Re: [Pdns-users] Can pdns (with ldap backend) be a master of BIND9 slave?

2010-09-02 Thread Nikolaos Milas
se confirm. Thanks, N. Milas On 1/9/2010 3:04 μμ, Nikolaos Milas wrote: Hi, I am interested in running pdns (I have already installed latest version, as an rpm on CentOS 5.5) with ldap backend (tree mode).

Re: [Pdns-users] Can pdns (with ldap backend) be a master of BIND9 slave?

2010-09-02 Thread Nikolaos Milas
Thank you very much Norbert, I assume that such a pdns/ldap master should NOT have a "master=on" setting. Correct? It's just the slave (e.g. slave.example.com) that must have configured itself as a slave to us and we should

Re: [Pdns-users] Can pdns (with ldap backend) be a master of BIND9 slave?

2010-09-02 Thread Nikolaos Milas
PM, Nikolaos Milas wrote: I assume that such a pdns/ldap master should *NOT* have a master=on setting. Correct? Correct. It's just the slave (e.g. slave.example.com) that must have configured itself as a slave to us and we should allow it by having it placed (i.e. the slave.example.com

Re: [Pdns-users] Strange time drift in log

2010-09-05 Thread Nikolaos Milas
Thanks Christian,  {I am resending in HTML format, to avoid auto line breaks which make terminal output illegible.} This problem happened to me only with pdns server logging. I've never had a similar problem on this or on any of the other

[Pdns-users] Successful, yet incomplete AXFR to BIND9 slave

2010-09-08 Thread Nikolaos Milas
In my pdns/ldap (tree) on CentOS 5.5, I am setting up a domain (say: 'example.com')  with its single SOA record. This has several virtual subzones (a.example.com, b.example.com etc.) which include their own MX records but are not delegated: the same NS

Re: [Pdns-users] Successful, yet incomplete AXFR to BIND9 slave

2010-09-08 Thread Nikolaos Milas
in the AXFR set? I am waiting for your advice. I like pdns and I am trying to resolve issues so that it can replace (gradually) all BIND9 servers in our organization. Nick On 8/9/2010 11:26 μμ, Nikolaos Milas wrote: In my pdns/ldap (tree) on CentOS 5.5, I am setting up a domain (say: 'example.com

Re: [Pdns-users] Successful, yet incomplete AXFR to BIND9 slave

2010-09-09 Thread Nikolaos Milas
webserver-password=* webserver-port=8081 webserver-print-arguments=yes Nick On 9/9/2010 12:51 πμ, Nikolaos Milas wrote: Yes, I can see exactly where it stopped, but I can't find a reason why it did so. It seems to

Re: [Pdns-users] Successful, yet incomplete AXFR to BIND9 slave

2010-09-09 Thread Nikolaos Milas
Thanks Christian, That did the trick! Now AXFR works fine! I set sizelimit unlimited in slapd.conf You were right. The default max size in openldap is 500 and I didn't know it. Would you have any hint about the Authority issue as well? Thanks again, Nick On 9/9/2010 11:07 πμ,

Re: [Pdns-users] Strange time drift in log

2010-09-09 Thread Nikolaos Milas
Thanks Christian, I tried to configure, but it fails: ... configure: error: ldap library (libldap) not found But there is libldap: # find / -name '*libldap*' /usr/lib/libldap_r-2.3.so.0.2.31 /usr/lib/libldap-2.3.so.0 /usr/lib/libldap_r-2.3.so.0 /usr/lib/libldap-2.3.so.0.2.31

Re: [Pdns-users] Strange time drift in log

2010-09-09 Thread Nikolaos Milas
By the way, The autoserial feature is not supported with the ldap backend according the documentation. Nick On 9/9/2010 11:27 , Christian Hofstaedtler wrote: * Christian Hofstaedtler c...@zeha.at [100909 09:56]:

Re: [Pdns-users] Strange time drift in log

2010-09-09 Thread Nikolaos Milas
I also installed compat-openldap and now I have: openldap-servers-2.3.43-12.el5_5.2 nss_ldap-253-25.el5 pdns-backend-ldap-2.9.21-4.el5.centos openldap-devel-2.3.43-12.el5_5.2 python-ldap-2.2.0-2.1 compat-openldap-2.3.43_2.2.29-12.el5_5.2 openldap-2.3.43-12.el5_5.2

Re: [Pdns-users] Successful, yet incomplete AXFR to BIND9 slave

2010-09-09 Thread Nikolaos Milas
/2010 11:24 πμ, Nikolaos Milas wrote: Would you have any hint about the Authority issue as well? ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Strange time drift in log

2010-09-10 Thread Nikolaos Milas
. Thanks, Nick On 9/9/2010 1:34 μμ, Nikolaos Milas wrote:  Now:    # find / -name '*libldap*'    /usr/lib/libldap_r-2.3.so.0.2.31    /usr/lib/libldap-2.3.so.0    /usr/lib/libldap_r-2.3.so.0    /usr

Re: [Pdns-users] Strange time drift in log

2010-09-10 Thread Nikolaos Milas
Hmm, I am not sure if I'll manage to compile myself... In any case, I think this issue should be corrected for the next release of powerdns authoritative server, because it makes no sense to have logging in a different time than system time. So I really hope that the next releases and the

Re: [Pdns-users] Question on IPv6 with ldap backend

2010-09-18 Thread Nikolaos Milas
Waiting for a reply on this (ipv6 with ldap, tree mode), I decided to test simple mode and I found the solution with it. I still believe that the tree method would need a 34-level deep ldap structure (32 items for ipv6 address plus ip6 plus arpa), which renders it totally unsuitable for ipv6

Re: [Pdns-users] NOTIFY by pdns master with ldap backend in next authoritative server releases?

2010-09-29 Thread Nikolaos Milas
of slaves, type of remote slaves, etc.), because, unfortunately, we can't use ldap backend on all slaves, and we don't want those slaves to remain not-synchronized for long, nor we can use very short refresh times. Please, could you give a hint? Thanks, Nick On 25/9/2010 12:54 πμ, Nikolaos

Re: [Pdns-users] NOTIFY by pdns master with ldap backend in next authoritative server releases?

2010-10-01 Thread Nikolaos Milas
Thanks again for your help, JP. I describe in short some more things I tried (I still need your guidance): Initially, I found out that the plugin was not being loaded in openldap (as recorded in ldap.log): /etc/openldap/slapd.conf: line 182: keyword plugin ignored And: # slaptest -d

Re: [Pdns-users] NOTIFY by pdns master with ldap backend in next authoritative server releases?

2010-10-02 Thread Nikolaos Milas
I have reached to the same conclusion. However, rebuilding openldap doesn't seem to be easy or straightforward (but I'll give it a try when I can)... It is commonly accepted that in production servers, pre-built, platform-specific RPMs are preferred (to avoid all sorts of problems), compiled

Re: [Pdns-users] NOTIFY by pdns master with ldap backend in next authoritative server releases?

2010-10-02 Thread Nikolaos Milas
(when changed), as discussed earlier in this thread (something which I concluded could not be done with pdns_control for the ldap backend). Nick On 2/10/2010 1:01 μμ, Nikolaos Milas wrote: What does it mean by Bad file descriptor? What can I do

[Pdns-users] Can a slave force quich refresh?

2010-10-02 Thread Nikolaos Milas
Hi, Can a slave (e.g. with BIND backend) force quick /refresh/ times, overriding the default SOA record value (as defined on the master zone)? In BIND9, one can use the max-refresh-time (and min-refresh-time) directive in a slave zone definition to do that. Does powerdns observe these

Re: [Pdns-users] NOTIFY by pdns master with ldap backend in next authoritative server releases?

2010-10-02 Thread Nikolaos Milas
Thanks Nils, I have now filed a bug ("new enhancement") for this, it's No. 318. (http://wiki.powerdns.com/trac/ticket/318). Nick. On 2/10/2010 4:20 , Nils Breunese (Lemonbit) wrote: I believe most public bug trackers

Re: [Pdns-users] NOTIFY by pdns master with ldap backend in next authoritative server releases?

2010-10-05 Thread Nikolaos Milas
of supporting Notify natively in powerdns / ldap backend*. Thanks again to Jean-Piet Mens for notify-dns-slaves tool. Nick On 2/10/2010 4:58 μμ, Nikolaos Milas wrote: I have now filed a bug (new enhancement) for this, it's No. 318. (http://wiki.powerdns.com/trac/ticket/318

Re: [Pdns-users] Announcing JPower Admin

2010-10-11 Thread Nikolaos Milas
Hi, Does it support (or will it support) LDAP backend? I've searched the source and it doesn't seem to mention ldap anywhere. Thanks, Nick On 12/10/2010 12:36 πμ, Jivko Sabev wrote: I have released yet another control panel for Power DNS. Some of the

Re: [Pdns-users] PowerDNS Recursor 3.3 released!

2010-10-12 Thread Nikolaos Milas
Hi Bert, Just wanted to mention that at powerdns.com homepage the latest recursor version still appears to be 3.2. The download links at the Downloads page have been updated to 3.3, but on the home page, neither the version number nor the download link have been updated. They're still 3.2!

Re: [Pdns-users] powerdns hangs when ldap backend is unavailable

2010-10-28 Thread Nikolaos Milas
Hi, I haven't received any feedback on this problem. If noone can suggest something, I think I should file it as a bug. Please, advise. Thanks, Nick On 24/10/2010 11:31 μμ, Nikolaos Milas wrote: I've noticed that when for some reason ldap is not available for a while (e.g. due to restart

Re: [Pdns-users] powerdns hangs when ldap backend is unavailable

2010-10-29 Thread Nikolaos Milas
I totally agree. I even use a local ldap slave server (an openldap syncrepl consumer, on the powerdns box) using syncrepl (on openldap) to avoid any pdns service outage due to network problems which would prevent connectivity with ldap. (Thankfully, syncrepl does not hang when there is a

[Pdns-users] Support for GSS-TSIG Dynamic DNS Updates

2012-06-01 Thread Nikolaos Milas
Does PowerDNS support or will it support GSS-TSIG Secure Dynamic DNS Updates (proabably related: RFC 3645, 2930) for interoperability with dynamic Windoze clients? Thanks, Nick ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com

Re: [Pdns-users] Complie problem on PDNS on CENTOS5

2013-02-05 Thread Nikolaos Milas
On 6/2/2013 4:14 πμ, RBK1001 wrote: I really need instruction on how to complie PowerDNS 3.2 in CENTOS5 This thread might help you: http://www.mail-archive.com/pdns-users@mailman.powerdns.com/msg04162.html ...although it's for v2.9.22. This thread might help you too:

Re: [Pdns-users] installing ldap as backend

2013-03-18 Thread Nikolaos Milas
On 18/3/2013 10:37 μμ, Jignesh Patel wrote: ...Is there any good documentation for setting up powerdns with ldap? Official support has been dropped for LDAP backend by its former maintainer and, as a result, by PowerDNS too. v2.9.22 is the last working version, even with some limitations

Re: [Pdns-users] installing ldap as backend

2013-03-19 Thread Nikolaos Milas
On 19/3/2013 3:15 πμ, Jignesh Patel wrote: Looks like pdns works with LDAP. Thanks to Beñat for his kind assistance to suggest removing white spaces after =. Please report here how it behaves (errors etc.). Now I am seeing for efficient UI to view content. Besides JXplorer and

Re: [Pdns-users] installing ldap as backend

2013-03-19 Thread Nikolaos Milas
On 19/3/2013 2:23 μμ, Jignesh Patel wrote: For the UI my question is in the context of PDNS, not for LDAP UI. Is there any UI which can work PDNS(with LDAP). Not that I know of. I am definitely going to install phpLDAPAdmin, but is that sufficient? Depends on your needs. If

[Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-03-19 Thread Nikolaos Milas
Hello, I'm trying to build PowerDNS 3.2 on CentOS 6.4 x86_64 using http://www.monshouwer.eu/download/3rd_party/pdns-server/el6/SRPMS/pdns-server-3.2-1.el6.MIND.src.rpm based NOT on standard el6/centos 6 LDAP libraries, but on those installed by LTB project's RPMs (see:

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-03-19 Thread Nikolaos Milas
On 19/3/2013 5:28 μμ, Nikolaos Milas wrote: Can you please guide me on how to adapt the spec file so as to build correctly using the custom ldap libraries / headers? Hmm, actually now that I tried to build using even the standard CentOS 6 RPMs/libs/headers/, it still fails at the same point

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-03-20 Thread Nikolaos Milas
On 19/3/2013 8:13 μμ, Nikolaos Milas wrote: But, as I mentioned, it even fails without any change in the spec file, simply trying to build with the standard CentOS 6 OpenLDAP packages. In that case, it should be using the default system lib dir: In the meantime, I tried building PowerDNS 3.2

Re: [Pdns-users] installing ldap as backend

2013-03-21 Thread Nikolaos Milas
On 19/3/2013 3:21 μμ, Jignesh Patel wrote: This http://www.ossramblings.com/creating-srv-records-powerdns talks about creating SRV records at org level, I would like to create an individual user level(i.e. ou=people). Sorry, I don't know about that. You mean you

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-03-21 Thread Nikolaos Milas
On 20/3/2013 8:38 μμ, a b wrote: What does config.log say regarding ldap? Thanks for the reply. Please, see below. Thanks, Nick === ... configure:18499: checking ldap.h usability configure:18499: g++ -c -D_GNU_SOURCE -O2 -g -pipe -Wall

[Pdns-users] Testing master functionality on ldap backend

2013-03-21 Thread Nikolaos Milas
Hello, I am testing the new ldap backend (http://repo.or.cz/w/pdns-ldap-backend.git) under pdns v3.2 on CentOS 6.4 x86_64 I have a question: It seems the master is sending duplicate notifications to the slave, both at the IPv4 and at the IPv6 address. Is this expected behavior? Please

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-03-21 Thread Nikolaos Milas
On 20/3/2013 8:25 μμ, a b wrote: You need to pass --libdir=/usr/local/openldap/lib64 on the %configure line. Tried that, but the same error occurred. %configure \ --sysconfdir=%{_sysconfdir}/powerdns \ --libdir=/usr/local/openldap/lib64 \ --with-sqlite3 \

Re: [Pdns-users] Testing master functionality on ldap backend

2013-03-22 Thread Nikolaos Milas
On 22/3/2013 9:11 πμ, Ruben d'Arco wrote: This is by design and not specific to the ldap backend. Powerdns simply receives the nameservers from the backend and starts resolving the name to ip addresses. If that name has multiple ip addresses (v6 or v4), notifies will be send to all of them.

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-03-22 Thread Nikolaos Milas
On 22/3/2013 6:23 pm, a b wrote: I did not mean that literally, sorry for the confusion. What I meant is that you muss pass the equivalent of --libdir=/usr/local/openldap/lib64 by using --libdir=%{_libdir}, which is a special RPM built-in macro. Thanks for your assistance. Sorry, I am not a

[Pdns-users] Selective notifications

2013-04-03 Thread Nikolaos Milas
Hello, Is it possible to somehow disable auto notifications when running authoritative server (3.2) in master mode and use pdns_control to send notifications manually when required to whichever servers we want? Thanks, Nick ___ Pdns-users mailing

[Pdns-users] Multiple notifications when notifying IPv6 addresses

2013-04-03 Thread Nikolaos Milas
We have observed that when the master (v3.2) notifies a slave using an IPv6 address, then multiple unnecessary notifications are being sent. The same behavior is observed using pdns_control. One notification is sent when the target is notified over an IPv4 address, multiple notifications are

Re: [Pdns-users] Selective notifications

2013-04-05 Thread Nikolaos Milas
On 5/4/2013 9:56 πμ, Ruben d'Arco wrote: I believe that should solve your first two points, i suggest you provide a bit more information (logging, configuration) in the other thread on the last point. Thanks, I am aware of these tickets, I've also asked about them, see:

Re: [Pdns-users] Selective notifications

2013-04-05 Thread Nikolaos Milas
On 5/4/2013 4:59 μμ, a b wrote: Which problem(s) are you experiencing currently? Thank you, Since the last time I posted regarding my issues, I haven't been able to find time to test your latest suggestions, so I am still at that point. :-( Too much work, too many priorities for us poor

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-04-09 Thread Nikolaos Milas
On 9/4/2013 5:30 μμ, Aki Tuomi wrote: This line here is the clue. You are missing -llber (/usr/lib64/llber.so) There is not such a lib (llber.so or lber.so or lldap.so or ldap.so) in any openldap installation either on CentOS/EL 5 or 6. If the process requires such libs, it's looking for

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-04-09 Thread Nikolaos Milas
On 10/4/2013 12:33 πμ, Ruben Kerkhof wrote: There must be something broken in your setup, can you show us the same output as I just did? [root@vmres x86_64]# rpm -qf /usr/lib64/liblber.so openldap-devel-2.4.23-32.el6_4.x86_64 [root@vmres x86_64]# ls -l /usr/lib64/liblber* lrwxrwxrwx. 1 root

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-04-10 Thread Nikolaos Milas
On 10/4/2013 10:44 πμ, Aki Tuomi wrote: LDFLAGS=-llber ./configure your configure options here OK, this worked! export LDFLAGS=-llber %configure options I am still puzzled why in my case the above export statement was needed, but anyway... And, if we want to link against the custom

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-04-11 Thread Nikolaos Milas
On 11/4/2013 4:20 μμ, a b wrote: Please add -rpath /usr/local/openldap/lib64 to your LDFLAGS so that you do not have to resort to LD_LIBRARY_PATH or ld.so.conf hacks. Hmm, it didn't work like that: LDFLAGS=${LDFLAGS} -L/usr/local/openldap/lib64 -lldap -llber -rpath

Re: [Pdns-users] Building pdns RPMs using custom LDAP libraries/headers

2013-04-11 Thread Nikolaos Milas
On 11/4/2013 9:51 μμ, a b wrote: That means that ./configure is using the compiler front end (gcc) to link the executable, which is correct and good, but is using LDFLAGS to do that, which is a mistake. For linking with the front end, the ./configure script should be using CFLAGS:

[Pdns-users] DNS Failover

2013-04-19 Thread Nikolaos Milas
Hello, We have two SMTP/POP/IMAP/Apache(Webmail) Servers, say mail1.example.com and mail2.example.com and we want to implement DNS-based failover. mail1.example.com is the main one; in case of mail1.example.com failure, DNS should redirect users as soon as possible to mail2.example.com. Is

Re: [Pdns-users] dns flood problem

2013-06-03 Thread Nikolaos Milas
On 3/6/2013 11:48 πμ, Steffan Noord wrote: Last weekend i had a DNS attack Is there some kind of IDS i can install in front of the pdns installation ? Thanxs for any advice on this. Start from fail2ban. Easy to setup and very effective. Regards, Nick

Re: [Pdns-users] dns flood problem

2013-06-03 Thread Nikolaos Milas
On 3/6/2013 1:10 μμ, Steffan Noord wrote: Hello Nick, Do you want to share your config with me. Wat are dns queries that we want to block ? Im starting the logs of pdns on a higher level I see some of these errors Received a malformed qdomain from 194.xx.xx.xx,

Re: [Pdns-users] Configure private subdomain

2015-03-28 Thread Nikolaos Milas
On 4/3/2015 8:17 μμ, Michael Ströder wrote: This sounds a bit like a special case for split horizon DNS. I promised to configure a demo using powerdns with LDAP backend for this based on OpenLDAP ACLs and several powerdns instances using different LDAP identities. Feel free to come here and

Re: [Pdns-users] Configure private subdomain

2015-03-03 Thread Nikolaos Milas
On 3/3/2015 1:48 μμ, bert hubert wrote: I'm not entirely sure I understand your question, since AXFRs are not sent but requested. However, I am sure that 2.9.22 can't do this. Thanks for the reply. You are right. I used wrong terminology; I

Re: [Pdns-users] Configure private subdomain

2015-03-03 Thread Nikolaos Milas
On 3/3/2015 2:44 μμ, Nikolaos Milas wrote: Ideally, we would like pdns to be configured to reply to requests *for particular names* (under a specific subdomain, say internal.example.com) by only providing records (if available, otherwise no results) and hide A records. This way we

[Pdns-users] Naming hosts with public IPv6 and Private IPv4 addresses

2015-03-02 Thread Nikolaos Milas
Hello, I would like to ask for your experience and advice on the following situation: When we use a private IPv4 subnet (e.g. 10.10.10.0/24) with NAT (to access the Internet) and at the same time (i.e. on the same LAN or VLAN) we use a public IPv6 address

Re: [Pdns-users] Configure private subdomain

2015-03-05 Thread Nikolaos Milas
On 5/3/2015 8:53 πμ, Michael Ströder wrote: Yes, IMHO it's far easier to build up a replicated setup with the LDAP backend than with any SQL DB. We are using LDAP replication for powerdns (rather than normal master-slaves) for years. It is a great setup. Unfortunately, Grégory

Re: [Pdns-users] Configure private subdomain

2015-03-04 Thread Nikolaos Milas
On 4/3/2015 8:17 μμ, Michael Ströder wrote: This sounds a bit like a special case for split horizon DNS. Precisely. I promised to configure a demo using powerdns with LDAP backend for this based on OpenLDAP ACLs and several powerdns instances using different LDAP identities. Feel free to

[Pdns-users] TXT domain verification record (using @) issues

2017-01-18 Thread Nikolaos Milas
Hello, I am using PowerDNS 4 with LDAP backend (simple mode). I am facing the problem of having to define a "@" TXT record value for domain verification purposes. I have defined such a record in this way: dn: dc=@,dc=noa.gr,ou=dns1,dc=noa,dc=gr objectClass: dNSDomain2 objectClass:

Re: [Pdns-users] TXT domain verification record (using @) issues

2017-01-19 Thread Nikolaos Milas
On 18/1/2017 4:20 μμ, Nikolaos Milas wrote: I tried to add a tXTRecord to the zone: dn: dc=noa.gr,ou=dns1,dc=noa,dc=gr objectClass: dNSDomain2 objectClass: domainRelatedObject dc: noa.gr associatedDomain: noa.gr nSRecord: vdns.noa.gr nSRecord: dns2.noa.gr nSRecord: sns0

Re: [Pdns-users] TXT domain verification record (using @) issues

2017-01-18 Thread Nikolaos Milas
On 18/1/2017 3:11 μμ, Jan-Piet Mens wrote: Are you sure the '@' doesn't refer to just zone apex, i.e. noa.grTXT "MS=ms..." Hmm, I am not sure. The directions are here:

Re: [Pdns-users] Syslog not logging to configured facility

2016-12-01 Thread Nikolaos Milas
On 1/12/2016 7:47 μμ, Pieter Lexis wrote: On CentOS 7, logging to syslog is disabled in the systemd unit file. You could ship the message via the systemd-journal_or_ create an override unit file to enable syslog. Thank you Pieter for your reply, In my system, rsyslog is in fact enabled

Re: [Pdns-users] Syslog not logging to configured facility

2016-12-02 Thread Nikolaos Milas
On 2/12/2016 11:09 μμ, Pieter Lexis wrote: This is because the systemd-journal is forwarded to syslog. You will need to remove the --disable-syslog flag from the PowerDNS Exec command in the service file to make PowerDNS*itself* log to syslog. Thank you Pieter, Your suggestion did the

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-14 Thread Nikolaos Milas
On 14/12/2017 10:11 μμ, Nikolaos Milas wrote: ... So, I tried disabling recursion entirely and running the Authoritative Server alone. However, the problem persists: ... In the meantime, I upgraded to Auth Server 4.1 (running standalone, without recursion on the same box), but the problem

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-14 Thread Nikolaos Milas
On 14/12/2017 5:23 μμ, Pieter Lexis wrote: It looks like you are using the authoritative server as a recursor for selected clients. This never works the way it is expected (or should). Hi Pieter, Actually, we don't need recursion any more. (It's been left over from the past.) So, I tried

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-14 Thread Nikolaos Milas
On 14/12/2017 11:18 μμ, Eric Beck wrote: Try putting an A record for the domain there. ... Thank you Eric, I may try it; Which IP Address is suggested to be used? The master dns server's IP Address? The organization web server IP Address? Which? Yet, there remain more questions: 1.

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-15 Thread Nikolaos Milas
On 15/12/2017 2:35 μμ, Peter van Dijk wrote: Please do file your issue, with as much detail as possible Thank you Peter, I have filed: https://github.com/PowerDNS/pdns/issues/6097 Important note: After more testing, I found that the issue occurs *only in v4.0.5 and 4.1.0* and NOT in 4.0.4

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-15 Thread Nikolaos Milas
Hello Pieter, Today I downgraded to Auth Server 4.0.3 and, voila!, everything works fine: [root@vdns ~]# rpm -qa | grep pdns pdns-recursor-4.0.8-1pdns.el7.x86_64 pdns-backend-ldap-4.0.3-1pdns.el7.x86_64 pdns-4.0.3-1pdns.el7.x86_64 [root@vdns ~]# pdnsutil check-zone noa.gr Dec 15 12:54:15

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-15 Thread Nikolaos Milas
to help resolve it. Thank you, Nick On 15/12/2017 1:15 μμ, Nikolaos Milas wrote: Please identify the bug and correct it. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-13 Thread Nikolaos Milas
On 13/12/2017 10:53 πμ, Pieter Lexis wrote: ... How is your set up? Please share your pdns.conf and recursor.conf. Also, can you show the output of `pdnsutil check-zone noa.gr`? ... Hi Pieter, Thank you for your reply. I list the details you requested below. I have also included our

Re: [Pdns-users] Dig: zone queries are not answered without the ANY flag

2017-12-12 Thread Nikolaos Milas
10.211#53(194.177.210.211) ;; WHEN: Wed Dec 13 00:44:20 2017 ;; MSG SIZE  rcvd: 74 (But we do get results when querying with the ANY flag, as I have demonstrated already.) What is the real cause of the problem and how to overcome it? Please advise! Thanks again, Nick On 12/12/2017 12:50 πμ,

Re: [Pdns-users] Private IP Addresses in DNS Records

2021-05-14 Thread Nikolaos Milas via Pdns-users
On 14/5/2021 10:17 π.μ., fr...@tembo.be wrote: To keep them hidden, what I would recommend, is to create private.noa.gr  as a separate zone (so add NS records for it in the noa.gr  zone and create a new zone), and add example.privrate.noa.gr

[Pdns-users] Private IP Addresses in DNS Records

2021-05-13 Thread Nikolaos Milas via Pdns-users
Hello, We are using PowerDNS Authoritative Server 4.1.14 with LDAP backend. In our setup we are hosting our organization domain (noa.gr) and there is a number of additional servers which are synced via AXFR. In this setup we do NOT host name records for internal hosts with private ip

Re: [Pdns-users] Upgrading Auth Server directly from 4.1.14 to 4.4.1

2021-05-21 Thread Nikolaos Milas via Pdns-users
On 21/5/2021 2:08 π.μ., Michael Ströder wrote: Do you really need the launch suffix 'bkend2' for the bindbackend parameters? Hi Michael, thanks for the reply. I simply had left this part of the config as it was (working before upgrade) at version 4.1.14. Obviously, bind suffix support was

Re: [Pdns-users] Upgrading Auth Server directly from 4.1.14 to 4.4.1

2021-05-20 Thread Nikolaos Milas via Pdns-users
On 19/5/2021 10:20 μ.μ., Brian Candler wrote: There is no state stored in pdns-auth itself, other than the state in the backend.  So as long as you change your backend to be compatible with 4.4.1, I see no reason why you can't jump straight to 4.4.1. Of course you should first do this in a

[Pdns-users] Upgrading Auth Server directly from 4.1.14 to 4.4.1

2021-05-19 Thread Nikolaos Milas via Pdns-users
Hello, We are (still) using PowerDNS Auth Server 4.1.14 (on CentOS 7) with LDAP backend (simple mode). Can we upgrade directly to 4.4.1 provided we do pertinent config changes as described in the upgrade guide, or it is suggested to upgrade in steps, e.g. to the last point release of each

Re: [Pdns-users] Private IP Addresses in DNS Records

2021-05-14 Thread Nikolaos Milas via Pdns-users
On 14/5/2021 3:50 μ.μ., Kevin P. Fleming wrote: I agree with this sentiment; my publicly-visible zones contain records with both private addresses and with non-reachable public addresses (IPv6 GUAs), and I'm fine with that. If someone can learn the address of one of those systems, that doesn't

[Pdns-users] Master Support with LDAP Backend

2021-06-02 Thread Nikolaos Milas via Pdns-users
On 19/5/2021 9:40 μ.μ., Nikolaos Milas via Pdns-users wrote: By the way, the LDAP backend documentation states "Master (support): No", yet there is a section (Master Mode) with configuration for Master operation.These changes will allow master operation in the future, or rather mast

Re: [Pdns-users] Master Support with LDAP Backend

2021-07-08 Thread Nikolaos Milas via Pdns-users
On 7/6/2021 1:40 μ.μ., Peter van Dijk via Pdns-users wrote: It is in fact available. The 'No' is wrong. I have just merged a documentation fix for that (should be visible in a few minutes). Thank you very much Peter, I somehow missed your reply and came across it only today. That is good