Re: High memory consumption in bind 9.18.2

2022-07-25 Thread Ondřej Surý
for free buffet where you come and just take. And don’t be mistaken - I was not helping you specifically, I was just disputing your claim that BIND 9.18 takes more memory than 9.16 because that claim didn’t match our own measurements. Have a nice day, -- Ondřej Surý — ISC (He/Him) My working

Re: Basic setup instructions

2022-07-25 Thread Ondřej Surý
macOS 10.10 reach end-of-life 5 years ago. You can try installing recent enough compiler with C11/C17 support and up-to-date libraries, but you are mostly on your own. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated

Re: Basic setup instructions

2022-07-25 Thread Ondřej Surý
Sorry, but you are being too terse. What is DNS setup? Which website? What *exactly* are you doing? Would you be able to help yourself with such little information you gave us? Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel

Re: High memory consumption in bind 9.18.2

2022-07-25 Thread Ondřej Surý
There’s no generic tool. The one that was mentioned in the article was tailored for that specific bug in jemalloc. In any case, the article is only tangential to the topic here. It talks about a issue in the jemalloc that was triggered by a specific code in named. Ondřej -- Ondřej Surý — ISC

Re: CNAME resolution weirdness

2022-07-25 Thread Ondřej Surý
if it sees truncation. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 26. 7. 2022, at 1:02, Boian Bonev via bind-users > wrote: > > Hello, > > For the Dev

Re: How to make SRV records work with caching resolvers?

2022-07-14 Thread Ondřej Surý
Could you for the purpose of the debugging share the DNS traffic between the phone device and the resolver? I think stepping back a little might help debug the issue. Perhaps people on the list might notice something that might help. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours

Re: High memory consumption in bind 9.18.2

2022-07-21 Thread Ondřej Surý
some memory as compared to the default system allocator 2. our expectations are to go even lower during the 9.19/9.20 development cycle, but no promises yet Cheers, -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated

Re: Bind and systemd-resolved

2022-04-18 Thread Ondřej Surý
r defaults for dig via ${HOME}/.digrc. This file is read and any options in it are applied before the command line arguments. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.

Re: Hell breaks loose in the afternoon with format error from X.X.X.X#53 resolving ./NS: non-improving referral

2022-05-06 Thread Ondřej Surý
articular issue. They were crippling the TTL to 0 in the wrong direction. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman/listinfo/b

Re: Hell breaks loose in the afternoon with format error from X.X.X.X#53 resolving ./NS: non-improving referral

2022-05-06 Thread Ondřej Surý
lly go with VPN as a first option. Other than that this is classical example of GIGO (garbage in, garbage out). Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https:

Re: Tuning Authoritative Memory Usage

2022-04-28 Thread Ondřej Surý
From top of my head - try setting the max-cache-size to infinite. The internal views might still pre-allocate some stuff based on available memory. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply

Re: Tuning Authoritative Memory Usage

2022-04-28 Thread Ondřej Surý
Pull the memory stats from the statschannel (json or xml). Also make sure you run 9.18 with jemalloc (you can use jemalloc with 9.16, but it needs to be linked explicitly with LDFLAGS or pre-loaded). Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different

Re: Attempting to configure an ISC BIND repository on Red Hat Linux 7.9

2022-04-28 Thread Ondřej Surý
I am actually thinking the similar thing that the COPR is being filtered from where you are. Try gnutls-cli to connect to the site whether it gives you the correct cert and everything. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do

Re: getting answers from DNS queries

2022-05-03 Thread Ondřej Surý
toring software. Also monitoring DNS traffic on the mirror doesn’t tell you anything **how** the DNS server sees the queries, so dnstap is going to be better solution for most deployments. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Ple

Re: Unrecognized Options --enable-threads

2022-05-03 Thread Ondřej Surý
atsoever. Modern systems are usually managed by using software from packages. However, the broad topic of system administration is out of topic for this list. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outs

Re: success resolving xxx after disabling EDNS

2022-05-04 Thread Ondřej Surý
t people should not write their own DNS server if they can’t implement it properly, but hey that’s what we have on the Internet now... Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your

Re: success resolving xxx after disabling EDNS

2022-05-09 Thread Ondřej Surý
as EDNS Can **you** tell if the problem why the server didn’t respond was IPv6 and not EDNS over IPv6? It’s impossible to tell whether the IPv4 and IPv6 addresses are handled on the same machine not to mention same software. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your

Re: DNSSEC signing of an internal zone gains nothing (unless??)

2022-08-01 Thread Ondřej Surý
to secondaries, or provided by a secure signing system, etc… Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 1. 8. 2022, at 18:40, John W. Blue via bind-users >

Re: High memory consumption in bind 9.18.2

2022-08-01 Thread Ondřej Surý
-> configure -> > make -> make install. All default values. I’ll try that. I have a custom script that tweaks some values (you can see that in the log snippets I sent). Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not

Re: High memory consumption in bind 9.18.2

2022-08-01 Thread Ondřej Surý
see a lower memory usage with 9.18+. But I see a common pattern here. I think both you and the OP were using CentOS/RHEL 7 which is using GCC 4.8. GCC was improved significantly since then. I would suggest to repeat the experiment on RHEL 9 if you can reproduce the same results. Ondrej -- Ondř

Re: High memory consumption in bind 9.18.2

2022-08-01 Thread Ondřej Surý
ocated in named, or is this allocated in the libraries? > Should the memory reduction apply to our experiment? The question doesn’t really make sense. We have not measured any increase in our test scenarios, which doesn’t mean you can’t find different scenarios with a memory increase. Ondrej -- Ondřej

Re: High memory consumption in bind 9.18.2

2022-08-01 Thread Ondřej Surý
vailable at https://www.isc.org/support 01-Aug-2022 22:09:59.363 01-Aug-2022 22:09:59.363 found 8 CPUs, using 8 worker threads 01-Aug-2022 22:09:59.363 using 8 UDP listeners per interface Swap:488612 USS:29592668 PSS:29593610 RSS:29596988 Ondrej -- Ond

Re: Bind 9.11/RHEL7 Server Freezes FUTEX_WAKE_PRIVATE

2022-08-02 Thread Ondřej Surý
than anything else. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 2. 8. 2022, at 0:29, Grant Taylor via bind-users > wrote: > On 8/1/22 4:21 PM, Greg Ch

Re: address/prefix length mismatch

2022-08-24 Thread Ondřej Surý
intention and whether it’s a typo in the network or in the bits - did the origin author meant 10.10.0.0-10.10.1.255 or 10.20.1.0-10.10.1.255 or something completely else (like 10.10.1.0-10.10.2.255 based on wrong assumption?) -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may

Re: BIND >= 9.18, jemalloc and EL7

2022-08-25 Thread Ondřej Surý
ultimately your decision It's little bit similar with libuv - you will be better running with latest upstream release, but you can get away with older versions too. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated

Re: Move from Development to Production

2022-08-26 Thread Ondřej Surý
First of all, the latest published version is 9.18.6, so why would you use a version that's ~two months old? Second, ISC does publish packages for EPEL, it's all listed here: https://www.isc.org/download/ <https://www.isc.org/download/> (the COPR link), so you can use that. -- Ondřej Su

Re: Intermittent v9.18 build fails on Fedora COPR buildsys, always in `netmgr_test` ?

2022-08-29 Thread Ondřej Surý
The netmgr unit tests are not meant to run fully in the CI as some of it are time sensitive. You might want to set the CI=true environment variable to reduce the set of the netmgr unit tests to just the more reliable subset. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your

Re: Intermittent v9.18 build fails on Fedora COPR buildsys, always in `netmgr_test` ?

2022-08-29 Thread Ondřej Surý
Then run only the system tests by running make check only in the bin/tests/system directory instead of the top level. Or don’t run the tests at all - these are mostly meant for development purposes where we have better control over the build environment. Ondřej -- Ondřej Surý — ISC (He/Him

Re: Thread handling

2022-08-24 Thread Ondřej Surý
y advantage from shared cache will be lost because the extra latency caused by communication with the MongoDB (or any other no-sql systems). Perhaps, describing the use case first (why do you want to use MongoDB at all) might have the benefit of not wasting time on your end. Ondrej -- Ondřej Surý

Re: Thread handling

2022-08-24 Thread Ondřej Surý
pdated with nsupdate works reasonably well in smaller deployments. Cheers, Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > Regards > Hamid Maadani > > &g

Re: address/prefix length mismatch

2022-08-24 Thread Ondřej Surý
at’s wrong. 10.60.0.0/23 means 10.60.0.0 to 10.60.1.255 range. > How do I configure this ACL in named.conf.local so that it takes the whole > range? Correctly specified range (without address/host bits) does takes the whole range. Ondrej -- Ondřej Surý — ISC (He/Him) My working ho

Re: address/prefix length mismatch

2022-08-24 Thread Ondřej Surý
ve already answered that, I would be just repeating their answers. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On Wed, Aug 24, 2022 at 10:33 AM Ondřej

Re: Bind 9.16.28 upgrade: high memory utiization and OOM

2022-09-27 Thread Ondřej Surý
should be collected in the newly created GitLab issue. Thanks, Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27. 9. 2022, at 16:09, Prasanna Mathivanan (pmath

Re: FORMERR responses after upgrading resolver from 9.16 to 9.18.8

2022-10-21 Thread Ondřej Surý
What you are really saying that we should dance how tech giants whistle, and I don’t think succumbing to tech giants is a good strategy long term. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your

Re: FORMERR responses after upgrading resolver from 9.16 to 9.18.8

2022-10-21 Thread Ondřej Surý
as well as to the code. The documentation is equally important as correct code, and we are not operator ourselves, so we might miss few things. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your

Re: FORMERR responses after upgrading resolver from 9.16 to 9.18.8

2022-10-20 Thread Ondřej Surý
https://bind9.readthedocs.io/en/v9_18_8/chapter9.html?highlight=cookie -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 20. 10. 2022, at 13:49, Andreas S. Kerber wr

Re: FORMERR responses after upgrading resolver from 9.16 to 9.18.8

2022-10-20 Thread Ondřej Surý
all EDNS0 incompatible servers and loosing customers to 8.8.8.8 > - which is able to resolve these names.. This is kind of moot argument - the DNS needs to evolve, and it can't evolve if we keep supporting broken stuff. This needs to be fixed on the authoritative operator side, not in BIND 9

Re: dig +norecurse behaviour changed with 9.16.33

2022-10-26 Thread Ondřej Surý
You need to be more specific with real examples. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 26. 10. 2022, at 17:41, Veronique Lefebure > wrote: >

Re: dig +norecurse behaviour changed with 9.16.33

2022-10-26 Thread Ondřej Surý
Or cache snooping behaves differently between two (or multiple) queries. That’s why questions like this should not imply where the problem is but rather describe what can be seen (possibly also on the wire). Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may

Re: automatic reverse and forwarding zones

2022-10-28 Thread Ondřej Surý
with other items with more priority. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27. 10. 2022, at 10:12, Matus UHLAR - fantomas wrote: > >  >> >>

Re: Installing bind on Windows 10

2022-09-09 Thread Ondřej Surý
No, the tools and named use the same internal libraries, so it doesn’t help to have “just tools”. You can keep using the last version of dig.exe, nobody can take this from you. It’s very unlikely that there will be serious security vulnerability (RCE) in dig. Ondřej -- Ondřej Surý — ISC (He

Re: TTL is varying across nameservers

2022-09-25 Thread Ondřej Surý
might always be inconsistent between the queries. But same thing can in theory happen even on same server. The cached entry might get evicted from cache either by memory pressure or by administrator. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please

Re: BINd9 Server for Public Website

2022-09-23 Thread Ondřej Surý
ingful advice. Please don't do that. Cheers, -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 23. 9. 2022, at 15:17, JAHANZAIB SYED wrote: > > > I am

Re: Dig -x +trace?

2022-10-03 Thread Ondřej Surý
ase tone down on the snarkiness. I get it that you might be frustrated, but this mailing list is not a place to vent off your frustration.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.O

Re: new dnssec zone OK, error "zone_rekey:dns_zone_getdnsseckeys failed: not found" only in local bind logs ?

2022-10-14 Thread Ondřej Surý
e user that named runs under and try changing to the directory and checking if you can access the files. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 14. 10. 20

Re: BIND 9.18.6 disables RSASHA1 at runtime?

2022-09-05 Thread Ondřej Surý
Petr, care to prepare a MR for this? After all, it's RedHat who is making us all to go through this mess. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 5

Re: DNSSEC adoption

2022-08-03 Thread Ondřej Surý
Not really. Using ECDSA (or EdDSA) CSK is pretty lightweight even during rollover. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 3. 8. 2022, at 19:10, Peter wr

Re: High memory consumption in bind 9.18.2

2022-08-02 Thread Ondřej Surý
. We are refactoring the database for storing the resource records in 9.20 and it's probably better spent time to work on the refactoring than look at this. As usual, we would accept any well commented and well thought patches. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working

Re: High memory consumption in bind 9.18.2

2022-08-02 Thread Ondřej Surý
I don’t see jemalloc anywhere in your setup scripts. Preferably use the latest upstream jemalloc version available. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > O

Re: High memory consumption in bind 9.18.2

2022-08-04 Thread Ondřej Surý
What Emmanuel said… -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 4. 8. 2022, at 19:15, Emmanuel Fusté wrote: > > Le 04/08/2022 à 17:48, Dmitri Pavlov a écrit >

Re: High memory consumption in bind 9.18.2

2022-08-01 Thread Ondřej Surý
> On 1. 8. 2022, at 16:14, Doug Whitfield wrote: > > as monitored from "top" RES value Please read the whole thread on measuring the real consumed memory. The '“top” RES value' has little or no value at all. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hou

Re: Troubleshooting scripted named startup

2022-12-27 Thread Ondřej Surý
Hi,running latest upstream version first might save you some time, it’s this:named can create unrecoverable managed-keys.jnl file (#2895) · Issues · ISC Open Source Projects / BIND · GitLabgitlab.isc.orgOndrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different

Deprecation notice for BIND 9.18: Differentiated Services Code Point (DSCP) support

2023-01-05 Thread Ondřej Surý
as whole: - `dscp` We plan to mark the options as deprecated in BIND 9.16 and 9.18 and remove it in BIND 9.20 because it's already non-operational. Cheers, -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside

Deprecation notice force BIND 9.20+: source port(s)

2023-01-04 Thread Ondřej Surý
the warning in BIND 9.18 to notify users that skip versions. 3. BIND 9.22 will be release in early 2026 Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https

Re: I need to find statistics on a running server.

2023-01-12 Thread Ondřej Surý
It's generally better to pull the server statistics via statistics channel via XML or JSON that can be directly parsed by many commonly available libraries and tools. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel

Re: managed-keys vs trust-anchors

2023-01-02 Thread Ondřej Surý
Hi Bob, no manually configured bind.keys file is needed. Just don't provide one and correct compiled-in defaults will be used. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal

Re: Records "not" too long fails with "ran out of space"

2022-12-27 Thread Ondřej Surý
, your 243 is actually 244 (first label also have to have length) + 4 (rpz) + 6 (local) + 1 (root) is exactly 255. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27.

Re: Bind 9.16.1 crash

2022-12-07 Thread Ondřej Surý
> On 8. 12. 2022, at 7:57, Ben Bridges wrote: > > When you say “ISC packages”, are you referring to the packages in the > ppa:isc/bind repository on launchpad? Yes, you can find the links here: https://www.isc.org/download/ Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My w

Re: Bind 9.16.1 crash

2022-12-07 Thread Ondřej Surý
general recommendation would be to go straight to latest 9.18.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.On 8. 12. 2022, at 1:03, Ben Bridges wrote: According

Re: Domain no longer fully secure after move

2022-12-16 Thread Ondřej Surý
he DS record when you move between registrars. I don't know if this is the case with .nl, but I just know that it might happen. Cheers, -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal worki

Re: Behavior of port tag in options clause is ambiguous

2022-12-15 Thread Ondřej Surý
the full range if possible. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 16. 12. 2022, at 7:26, Vikas Sharma wrote: > >  > Hi Team, > >

Re: plugin_version

2022-12-15 Thread Ondřej Surý
BIND 9 version. I am open to any suggestions, but I think the having a GitLab issue would be a better venue to record any ideas around the plugin system. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply

Re: plugin_version

2022-12-15 Thread Ondřej Surý
with any new feature.) Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 15. 12. 2022, at 20:10, Marcus Kool wrote: > >  > Hi, > > I have written

Re: dig +norecurse behaviour changed with 9.16.33

2022-12-14 Thread Ondřej Surý
I think it would be useful if you read the documentation on the feature before we continue this thread. Guessing what the feature is or isn’t does not help helpful discussion.8. Configuration Reference — BIND 9 9.18.9 documentationbind9.readthedocs.ioThanks,--Ondřej Surý — ISC (He/Him)My working

Re: PowerDNS secondary servers receive empty SOA response for particular zone. Truncation issue?

2022-11-17 Thread Ondřej Surý
The default EDNS0 buffer size has changed to 1232, how big is the response when you use dig? Perhaps increasing the edns buffer sizes would be a way out? Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply

Re: DF-Flag on UDP-based sockets?

2022-11-30 Thread Ondřej Surý
> On 30. 11. 2022, at 11:03, Tom wrote: > > Does someone of ISC agree? If so, I'll file a bug. Please do. A MR or patch would be even better ;-) Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated

Re: forwarder cache

2022-11-30 Thread Ondřej Surý
and the client in the lab. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 30. 11. 2022, at 20:00, Hamid Maadani wrote: > >  > > > Weird. Please sen

Re: forwarder cache

2022-12-01 Thread Ondřej Surý
;; AUTHORITY SECTION: example.nil.3600IN NS example.nil. ;; Query time: 0 msec ;; SERVER: 10.53.0.1#5300(10.53.0.1) (UDP) ;; WHEN: Thu Dec 01 17:04:17 CET 2022 ;; MSG SIZE rcvd: 98 This is from the example driver located in the system tests (bin/tests/system/dlzexter

Re: forwarder cache

2022-12-01 Thread Ondřej Surý
> test.com <http://test.com/>. 0 IN A 10.10.10.10 I think this line just have it all - you are generating record with TTL 0. > ;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 FTR it's an authoritative answer. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My w

Re: Gratuitous AXFRs of RPZ after 9.18.11

2023-01-27 Thread Ondřej Surý
perhaps something will stand out Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from th

Re: Docker image

2023-01-27 Thread Ondřej Surý
Hi, Yes, it is. Ondřej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 27. 1. 2023, at 19:07, Elias Pereira wrote: > >  > hi, > > Is this doc

Re: Deprecation notice for BIND 9.18: Differentiated Services Code Point (DSCP) support

2023-01-05 Thread Ondřej Surý
> On 5. 1. 2023, at 14:46, Robert M. Stockmann wrote: > > On Thu, 5 Jan 2023, [utf-8] Ondřej Surý wrote: > >> There's an alternative plan that would include re-implementing the >> functionality, but there would have to be strong user case behind the >> work. Bu

Re: Reverse lookups not working when Internet connection failed.

2022-11-05 Thread Ondřej Surý
The IPv4 reverse zone is easy to scrape and stored for situations like this… just saying. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 5. 11. 2022, at 0:48, Gr

Re: Unexpected extra care needed for building BIND 9.18.8

2022-11-06 Thread Ondřej Surý
ldd` might give you some hints. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 6. 11. 2022, at 16:27, Niall O'Reilly wrote: > > Building BIND 9.18.8 from

Re: automatic reverse and forwarding zones

2022-11-07 Thread Ondřej Surý
ften even if not very recently? How do you know it's a garbage? One woman's trash is another woman's treasure... Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working ho

Re: automatic reverse and forwarding zones

2022-11-07 Thread Ondřej Surý
That's not any different than wildcard record in a forward zone. The resolvers already have to deal with garbage in the cache and cache eviction algorithms. The DNS server doesn't live among rainbows and unicorns, so we prepare for the worst to come from network, not the best. Ondrej -- Ondř

Re: failed to start BIND 9.16.34 on Ubuntu 20.04

2022-11-12 Thread Ondřej Surý
is too small by default. To limit the amount of memory used by the server, use the ``max-cache-size`` and ``recursive-clients`` options instead. -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside

Re: CH/TXT/VERSION.SERVER queries

2022-11-14 Thread Ondřej Surý
Hi Anand, correct me if I am wrong, but the VERSION.SERVER doesn't seem to be anywhere documented[1], and you are the first one to request it[2]. 1. RFC 4892 only talks about ID.SERVER 2. Please create a GitLab issue for tracking Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours

Re: How to *require* TSIG for NOTIFY

2022-11-14 Thread Ondřej Surý
It’s `also-notify ;` and `notify explicit;` The online documentation is here: https://bind9.readthedocs.io/en/v9_16_34/reference.html Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal

Re: dig +norecurse behaviour changed with 9.16.33

2022-10-31 Thread Ondřej Surý
resolver still has to revalidate the answer, and there's no point in appending records that would be thrown away anyway. Cheers, Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working

Re: How to use update-policy type "external"

2023-03-14 Thread Ondřej Surý
al * CNAME; }; e.g. you need to quote the path. The documentation is silent on NAME field, but I would suggest using either * or . as placeholder. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply ou

Re: How to use update-policy type "external"

2023-03-14 Thread Ondřej Surý
> I am not sure how to start debugging this. Can anyone help? Well, start with sharing as much details as you can. It’s hard to tell what you are doing from a single configuration line. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please

Re: Deprecation notice for BIND 9.18: (root-)delegation-only option

2023-03-23 Thread Ondřej Surý
> On 23. 3. 2023, at 17:57, Matus UHLAR - fantomas wrote: > > On 22.03.23 17:36, Ondřej Surý wrote: >> in line with our deprecation policy, I am notifying the mailing list about >> our intent >> to deprecated the delegation-only and root-delegation-only options.

Re: Bind listener to an IPv6 from AnyIP subnet

2023-03-13 Thread Ondřej Surý
e destination addresses from the AnyIP range to single local address (DNAT) or if you are feeling really fancy I think this could be also accomplished with an eBPF rule. Ondrej 1. Or implement an extra logic to see whether the bound interface is "wildcard" or not. -- Ondřej Surý (He/

Re: Bind not sending notifies for some time

2023-03-24 Thread Ondřej Surý
> On 24. 3. 2023, at 14:36, Klaus Darilion via bind-users > wrote: > > Is there some rate liming in Bind? https://bind9.readthedocs.io/en/stable/reference.html#namedconf-statement-notify-rate -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may

Re: PPA for Raspbian distros

2023-03-24 Thread Ondřej Surý
hardware compatibility than Debian’s armhf was wrong, so you need to be careful. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 25. 3. 2023, at 3:37, Andrew P. wr

Re: BIND 9.16.30 - $INCLUDE file in the rpz zone file not reloading content and dig not working

2023-03-24 Thread Ondřej Surý
that includes all the bugfixes and security fixes is BIND 9.16.39, but our general recommendation is to upgrade to latest 9.18 version (9.18.13 as of now). Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside

Re: RPZ answer me NXDOMAIN for some domain

2023-03-22 Thread Ondřej Surý
Hi, look for break-dnssec in https://bind9.readthedocs.io/en/stable/reference.html#response-policy-zone-rpz-rewriting -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 22

Re: RPZ answer me NXDOMAIN for some domain

2023-03-22 Thread Ondřej Surý
s something that's impossible to answer without seeing the full configuration (named-checkconf -px). Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lis

Re: BIND Process failed during logrotate

2023-03-22 Thread Ondřej Surý
e ISC BIND 9 packages, I would recommend upgrading straight to the latest BIND 9.18 (with proper testing, etc..). The packages are available from: https://www.isc.org/download/ (See the paragraph just above the table.) Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and y

Deprecation notice for BIND 9.18: (root-)delegation-only option

2023-03-22 Thread Ondřej Surý
/bind9/-/issues/3953 1. https://en.wikipedia.org/wiki/Site_Finder 2. https://circleid.com/posts/the_name_domain_disrupted_by_site_finder_patch 3. https://www.afnic.fr/en/observatory-and-resources/news/warning-for-bind-and-delegation-only-users/ Ondřej -- Ondřej Surý (He/Him) ond...@isc.org My

Re: Simplistic serial number roll back

2023-02-17 Thread Ondřej Surý
needs to be put in place. And it’s something you don’t really do on a daily basis.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.On 17. 2. 2023, at 20:34, John Thurston wrote

Re: Simplistic serial number roll back

2023-02-17 Thread Ondřej Surý
Why so complicated? Stop the secondary, purge the zone files and journal, and start the secondary. The zones will get retransfered as there’s no state now.--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal

Deprecation notice force BIND 9.20+: TKEY Mode 2 (Diffie-Hellman Exchanged Keying)

2023-02-28 Thread Ondřej Surý
://gitlab.isc.org/isc-projects/bind9/-/issues/3905 Thanks. -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to un

Re: Message "Loop detected resolving..." and different query-behavior after flushing a cache entry

2023-02-21 Thread Ondřej Surý
Tom, the ADB (Address DataBase) responsible for caching the delegations had been heavily refactoring in 9.19 branch, I think the best course of action would be to fill a GitLab issue with the description, so we can follow-up there. Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours

Re: Fully automated DNSSEC with BIND 9.16

2023-04-17 Thread Ondřej Surý
rg/pipermail/bind-announce/2022-March/001210.html Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 17. 4. 2023, at 13:57, Petr Menšík wrote: > > Our

Re: help with notify

2023-04-17 Thread Ondřej Surý
the Debian being frozen for the next stable release). Ondrej -- Ondřej Surý (He/Him) ond...@isc.org My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to uns

Re: Is it possible to upgrade bind from 9.11 to 9.18 directly?

2023-04-21 Thread Ondřej Surý
Hi, I can confirm that it’s ok to skip 9.16 and go straight to 9.18. There’s no need for the intermediate step. As usual, it’s recommended to do a test migration first if you want to be extra careful. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may

Re: Response Policy Zone returns servfail for time.in Trigger

2023-04-08 Thread Ondřej Surý
-policy on qname-wait-recurse and break-dnssec to turn off the default behavior.Ondrej--Ondřej Surý — ISC (He/Him)My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.On 8. 4. 2023, at 16:32, Matthew Gomez wrote:Hi, has

Re: RPZ zone response delay time ?

2023-04-10 Thread Ondřej Surý
I don’t think we are ever going to implement something like this. This is a wrong layer to fix this. -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours. > On 10. 4. 2023, at 22

<    1   2   3   4   5   >