05-27 Thread Mirsad Goran Todorovac
, which of course is not much security at all. I've never had luck getting AD admins to offer anything better. I'm definitely no AD expert myself. One possibility of course is to secure at the IP layer, a.k.a. IPsec. You could secure all traffic between the servers with transport mode AH. Th

BIND9 TSIG from Windows Server 2016 DNS Server Zone

2022-05-25 Thread Mirsad Goran Todorovac
documented features, but right now I am presented with a problem I can't seem to solve because it is not an open system. Thanks for any help. Kind regards, Mirsad Todorovac -- Mirsad Goran Todorovac CARNet sistem inženjer Grafički fakultet | Akademija likovnih umjetnosti Sveučilište u Zagrebu -- CAR

BIND9 TSIG from Windows Server 2016 DNS Server Zone

2022-05-25 Thread Mirsad Goran Todorovac
documented features, but right now I am presented with a problem I can't seem to solve because it is not an open system. Thanks for any help. Kind regards, Mirsad Todorovac -- Mirsad Goran Todorovac CARNet sistem inženjer Grafički fakultet | Akademija likovnih umjetnosti Sveučilište u Zagrebu -- CAR

BIND9 TSIG from Windows Server 2016 DNS Server Zone

2022-05-25 Thread Mirsad Goran Todorovac
documented features, but right now I am presented with a problem I can't seem to solve because it is not an open system. Thanks for any help. Kind regards, Mirsad Todorovac -- Mirsad Goran Todorovac CARNet sistem inženjer Grafički fakultet | Akademija likovnih umjetnosti Sveučilište u Zagrebu -- CAR

DNSSEC problem with our zone

2022-05-18 Thread Mirsad Goran Todorovac
2giVp04ZC0agS+rPaCQZgeUXuneUk 5wle1qc5GF+R3E8rheTioWPJLw+L2V/n39LYOlQ= ) ;; Query time: 189 usec ;; SERVER: 161.53.235.3#53(161.53.235.3) ;; WHEN: Wed May 18 17:34:31 CEST 2022 ;; MSG SIZE  rcvd: 251 root@domac:/var/cache/bind# Can you please help? Thank you very much. Kind regards, Mirsad On

Re: Spurious failures in a dynamically updated to a sub /24 reverse DNS domain P.S.

2021-12-30 Thread Mirsad Goran Todorovac
hostnames and report a problem globally. Kind regards, Mirsad On 12/30/2021 12:43 AM, Tony Finch wrote: Mirsad Goran Todorovac wrote: Please excuse me, as I am a bit confused ... I have tried to verify your findings, but I've found something awkward: Something has changed, because ear

Re: Spurious failures in a dynamically updated to a sub /24 reverse DNS domain P.S.

2021-12-29 Thread Mirsad Goran Todorovac
that the delegation of the 192/27.186.198.193.in-addr.arpa is in the zone 186.198.193.in-addr.arpa? Moment ago it was all so clear to me, but now it seems hieroglyphic again :-( Any idea? Thank you ... Kind regards, Mirsad On 12/29/2021 6:57 PM, Tony Finch wrote: Mirsad Goran Todorovac wrote

Re: Spurious failures in a dynamically updated to a sub /24 reverse DNS domain

2021-12-29 Thread Mirsad Goran Todorovac
On 12/29/2021 6:57 PM, Tony Finch wrote: Mirsad Goran Todorovac wrote: I have recently implemented dynamic updates to a sub /24 reverse DNS domain, 193.198.186.192/27. I had upstream domain 192/27.186.198.193.in-addr.arpa. delegated from authoritative servers. However, something still isn't

Spurious failures in a dynamically updated to a sub /24 reverse DNS domain

2021-12-28 Thread Mirsad Goran Todorovac
Hello, I have recently implemented dynamic updates to a sub /24 reverse DNS domain, 193.198.186.192/27. I had upstream domain 192/27.186.198.193.in-addr.arpa. delegated from authoritative servers. However, something still isn't right. In some reverse PTR addresses, the resolver sees first

Re: BIND9: one zone is not up to date

2021-12-13 Thread Mirsad Goran Todorovac
Dear Roberto, It is hard to say without seeing the named.conf.local, but are you sure you have incremented the serial? Kind regards, Mirsad On 12/13/2021 7:24 PM, Roberto Carna wrote: Dear all, I have BIND 9 and Webmin. One master and one slave using zne ransfer with TSIG Everything was Ok

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet P.S.

2021-12-13 Thread Mirsad Goran Todorovac
c ;; SERVER: 2001:b68:c:2::70:0#53(2001:b68:c:2::70:0) ;; WHEN: Sun Dec 12 22:06:50 PST 2021 ;; MSG SIZE  rcvd: 88 On 2021-12-12 06:45, Mirsad Goran Todorovac wrote: Hello Crist, I have implemented the recommended changes. It works forward and reverse for the test record, from out doma

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet P.S.

2021-12-13 Thread Mirsad Goran Todorovac
the name resolution is more stable with the secondary (slave) servers for the zone. Kind regards, Mirsad Todorovac On 13.12.2021. 9:25, Mirsad Goran Todorovac wrote: Hello Crist, The good news is that it seems that the dynamic DDNS update from DHCP works! See here a snap from /var/log/syslog: Dec

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet P.S.

2021-12-13 Thread Mirsad Goran Todorovac
PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ; COOKIE: 341626673209a23b4777d39761b6e2f9656e01a40d454dcd (good) ;; QUESTION SECTION: ;192/27.186.198.193.in-addr.arpa. IN    NS ;; Query time: 181 msec ;; SERVER: 2001:b68:c:2::70:0#53(2001:b68:c:2::70:0) ;; WHEN: Sun Dec 12 22:06:50 PST 2021 ;; MSG

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet P.S.

2021-12-12 Thread Mirsad Goran Todorovac
with DHCP DDNS updates. :-) You said ABSOLUTELY NO WARRANTY but I am an open source fan and I can live with that ;-) Until tomorrow, then ... Kind regards, Mirsad Todorovac On 12/12/2021 10:33 AM, Mirsad Goran Todorovac wrote: Hi Crist, Now the resolution from the problematic record started

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet P.S.

2021-12-12 Thread Mirsad Goran Todorovac
if something becomes virus infected or even spambot, and not have to browse DHCP leases in forensic analysis, which my fellow administrator probably would not know how to do ... Kind regards, Mirsad Todorovac On 12/12/2021 10:19 AM, Mirsad Goran Todorovac wrote: Hi Crist, Thank you for your

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet

2021-12-12 Thread Mirsad Goran Todorovac
86.198.193.in-addr.arpa to test-record.slava.alu.hr <http://test-record.slava.alu.hr>. and resolving 193.198.186.195 that apparently fails? Is there a way to see more interim debugging output? Thank you very much. Kind regards, Mirsad Todorovac On 12/11/2021 10:25 AM, M

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet

2021-12-11 Thread Mirsad Goran Todorovac
ORIGIN 192-27.186.198.193.in-addr.arpa. 193  IN CNAME 193.186.198.193.rev.example.com <http://193.186.198.193.rev.example.com>. 194  IN CNAME 194.186.198.193.rev.example.com <http://194.186.198.193.rev.example.com>. … On Fri, Dec 10, 2021 at 2:51 PM Mirsad Goran Todorovac wrote: Hello,

Re: ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet

2021-12-11 Thread Mirsad Goran Todorovac
186.198.193.rev.example.com <http://193.186.198.193.rev.example.com>. 194  IN CNAME 194.186.198.193.rev.example.com <http://194.186.198.193.rev.example.com>. … On Fri, Dec 10, 2021 at 2:51 PM Mirsad Goran Todorovac wrote: Hello, I have a problem with DHCP DDNS update to BIND 9 re

ISC-DHCP and BIND 9 DNS: DDNS update fails for /27 subnet

2021-12-10 Thread Mirsad Goran Todorovac
max-lease-time 86400; } | Thank you very much for your time reading this mail and help. Kind regards, -- Mirsad Goran Todorovac Academy of Fine Arts | Faculty of Graphic Arts University of Zagreb | ___ Please visit https://lists.isc.org/mailman/l