Re: A policy for removing named.conf options.

2019-06-13 Thread John Thurston
want my automated processes to stop working because something will be going away at some point in the near future. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska

Re: Preferred log location with ISC copr package

2019-05-21 Thread John Thurston
ermissions on /var/opt/isc/isc-bind/log? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman/lis

Preferred log location with ISC copr package

2019-05-20 Thread John Thurston
-bind/log/ Since I'm new the "Software Collection" paradigm, I don't know if this is an acceptable location for my operational logs. Is that location going to get trashed when I install the next update? -- Do things because you should, not just because you can. John Thurston90

rndc - sync before reload?

2019-07-10 Thread John Thurston
On a server with both static and dynamic zones, is there any reason to perform an: rndc sync prior to issuing an: rndc reload -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska

Status of experimental COPR packages

2019-09-06 Thread John Thurston
stabilize it? Are there outstanding feature requests to be addressed? Is there a timeline somewhere? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State

Re: Status of experimental COPR packages

2019-09-09 Thread John Thurston
n" concept meet our needs, and I'd dearly like to be able to consider it stable. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Ple

factor addresses out of 'forwarders' statement

2019-07-18 Thread John Thurston
. Is there some way to do this? alias { 10.10.1.2; 10.10.3.4; 10.10.5.6; } zone "foo" {type forward; forwarders ( alias;}; }; -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State

Status of experimental packages

2019-07-23 Thread John Thurston
addressed? Is there a timeline somewhere? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman/lis

Exempt .local from dnssec validation on resolver?

2019-07-25 Thread John Thurston
to the servers which are already answering for them? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman

Log rolling stopped working in 9.11.12 ?

2019-11-18 Thread John Thurston
ooked over the BIND release notes and don't see anything about a change to the logging behavior. Did I miss something? Or maybe some kernel (or other package) patch broke some dependency? I'm looking for ideas here. -- Do things because you should, not just because you can. John Thurston90

Re: Log rolling stopped working in 9.11.12 ?

2019-11-19 Thread John Thurston
path in my named.conf is currently set to a relative path "../../log/query.log", but I could easily change it to an absolute path "/var/log/named/query.log" -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Depa

Re: Log rolling stopped working in 9.11.12 ?

2019-11-19 Thread John Thurston
On 11/19/2019 8:34 AM, Reindl Harald wrote: Am 19.11.19 um 18:23 schrieb John Thurston: A) Should I expect these file permissions be altered by a minor update? I know I started at 9.11.8 and have updated to 9.11.9 and 9.11.10 without seeing this behavior. yes, every by a package owned

9.11 -> 9.16 via COPR

2020-08-21 Thread John Thurston
t;yum install"? Is it simpler than that? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailm

Re: Request for review of performance advice

2020-07-08 Thread John Thurston
you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska Can those of you who care about performance, who have worked to improve your performance, share some of your suggestions that have the most impact?  Please also comment if you think any

BIND through COPR after CentOS

2020-12-18 Thread John Thurston
to offer up other linux distributions on which they have had unqualified success with these same packages? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska

rndc stops listening

2020-12-11 Thread John Thurston
for something? If so, for what? and how high? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.o

Re: getting a later-version of BIND on various linux OS's

2020-11-10 Thread John Thurston
ut/ having to download and compile the source code? Please take a look at the ISC "Software Collection": https://copr.fedorainfracloud.org/coprs/isc/ We use those packages with CentOS 7 and 8 to deliver ISC BIND 9.11 and 9.16. -- Do things because you should, not just because you can.

"in-view" behavior

2020-10-30 Thread John Thurston
If so, which properties? (FWIW, BIND version 9.11.24 on the primary and 9.16.8 on the secondary.) -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska _

BIND 9.16.10 launchpad package for Ubuntu ?

2021-01-14 Thread John Thurston
because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds

Limit actions on control channel?

2021-06-17 Thread John Thurston
ask for "status" without also letting it ask for "reload" or "flushname". -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska __

Re: Only zones with wildcards affected on authoritative servers

2021-06-18 Thread John Thurston
urn BIND 9.16.17 (Stable Release) BIND 9.16.18-Ubuntu (Stable Release) -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please v

Syslog with BIND on CentOS

2021-05-20 Thread John Thurston
to madness. The only thing I can come up with is to activate dnstap, and have some other process absorbing the data and spewing it directly to the central syslogd. -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department

Re: Syslog with BIND on CentOS

2021-05-21 Thread John Thurston
arning: When started for the first time, imfile will read the existing file and start forwarding. If the query log already contains 800MB of lines, those will all be read in and passed through the parser and output modules. -- Do things because you should, not just because you can. John Thurston907

Re: replication time for dynamic records from primary to secondary servers

2021-03-30 Thread John Thurston
transfers? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: rndc stops listening

2021-04-07 Thread John Thurston
. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 12/11/2020 11:13 AM, John Thurston wrote: Running BIND 9.16.9 on CentOS 8 I have the following in my .conf controls {   inet 127.0.0.1 port 953     allow { 127.0.0.1; } keys { "

Switching key types for authorizing updates

2021-08-10 Thread John Thurston
TXT records, while letting the current key continue to work. Is there a way to get the configuration I want? or must I make a wholesale swap of each md5 key for something newer? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thur

Re: Switching key types for authorizing updates

2021-08-12 Thread John Thurston
ld, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the developm

Re: DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2022-01-03 Thread John Thurston
stupid domains; there must be an explicit 'forward' zone defined. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https

Re: Recursion Question

2021-12-20 Thread John Thurston
Define an explicit forward-zone on the recursive server for private.dns.com In the zone definition, put the addresses of the servers which can answer for private.dns.com. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov

Re: acl type construct for update-policy

2021-11-10 Thread John Thurston
On 11/10/2021 6:25 AM, Giddings, Bret wrote: Is there any other facility for including effectively the same grant statements within multiple zones? I am not aware of any -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov

RPZ rule to apply to NS record requests?

2021-11-15 Thread John Thurston
-- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this

Re: RPZ rule to apply to NS record requests?

2021-11-16 Thread John Thurston
On 11/16/2021 2:41 AM, Tony Finch wrote: John Thurston wrote: If I have a Reverse Policy Zone (RPZ) defined, I can define a specific answer to be sent for a specific record-type for a specific name: foo.bar.com IN A 10.11.12.13 foo.bar.com IN TXT "Hello World" But I

Re: named service suddenly fails to start

2021-11-04 Thread John Thurston
some validity checks into your edit/deploy process. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska ___ Please visit https://lists.isc.org

re: insecurity proof failed for a domain

2021-12-13 Thread John Thurston
If you update your resolver to 9.16, I think you can do exactly what you want with the "validate-execpt" option. {rolls eyes} been there. done that. for exactly the same reason :/ -- -- Do things because you should, not just because you can. John Thurston907-465-8591

Re: Reminder: BIND 9.11 is going EOL in March 2022

2022-04-05 Thread John Thurston
, and bind-dev Is it reasonable to expect these changes will occur in about the middle of the month? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org

Re: Using nsupdate in scripts

2022-03-21 Thread John Thurston
r compiled in), then named-checkconf isn't going to help. To learn those, I think you'll need to query the operating system for information about the specif process. I'd be looking at pgrep and ps, but there's probably better ways to do it. -- Do things because you should, not just because you

Re: ISC BIND & Windows

2022-02-01 Thread John Thurston
Check the list archives beginning April 2021 for the thread: Deprecating BIND 9.18+ on Windows (or making it community improved and supported)​ -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration

Capabilities and limitations of catalog zones

2022-02-08 Thread John Thurston
gov' is defined on the primary like so: zone "ak.gov" {type forward;forward only;forwarders { 10..11.12.13; }; }; -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of

Re: Capabilities and limitations of catalog zones

2022-02-09 Thread John Thurston
On 2/9/2022 2:36 AM, Tony Finch wrote: John Thurston wrote: Are we not able to use catalog zones to propagate zone-configuration for anything other than 'master' zones? > It is only for configuring authoritative secondary zones. That's unfortunate, but thanks for the confirmation

9.11, 9.16 and ESV designation

2022-01-26 Thread John Thurston
' and 'user' mailing lists. I need to find and plug this communication hole.) B) What are the plans for the 'bind-esv' COPR? (Will it soon start serving 9.16? Do I need to manually switch from 'bind-esv' to 'bind'? Is COPR dead?) -- -- Do things because you should, not just because you can.

consolidating in-addr.arpa data

2023-09-15 Thread John Thurston
, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions

Re: consolidating in-addr.arpa data

2023-09-15 Thread John Thurston
an NXDOMAIN with confidence. And since writing my earlier note, I have re-located the code I think I stumbled across earlier Tony Finch's "nsdiff" https://dotat.at/prog/nsdiff/ -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@

Stop leaking queries for RFC 1918 zones

2023-09-22 Thread John Thurston
e best way to correct this? Or maybe add the un-used RFC 1918 zones to our RPZ? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman/listinfo/

Re: consolidating in-addr.arpa data

2023-09-18 Thread John Thurston
s from all of the possible DNS services in the environment. But this is achievable, and will address the problem (of our own making) which is causing pain. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administra

Unhelpful startup message re: RPZ

2023-09-21 Thread John Thurston
hours were of diminishing value, as my caffeine wore off and my frustration grew. After a night's sleep, and a pot of fresh tea I figured it out. -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administra

Re: Zone transfer over VPN

2022-09-06 Thread John Thurston
s. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 9/6/2022 2:31 PM, Greg Choules via bind-users wrote: Hi Michael. Have you tried without the "allow-transfer" state

Re: Bind 9.16.1 crash

2022-12-07 Thread John Thurston
on of BIND? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 12/7/2022 10:32 AM, Ben Bridges wrote: The BIND version is 9.16.1 running on a fully patched Ubuntu 20.04.5 server.-- V

Finding dnssec validation failures in the logs

2023-01-23 Thread John Thurston
gning information for wunderkind.co and found none. That's cool, we didn't expect them to be." -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman

Re: Finding dnssec validation failures in the logs

2023-01-24 Thread John Thurston
have my suspicions of what's happening, but not enough information to form a solid hypothesis or perform tests. I want higher confidence that I'm recognizing the important lines in the logs before I start casting stones. -- Do things because you should, not just because you can. John Thurston

Resolving and caching illegal names

2023-01-24 Thread John Thurston
urns a SERVFAIL to the customer. I haven't yet tried, but I don't expect I can define an RPZ to trap such illegal names. Can I? If I could, it would reduce the traffic to Akamai, and the number of validations I'm trying to do. -- -- Do things because you should, not just bec

Re: Resolving and caching illegal names

2023-01-25 Thread John Thurston
s because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 1/25/2023 8:36 AM, John Thurston wrote: Off-list, it was suggested to me that I _could_ handle this in my RPZ, by enumerating all 255 illegal TLDs (

Re: Resolving and caching illegal names

2023-01-25 Thread John Thurston
and ignore the rest. I think this will get me what I want, at a level of complexity I can accept. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 1/24/2023 10:26 PM, Greg Cho

Gratuitous AXFRs of RPZ after 9.18.11

2023-01-26 Thread John Thurston
imilar behavior? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the develop

Use of stale data during dnssec validation

2023-03-03 Thread John Thurston
+XHeB8O8GTLqk7HgfdM8=     ) ; KSK; alg = RSASHA256 ; key id = 46144 -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org

Tools for parsing a dumped cache

2023-03-03 Thread John Thurston
s because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid supp

Simplistic serial number roll back

2023-02-17 Thread John Thurston
-- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software w

Re: Simplistic serial number roll back

2023-02-17 Thread John Thurston
the other views, would be uninterrupted. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 2/17/2023 10:23 AM, Ondřej Surý wrote: *CAUTION:* This email originated fr

Re: Simplistic serial number roll back

2023-02-17 Thread John Thurston
ld, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 2/17/2023 10:46 AM, Ondřej Surý wrote: Well, the serial number arithmetics is there for a reason - you usually don’t want to rollback to previous version of the

Delegation NS-records when zones share an authority server

2023-04-12 Thread John Thurston
hese tests. Arguments against: * Maybe I misunderstand, and such NS records aren't actually benign Unknown: * Does the answer change if we want to start signing either zone? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.go

Reverse Policy Zone to make MS Azure stuff work?

2023-04-13 Thread John Thurston
Were you able to do it with your RPZ? * https://learn.microsoft.com/en-us/azure/app-service/environment/create-ilb-ase -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://l

Re: Gratuitous AXFRs of RPZ after 9.18.11

2023-01-31 Thread John Thurston
al number, and waiting patiently for the refresh interval to expire before checking again. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 1/27/2023 1:53 AM, Ondřej Surý wrote: FTR I am

BIND 9.18 available for Ubuntu from PPA ?

2023-06-23 Thread John Thurston
/+archive/ubuntu/bind I think it is telling me that 1:9.18.16-1+ubuntu22.04.1+isc+1 should be available. Has anyone successfully updated to 9.18.16 from this PPA? Can you suggest what I'm doing wrong today? -- -- Do things because you should, not just because you can. John Thurston907-465

Re: BIND 9.18 available for Ubuntu from PPA ?

2023-06-23 Thread John Thurston
amd64 Packages     500 http://security.ubuntu.com/ubuntu bionic-security/main amd64 Packages 1:9.11.3+dfsg-1ubuntu1 500     500 http://azure.archive.ubuntu.com/ubuntu bionic/main amd64 Packages -- Do things because you should, not just because you can. John Thurston907-465

Re: BIND 9.18 available for Ubuntu from PPA ?

2023-06-23 Thread John Thurston
Welp, there I have it. I thought I had until April 2028 :( Sorry for the noise. -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 6/23/2023 12:04 PM, Ondřej Surý wrote

Value of a DNSSEC validating resolver

2023-12-01 Thread John Thurston
why should my clients be trusting *me* to validate them? Can someone make a good case to me for continuing to perform DNSSEC validation on my central resolvers? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov

Re: BIND 9.16 is approaching EOL in April, 2024

2024-03-11 Thread John Thurston
things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 2/26/2024 7:35 AM, Victoria Risk wrote: The BIND 9.16 release branch is approaching EOL as of April, 2024. We encourage users running 9.16

Crafting a NOTIFY message from the command line?

2024-03-19 Thread John Thurston
I can use dig to request a zone transfer: dig AXFR foo.com I am unable to find a simple way to craft a NOTIFY message. Can anyone help me out? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration

"bad cache-hit" or "bad-cache hit"

2024-04-16 Thread John Thurston
. We found what we wanted in the cache of bad entries) Can anyone confirm my hypothesis? -- -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman

Answers for www.dnssec-failed.org with dnssec-validation auto;

2024-04-16 Thread John Thurston
;; ANSWER SECTION: www.dnssec-failed.org.  7198    IN  A   68.87.109.242 www.dnssec-failed.org.  7198    IN  A   69.252.193.191 ;; Query time: 0 msec ;; SERVER: 127.0.0.1#53(localhost) (UDP) ;; WHEN: Tue Apr 16 15:21:46 AKDT 2024 ;; MSG SIZE  rcvd: 110 -- -- Do things

Re: Answers for www.dnssec-failed.org with dnssec-validation auto;

2024-04-17 Thread John Thurston
08:40:40.323 validating www.dnssec-failed.org/A: no supported algorithm/digest (dnssec-failed.org/DS) 17-Apr-2024 08:40:40.323 validating www.dnssec-failed.org/A: marking as answer (proveunsecure (2)) 17-Apr-2024 08:40:40.323 validator @0x7fb8722b8e00: dns_validator_destroy -- Do thing

Re: Answers for www.dnssec-failed.org with dnssec-validation auto;

2024-04-17 Thread John Thurston
. Is there a way to narrow it down? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska On 4/17/2024 9:21 AM, Ondřej Surý wrote: Let me guess - you are running on RHEL (without SHA-1 support

Re: Broken DNS QNAME Recovery

2024-04-22 Thread John Thurston
atalog-zones? -- Do things because you should, not just because you can. John Thurston907-465-8591 john.thurs...@alaska.gov Department of Administration State of Alaska -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the develo