Re: bind_dlz and views and samba

2024-05-16 Thread Petr Špaček
hould crash. This might be a bug in Samba DLZ module so I suggest to: 1. Write complete bug reports including all and exact version numbers 2. Add complete minimal configuration which demonstrates the issue 3. Take it to relevant Samba DLZ mailing list If there are bugs in BIND we will hav

Re: Add Tag for minor release version to official Docker images

2024-04-19 Thread Petr Špaček
://hub.docker.com/r/internetsystemsconsortium/bind9/tags I'm curious what is the motivation? Testing exploits on old versions or ...? It's lots of storage to provide copies of vulnerable versions. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users

Re: Crafting a NOTIFY message from the command line?

2024-03-20 Thread Petr Špaček
On 19. 03. 24 23:10, Anand Buddhdev wrote: You can try something like: dig +norec +opcode=notify soa @server As an alternative, script https://github.com/rthalley/dnspython/blob/main/examples/send_notify.py allows you to specify SOA serial in the NOTIFY message as well. Petr Špaček

Re: Update to 9.18 failed due to libuv

2024-03-04 Thread Petr Špaček
-for-bind-9 If you need to recompile I suggest submitting support request with your distributor, missing devel packages are a problem in their distribution. As a workaround you can enable the EPEL repo (I guess?). -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman

Re: Problem upgrading to 9.18 - important feature being removed

2024-03-01 Thread Petr Špaček
bly should, I missed that too. ARM has warning like this: https://bind9.readthedocs.io/en/v9.18.15/reference.html#namedconf-statement-auto-dnssec If you have a proposal to improve it I'm all ears. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-us

Re: Problem upgrading to 9.18 - important feature being removed

2024-03-01 Thread Petr Špaček
obviously. -- Petr Špaček Internet Systems Consortium P.S. My combinatorics is really really rusty, but I think that even if I got it wrong by two orders of decimal magnitude you get the idea. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the d

Re: Deprecated DSCP support

2024-02-29 Thread Petr Špaček
tack. We are hesitant to (re)introduce complexity and layering violations without rock solid use-case without existing alternatives. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of thi

Re: feature request for improving named-compilezone

2024-01-19 Thread Petr Špaček
tizens in DNS server it will "naturally" solve the problem you are having. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us

Re: DNSSec mess with SHA1

2023-12-15 Thread Petr Špaček
On 15. 12. 23 14:28, Scott Morizot wrote: On Fri, Dec 15, 2023 at 6:58 AM Petr Špaček <mailto:pspa...@isc.org>> wrote: Hello. It smells like a packaging issue to me. Stock BIND (not an obsolete Red Hat-Frankenstein version) should detect this condition and threat

Re: DNSSec mess with SHA1

2023-12-15 Thread Petr Špaček
it to Red Hat. HTH Petr Špaček Internet Systems Consortium On 15. 12. 23 13:21, Wolfgang Riedel wrote: Hello, To answer my own question, the following will work: shadowman-200.png Chapter 4. Using system-wide cryptographic policies Red Hat Enterprise Linux 8 | Red Hat Customer Portal <ht

Re: DNSSec mess with SHA1

2023-12-14 Thread Petr Špaček
FIPS mode is in play or not? ... and then we can get to diagnosing your issue. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at

Re: Deprecation notice for BIND 9: "resolver-nonbackoff-tries", "resolver-retry-interval"

2023-12-07 Thread Petr Špaček
On 07. 12. 23 22:12, Fred Morris wrote: I welcome birds of a feather. Need to define / refine the problem statement first. On 12/7/23 12:30 AM, Petr Špaček wrote: On 07. 12. 23 1:05, Fred Morris wrote: On Wed, 6 Dec 2023, Evan Hunt wrote: I say go ahead, if nothing else consider it a "s

Re: Deprecation notice for BIND 9: "resolver-nonbackoff-tries", "resolver-retry-interval"

2023-12-07 Thread Petr Špaček
mize using real (anonymized!) traffic provided to us by operators. Here's what we need: https://kb.isc.org/docs/collecting-client-queries-for-dns-server-testing If you want us to optimize for your use-case let's talk how we can get the data and replicate your setup! -- Petr Špaček Intern

Re: Is bind 9.18.19 a validating resolver to shield against CVE-2023-42119 ?

2023-10-02 Thread Petr Špaček
://lists.exim.org/lurker/message/20231001.165119.aa8c29f9.en.html [2] https://www.zerodayinitiative.com/advisories/ZDI-23-1473/ It's impossible to judge from the (lack of) details provided. Sorry! -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users

Re: inline-signing breaks nsdiff.

2023-10-02 Thread Petr Špaček
he problem. It will greatly help us to write automated test for it. Thank you for your time. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions.

Re: unresolvable pms.psc.gov, but google/cloudflare/unbound work

2023-09-19 Thread Petr Špaček
On 19. 09. 23 9:53, Ondřej Surý wrote: On 19. 9. 2023, at 9:25, Petr Špaček wrote: $ bin/dig/dig +short -p 12345 pms.psc.gov @127.0.0.1 $ bin/dig/dig +noall +comments -p 12345 pms.psc.gov @127.0.0.1 ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 45084 ;; fla

Re: unresolvable pms.psc.gov, but google/cloudflare/unbound work

2023-09-19 Thread Petr Špaček
IN A ;; ANSWER SECTION: pms.psc.gov.3600IN CNAME pms.ha.psc.gov. pms.ha.psc.gov. 30 IN A 156.40.178.24 ;; Query time: 1533 msec ;; SERVER: 127.0.0.111#53(127.0.0.111) (UDP) ;; WHEN: Tue Sep 19 09:23:58 CEST 2023 ;; MSG SIZE rcvd: 105 -- Pet

Re: consolidating in-addr.arpa data

2023-09-19 Thread Petr Špaček
ustom code and possibly nsdiff are in order as fallback when IXFR is not available. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions.

Re: Why are XFRs to Secondaries equally fast?

2023-07-27 Thread Petr Špaček
thedocs.io/en/latest/reference.html#namedconf-statement-transfers-in options for tuning. Consumption speed might be hampered by slow storage (zone journaling does lots and lots of fsync()s, at least when you test IXFR). -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman

Re: Best way to handle multiple retries from BIND?

2023-06-27 Thread Petr Špaček
. At that mark it starts to smell like slow lorris attack and the client might close the connection. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us

Re: AW: Tools to mesure performance and benchmarking of a DNS

2023-06-22 Thread Petr Špaček
impact on your benchmark. For details see https://www.usenix.org/legacy/event/nsdi06/tech/full_papers/schroeder/schroeder.pdf Good luck with benchmarking! Petr Špaček Internet Systems Consortium On 21. 06. 23 23:34, Klaus Darilion via bind-users wrote: There are several tools with different features

Re: "an error occurred while creating registry keys" - BIND 9 installer

2023-06-08 Thread Petr Špaček
Hello, let me remind everyone on this list that Windows support is going to end at the end of 2023: https://kb.isc.org/docs/supported-platforms Better to start looking for alternatives now. Petr Špaček On 07. 06. 23 21:07, Danny Mayer wrote: You need to be an administrator to do

Re: Documentation on readthedocs - links to older releases return 404 errors

2023-05-31 Thread Petr Špaček
ee if we can restore the old links, but I cannot promise any specific timeline. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc

Re: Is it possible to move a zone between catalogs on the same secondary? It is.

2023-05-02 Thread Petr Špaček
t be more resilient against race conditions when named is restarted? -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at ht

Re: Best practice MultiView

2023-04-20 Thread Petr Špaček
. Let me add one thing: Not having delegations is asking for problems _also_ because non-existence of a domain is/can be cached on several levels. When a client moves from external to internal view it might still "not see" the internal domains because of the cache. -- Petr Špače

Re: Is it possible to move a zone between catalogs on the same secondary?

2023-04-20 Thread Petr Špaček
the process is supposed to work. And yes, you can automate this with nsupdate to old and new catalog, just beware that you need to wait until the change is propagated to all secondaries before moving on. (AFAIK order of operations is important, do it exactly as specified.) HTH. Petr Špaček

Re: DNSSEC and forward zone

2023-04-19 Thread Petr Špaček
This confirms that NS record is missing. If there were NS record in ubi.pt zone the validator would have detected that the AD zone is not signed. To fix that just add the NS record and it should start working again. Petr Špaček On 19. 04. 23 12:42, David Carvalho wrote: Hello and thanks

Re: DNSSEC and forward zone

2023-04-19 Thread Petr Špaček
on the authoritative servers to not respond to queries from outside of your network. I hope it helps. Petr Špaček On 19. 04. 23 11:27, Darren Ankney wrote: Hi David, You can disable validation on one or more domains using "validate-except" - https://bind9.readthedocs.io

Re: BIND operating in Parental Agent role (according to RFC 7344)?

2023-04-12 Thread Petr Špaček
a DNS server should do. There are external tools which can automate zone scan, e.g. https://github.com/CZ-NIC/fred-cdnskey-scanner I suppose that it should be possible to glue it to standard DNS UPDATE mechanism and thus make it work with any standard DNS server. -- Petr Špaček -- Visit https

Re: Bind dns amplification attack

2023-03-28 Thread Petr Špaček
are indeed coming from your internal network and do not have spoofed source IP). Once you have confirmation the only thing left is to determine infected/misbehaving client machines and clean it up locally. Hopefully it helps a bit to narrow the area you have to search. -- Petr Špaček

Re: Resolve some hosts thats are dnssec signed differently

2023-02-08 Thread Petr Špaček
directly - that way you don't have to do anything in the DNS. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more

Re: Incremental transfers generate complete zone reloading

2023-01-16 Thread Petr Špaček
-- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org

Re: Incremental transfers generate complete zone reloading

2023-01-15 Thread Petr Špaček
tend", not the storage "backend". Second, map is deprecated in 9.16 and removed from 9.18 onward. In case you use it somewhere it's time to move on! HTH. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from t

Re: I need to find statistics on a running server.

2023-01-13 Thread Petr Špaček
And here is how you can configure it: https://bind9.readthedocs.io/en/v9_18_10/reference.html#namedconf-statement-statistics-channels HTH Petr Špaček On 12. 01. 23 21:31, Ondřej Surý wrote: It's generally better to pull the server statistics via statistics channel via XML or JSON that can

Re: DoT forwarding from BIND9

2022-12-15 Thread Petr Špaček
. (Also, if you hover your cursor over individual labels it will give you more wordy description of their meaning.) HTH. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscript

Re: TIL: Restricting DiG to UDP only with +ignore

2022-12-05 Thread Petr Špaček
n't know they had. If you have a specific proposal for docs we would be happy to improve the dig man page. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Conta

Re: forwarder cache

2022-11-30 Thread Petr Špaček
al test.com zone file required to start the server and we can have a look. (Recreating config from possibly incomplete or mis-formatted snippets in e-mails is a hassle.) -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the

Re: CH/TXT/VERSION.SERVER queries

2022-11-21 Thread Petr Špaček
if special magic for CH is removed and you are left with standard NSID? Petr Špaček On 14. 11. 22 17:39, Ondřej Surý wrote: Hi Anand, correct me if I am wrong, but the VERSION.SERVER doesn't seem to be anywhere documented[1], and you are the first one to request it[2]. 1. RFC 4892 only talks

Re: How to *require* TSIG for NOTIFY

2022-11-16 Thread Petr Špaček
ferent behavior please open feature request at https://gitlab.isc.org/isc-projects/bind9/-/issues/new . Thank you for your time. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid s

Re: Inconsistent Behavior with 'forward first'

2022-11-16 Thread Petr Špaček
or IPv6? Does the log say anything when it happens? If yes please send relevant log lines. If the answer to both questions is "no" then please send over PCAPs so we can see the query going in and also the query going out. Petr Špaček __CONFIGURATION FOR NS1 ON subdomainA (19

Re: Inconsistent Behavior with 'forward first'

2022-11-15 Thread Petr Špaček
{} and zone {} configuration for one of the zones which is giving you trouble. If your config has overlapping subtrees then please include all zone {} definitions from top down. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: automatic reverse and forwarding zones

2022-11-07 Thread Petr Špaček
. On 07.11.22 15:06, Petr Špaček wrote: Yes, that's exactly why plugin is needed. The plugin can generate answers on the fly without having all of them in memory. what about BIND receiving those records? I don't want my resolving DNS server to fill out cache by reverse records of any remote ipv6 range

Re: automatic reverse and forwarding zones

2022-11-07 Thread Petr Špaček
generate answers on the fly without having all of them in memory. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more

Re: dig +norecurse behaviour changed with 9.16.33

2022-10-27 Thread Petr Špaček
e in a private email ? I'm not Greg, but please don't e-mail us privately. https://blog.powerdns.com/2016/01/18/open-source-support-out-in-the-open/ applies here as well. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the develo

Re: procedure for re-signing zones on nsec3param change, when using dnssec-policy full automation?

2022-10-20 Thread Petr Špaček
. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users

Re: Question About Internal Recursive Resolvers

2022-10-18 Thread Petr Špaček
updated. ACLs can be applied on auths as needed to limit access to the "internal" zone from outside, but there is no technical reason why it cannot be delegated from public tree - and it will save you lots of headache. HTH. -- Petr Špaček -- Visit https://lists.isc.org/mailman/lis

Re: secure/tls access for statistics-channels ?

2022-10-18 Thread Petr Špaček
anyway - and then TLS is just overhead. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind

Re: Bind 9.16.33 startup problem

2022-10-04 Thread Petr Špaček
ls. (An alternative was to let the zone break silently later when updates are eventually allowed.) -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subsc

Re: Bind 9.16.28 upgrade: high memory utiization and OOM

2022-09-29 Thread Petr Špaček
: This particular configuration had "max-cache-size unlimited;" in named.conf. This causes, you have guessed it, an unlimited growth of memory usage, which is the purpose of this configuration. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: Fwd: Build errors for nsupdate 9.18.6

2022-09-29 Thread Petr Špaček
Hello. The log file you attached has answer around line 451. (Generally open the file and search for the error message - in this case "C compiler cannot create executables".) Seems like libraries from wrong architecture or something unexpected like that. -- Petr Špaček -- V

Re: Sparklight and DNSSEC

2022-09-26 Thread Petr Špaček
:-) -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list

Re: Sparklight and DNSSEC

2022-09-26 Thread Petr Špaček
enabling DNSSEC then at least 'dnssec-enabled yes; dnssec-validation no;' configuration would improve situation for people who care. -- Petr Špaček Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development

Re: DS keys with 2 digest algorithms

2022-09-21 Thread Petr Špaček
we cannot be sure without checking on the real domain name. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more in

Re: BIND 9.18.6 disables RSASHA1 at runtime?

2022-09-13 Thread Petr Špaček
ne with all disabled? Or one one with all enabled? What log level? Log category? It it okay it will be almost always logging GOST? ... So many questions to get log line covering < 2 % of all signed domains, which will be obsolete over time anyway (hopefully). -- Petr Špaček -- Visit https:/

Re: Question about dnstap

2022-09-13 Thread Petr Špaček
On 12. 09. 22 15:49, Peter wrote: On Mon, Sep 12, 2022 at 03:01:38PM +0200, Petr Špaček wrote: ! My testing did not uncover anything problematic. ! ! Versions: ! fstrm 0.6.1-1 ! protobuf 21.5-1 ! protobuf-c 1.4.1-1 ! ! ! A procedure which works: ! - start BIND configured with ! options

Re: Question about dnstap

2022-09-12 Thread Petr Špaček
be eliminated from the equation. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users maili

Re: Thread handling

2022-09-12 Thread Petr Špaček
other option. Yet another option might be _something else_ based on AXFR/nsupdate. I hope it helps. Petr Špaček Regards Hamid Maadani Original message From: Ondřej Surý Date: 8/24/22 02:32 (GMT-08:00) To: hamid Cc: ML BIND Users Subject: Re: Thread handling On 24. 8.

Re: DoH GET not working for me

2022-08-17 Thread Petr Špaček
it. Fix prepared by my colleague Artem is here: https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/6672 Please let us know in the merge request if there is any issue with it (or docs). -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: isc python module

2022-08-16 Thread Petr Špaček
sible module, I believe, so in that respect nothing has changed - use whatever third party software you were using before. The rndc protocol is not evolving at the moment, so it should be unlikely we break the compatibility in near future. Does it answer your question? -- Petr Špaček -- Visit

Re: isc python module

2022-08-16 Thread Petr Špaček
On 16. 08. 22 10:41, Petr Špaček wrote: On 16. 08. 22 9:36, BÖSCH Christian wrote: Hello, I have FreeBSD and the bind-tools 9.16.X package installed and I am using the python module "isc" included in it with ansible. Now when I tried to upgrade to bind-tools 9.18 pac

Re: isc python module

2022-08-16 Thread Petr Špaček
en/v9_18_5/notes.html#removed-features Besides other things it links to copy of the library, (which is formally not unsupported outside of BIND 9.16, to be clear). I hope it helps. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: DNSSEC signing of an internal zone gains nothing (unless??)

2022-08-04 Thread Petr Špaček
-krishnaswamy-dnsop-dnssec-split-view Keep in mind it is 15 years old, but it will give you an idea about various points of view. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support

Re: High memory consumption in bind 9.18.2

2022-07-26 Thread Petr Špaček
it was not verified. I did lots of testing and simply cannot reproduce it, so it might be not surprising I consider it a bad idea to extend our articles with information we cannot verify. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC

Re: 9.18 behavior change for mDNS queries with dig

2022-06-27 Thread Petr Špaček
lease open a bug report at https://gitlab.isc.org/isc-projects/bind9/-/issues, we'll look into it. Please don't forget to attach PCAP file produced by tcpdump or similar tool so we can see if anything happens on the wire or not. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/

Re: Parsing named.conf in PyParsing Python3 and JSON now available

2022-06-01 Thread Petr Špaček
etween versions etc. Feel free to approach me if you want to exchange ideas and code! -- Petr Špaček @ Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscri

Re: High memory consumption in bind 9.18.2

2022-05-19 Thread Petr Špaček
). I hope it helps. Petr Špaček Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. On 18. 5. 2022, at 22:32, Klaus Darilion via bind-users wrote: Can you please provide

Re: AW: High memory consumption in bind 9.18.2

2022-05-18 Thread Petr Špaček
. If you encounter it again please get back to us so we can diagnose it. Thank you! Petr Špaček On 18. 05. 22 8:56, Klaus Darilion via bind-users wrote: I remember we had similar issues with 9.18 (isc ppa packages) and hence wen't back to 9.16. But I can not remember the details. regards Klaus

Re: DNS traffic tracking

2022-05-09 Thread Petr Špaček
c, but that's about it. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-

Re: DNS traffic tracking

2022-05-09 Thread Petr Špaček
On 09. 05. 22 10:34, Alex K wrote: Hi Petr, On Mon, May 9, 2022 at 10:26 AM Petr Špaček <mailto:pspa...@isc.org>> wrote: On 06. 05. 22 17:02, Alex K wrote: > Hi all, > > I have the following problem: I run a caching dns server using bind9 > v9.10.

Re: Determining Which Authoritative Sever to Use (Bob McDonald)

2022-05-09 Thread Petr Špaček
I have to warn you: Authoritative server selection in DNS is not standardized, and thus it is not guaranteed to be stable even between BIND releases. If you need to make static and/or optimal routing then you need to reach into IP routing layer for that. Petr Špaček On 08. 05. 22 18:57

Re: DNS traffic tracking

2022-05-09 Thread Petr Špaček
are involved then I say "don't even try": All reasonable solutions will cause either overcharging or undercharging, which is not only objectionable but also possibly illegal. Out of curiosity, is the amount of traffic so large it is worth considering it? Compared to all the YouTube videos? :-)

Re: Transitioning to new algorithm for DNSSEC

2022-05-05 Thread Petr Špaček
-out-in-the-open/ -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-use

Re: success resolving xxx after disabling EDNS

2022-05-04 Thread Petr Špaček
. After all EDNS is from 1999 ... The name servers for this domain have more problems to fix as well: https://dnsviz.net/d/woinsta.com/YnJ6tQ/dnssec/?rr=all=all=all=on=.= Petr Špaček Cheers, Greg On Wed, 4 May 2022 at 13:13, Veronique Lefebure mailto:veronique.lefeb...@cern.ch>>

Re: getting answers from DNS queries

2022-05-03 Thread Petr Špaček
roblem with packet mirroring and parsing is that it is unusable for encrypted transports. For that very reason I think dnstap is the way to go. -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software wit

Re: Tuning Authoritative Memory Usage

2022-04-27 Thread Petr Špaček
e memory/InUse which will be significantly smaller than value seen by OS. In case the two values are close then you are seeing some other quirk and we need to dig deeper. Petr Špaček P.S. BIND 9.18 does not suffer from this, so I suggest you just upgrade and see. I can't seem to find any re

Re: Merging DNS servers

2022-04-27 Thread Petr Špaček
and only _then_ you can shutdown the old server. Pro tip: You can lower the TTLs before so it you do not need to wait that long when the shutdown event is due. Commands: $ rndc sync -clean $ rndc stop ... might be a good idea as well, I think. -- Petr Špaček -- Visit https://lists.isc.org/

Re: FIPS 140-3 mode on RHEL 9 and RSA validation of <2048 keys

2022-04-25 Thread Petr Špaček
h it makes sense to me to treat RSA keys with 512 bits as insecure. The threshold could go even higher... https://en.wikipedia.org/wiki/RSA_Factoring_Challenge -- Petr Špaček -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the d

Re: Problems building bind 9.18.1 on FreeBSD

2022-03-17 Thread Petr Špaček
On 17. 03. 22 10:02, Borja Marcos wrote: On 17 Mar 2022, at 08:59, Petr Špaček wrote: Hello, On 17. 03. 22 8:49, Borja Marcos wrote: Trying to compile bind 9.18.1 on FreeBSD I am stumbling upon a really silly problem. Getting plenty of errors like this building the man pages. building [man

Re: Problems building bind 9.18.1 on FreeBSD

2022-03-17 Thread Petr Špaček
tion. I wonder whether I am missing some needed package. Also, is it really necessary to complicate the generation of man pages to this extent? Depends on who you ask. There are people who like to have correct path names in the the man pages, and other group of people don't that much :shru

Re: about apply Deckard to test BIND named

2022-02-16 Thread Petr Špaček
/-/merge_requests/217/diffs?commit_id=aa70a23ca2dd04929d1425257322bcd55c661065 Enjoy testing BIND :-) Petr Špaček @ Internet Systems Consortium On 16. 2. 2022, at 9:59, Petr Špaček wrote: - It does not work anyway because jemalloc library used by libfaketime breaks libfaketime library is used

Re: about apply Deckard to test BIND named

2022-02-16 Thread Petr Špaček
/wolfcw/libfaketime/issues/130. So for now you are out of luck. Besides that other points raised by Ondrej below are valid. Petr Špaček @ Internet Systems Consortium On 16. 02. 22 9:04, Ondřej Surý wrote: Hi Sun, this is impressive effort, but it has several known gotchas: 1. The `named

Re: BIND 9.16.25 "file descriptor exceeds limit" messages

2022-02-01 Thread Petr Špaček
On 01. 02. 22 15:43, Anand Buddhdev wrote: On 01/02/2022 15:33, Petr Špaček wrote: Hi Petr, As you correctly noticed, the log message "adjusted limit on open files from 4096 to 1048576" already shows that BIND adjusted OS-level file descriptor limit. The only way out is what

Re: BIND 9.16.25 "file descriptor exceeds limit" messages

2022-02-01 Thread Petr Špaček
file. Am I mistaken? -- Petr Špaček @ Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.

Re: DNSSEC validation via AD bit?

2022-02-01 Thread Petr Špaček
. I hope it helps. -- Petr Špaček @ Internet Systems Consortium -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more informati

Re: BIND 9.16.25 "file descriptor exceeds limit" messages

2022-02-01 Thread Petr Špaček
ine to avoid hitting the fixed MAXSOCKETS limit, and leave -n (max sockets) unset, at its default. You can also set ISC_SOCKET_MAXSOCKETS at build time, if you can work out how to wrangle the build system :-) Or go for 9.18.0 which does not have this limit anymore. -- Petr Špaček @ Internet Systems

Re: AW: Problems with (unsigned) forward zones, dnssec-validation auto and validate-except on BIND 9.16 and 9.17

2022-01-27 Thread Petr Špaček
ms to have changed somewhere between 9.14 and 9.16... FTR it was introduced in 9.12.0, later disabled by default in 9.15.6, and reenabled by default in 9.17.21. -- Petr Špaček @ Internet Systems Consortium ___ Please visit https://lists.isc.org/mailma

Re: A good name for development branch releases package

2021-12-01 Thread Petr Špaček
If you don't like nginx naming, then what about Linux kernel naming: bind-next (similarly linux-next)? Petr Špaček On 01. 12. 21 13:07, pemensik at redhat.com (Petr Menšík) wrote: Mainline seems strange term to me. I think it should be used also by ISC to identify that major version. When I