Re: [CentOS] Bind - built in root hints?

2013-02-20 Thread Jay Leafey
A LONG time ago an older (at the time, I think I've caught up) sysadmin told me to use dig to update the named.ca file. Periodically he would run dig with no arguments and compare the output to the existing /var/named/named.ca file and copy it over the old one if anything had changed. Maybe

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Nathan Duehr
On Feb 14, 2013, at 11:02 AM, Robert Moskowitz r...@htt-consult.com wrote: No need to worry. They are only hints, and named uses them to get the current list of root name servers at startup. Even if they are 15 years out of date it will still work, because the root name servers do not

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Robert Moskowitz
On 02/19/2013 08:17 AM, Nathan Duehr wrote: On Feb 14, 2013, at 11:02 AM, Robert Moskowitz r...@htt-consult.com wrote: No need to worry. They are only hints, and named uses them to get the current list of root name servers at startup. Even if they are 15 years out of date it will still work,

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Morten Stevens
On 14.02.2013 16:33, Robert Moskowitz wrote: Over on the bind-us...@lists.isc.org list, I am in a discussion about building the named.zone file, as Centos 6.3 does not provide it. It DOES provide a named.ca which is already old (wrt records) compared to the named.zone provided by

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Bry8 Star
The named.cache / root hints just updated on jan 3 2013 after jun 8 2011. I'm not 100% sure but i think many centos/rhel boxes are still using that 2011 hint. So before rhel/centos releases/updates their bind/hint file/bin, or users who do not want to update hint/bind portion specifically via yum,

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread John R Pierce
On 2/19/2013 4:22 PM, Bry8 Star wrote: So before rhel/centos releases/updates their bind/hint file/bin, or users who do not want to update hint/bind portion specifically via yum, for such type of users, to use the latest hint file, i think the existing hint file its location would help to

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Bry8 Star
sorry, let me re-phrase: Some users do not want to update their bind with what rhel/centos repo provides. Some users update their bind/hint files when centos/rhel repo updates. so those who want to manually place/use the hint file for their BIND, they can do so bit easily if the old one is

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread John R Pierce
On 2/19/2013 4:35 PM, Bry8 Star wrote: they can do so bit easily if the old one is visible. whats not visible about /var/named/named.ca ? its even listed in /etc/named.conf as the root zone. -- john r pierce 37N 122W somewhere on the middle of the

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Bry8 Star
ofcourse it is now visible. which is good. so removing it would not be good. even if bind has built into it older or latest hint. Received from John R Pierce, on 2013-02-20 1:20 AM: On 2/19/2013 4:35 PM, Bry8 Star wrote: they can do so bit easily if the old one is visible. whats not

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Markus Falb
On 20.2.2013 02:20, John R Pierce wrote: On 2/19/2013 4:35 PM, Bry8 Star wrote: they can do so bit easily if the old one is visible. whats not visible about /var/named/named.ca ? its even listed in /etc/named.conf as the root zone. hmm, here as I understand this: A point was made by

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Robert Moskowitz
On 02/19/2013 08:59 PM, Bry8 Star wrote: ofcourse it is now visible. which is good. so removing it would not be good. even if bind has built into it older or latest hint. My point, what I have learned over the past few days, is that having a hint stub for the roots is an artifact of the old

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Robert Moskowitz
On 02/19/2013 09:07 PM, Markus Falb wrote: On 20.2.2013 02:20, John R Pierce wrote: On 2/19/2013 4:35 PM, Bry8 Star wrote: they can do so bit easily if the old one is visible. whats not visible about /var/named/named.ca ? its even listed in /etc/named.conf as the root zone. hmm, here as

Re: [CentOS] Bind - built in root hints?

2013-02-19 Thread Bry8 Star
most recent release of BIND can obtain latest root hints by itself, and i do not think it connects with (INTERNIC.NET or with) root servers after a successful authentication of DNSSEC records, so at initial point (during setup), there is a chance for an entity in the middle to supply a false one.

[CentOS] Bind - built in root hints?

2013-02-14 Thread Robert Moskowitz
Over on the bind-us...@lists.isc.org list, I am in a discussion about building the named.zone file, as Centos 6.3 does not provide it. It DOES provide a named.ca which is already old (wrt records) compared to the named.zone provided by internic. A few contributors have stated that now

Re: [CentOS] Bind - built in root hints?

2013-02-14 Thread Paul Heinlein
On Thu, 14 Feb 2013, Robert Moskowitz wrote: Over on the bind-us...@lists.isc.org list, I am in a discussion about building the named.zone file, as Centos 6.3 does not provide it. It DOES provide a named.ca which is already old (wrt records) compared to the named.zone provided by

Re: [CentOS] Bind - built in root hints?

2013-02-14 Thread Robert Moskowitz
On 02/14/2013 12:29 PM, Paul Heinlein wrote: On Thu, 14 Feb 2013, Robert Moskowitz wrote: Over on the bind-us...@lists.isc.org list, I am in a discussion about building the named.zone file, as Centos 6.3 does not provide it. It DOES provide a named.ca which is already old (wrt records)

Re: [CentOS] Bind - built in root hints?

2013-02-14 Thread Robert Moskowitz
On 02/14/2013 12:47 PM, Reindl Harald wrote: Am 14.02.2013 18:37, schrieb Robert Moskowitz: On 02/14/2013 12:29 PM, Paul Heinlein wrote: On Thu, 14 Feb 2013, Robert Moskowitz wrote: Over on the bind-us...@lists.isc.org list, I am in a discussion about building the named.zone file, as

Re: [CentOS] Bind - built in root hints?

2013-02-14 Thread Robert Moskowitz
On 02/14/2013 12:47 PM, Reindl Harald wrote: Am 14.02.2013 18:37, schrieb Robert Moskowitz: On 02/14/2013 12:29 PM, Paul Heinlein wrote: On Thu, 14 Feb 2013, Robert Moskowitz wrote: Over on the bind-us...@lists.isc.org list, I am in a discussion about building the named.zone file, as