Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread John Marshall
On Sun, 13 Jun 2010, 12:53 -0700, Doug Barton wrote: On 06/11/10 02:51, John Marshall wrote: Is there something else I need to do to nudge BIND in the direction of libgssapi_krb5 in /usr/local ? Until now I've never built BIND with gssapi, so I'm prepared to be told I've missed something

Re: Request Redirect

2010-06-15 Thread Jorge Fábregas
On Tuesday 15 June 2010 07:52:34 sasa sasa wrote: we have 2 network, when network 1 request www.example.com i want to reply with x.x.x.x A record, and when network 2 request www.example.com i want to reply with y.y.y.y A record. is that possible in Bind configuration? Hi, Sure. Check out Bind

the one A record that must be in a Zone

2010-06-15 Thread Martin McCormick
We have our main domain of okstate.edu plus a ton of non-okstate.edu names that we serve because someone purchased the name. Each of these small zones has per haps one or two A records and 99.9% of the time, the A records are redundant A records that are the same as some host on our

Re: the one A record that must be in a Zone

2010-06-15 Thread Doug Barton
On 06/15/10 09:53, Martin McCormick wrote: Is there any kind of dummy A record one can stuff in to a zone which satisfies this requirement such that one can then use aliases or CNAME records for the valid hosts in the zone? localhost A 127.0.0.1 hth, Doug --

RE: the one A record that must be in a Zone

2010-06-15 Thread Lightner, Jeff
Do they all actually use separate IPs? Here we have multiple domains that all go to the same web server many of which are going to the same NATed IP. For those we just create a zone (e.g. okstate-aliases) with standard setup and then the A record we have is for @ like: @ IN SOA

Re: Microsoft's nslookup Implementation Problems

2010-06-15 Thread Steve Shockley
On 6/13/2010 4:00 PM, Merton Campbell Crockett wrote: Inspecting the query log on the name server indicates that BIND never services a request from the system running Microsoft's nslookup tool. In addition, using tcpdump in controlled tests, I find that Microsoft's nslookup implementation never

Re: Microsoft's nslookup Implementation Problems

2010-06-15 Thread Tim Maestas
One thing I also learned recently is that the Cisco IPSEC VPN client dialer hijacks all UDP DNS packets and sends them to the DNS server handed out by the VPN concentrators. So dig @x.x.x.x and nslookup foo.bar x.x.x.x queries don't actually go to x.x.x.x. Don't know if that's in play here but

Re: Request Redirect

2010-06-15 Thread Kevin Darcy
Since views require parallel maintenance of zone data, they are somewhat of a heavyweight/sledgehammer approach to the problem. Subject to certain caveats, the sortlist feature may be a better fit for this requirement, i.e. define the name with *both* IP addresses, and then sort the answers

Re: the one A record that must be in a Zone

2010-06-15 Thread Chris Thompson
On Jun 15 2010, Martin McCormick wrote: We have our main domain of okstate.edu plus a ton of non-okstate.edu names that we serve because someone purchased the name. Each of these small zones has per haps one or two A records and 99.9% of the time, the A records are redundant A records

Re: Bind 9.7.0-P2 Bus Error - Solaris 9

2010-06-15 Thread b19141
At Mon, 14 Jun 2010 09:06:50 -0500 (CDT), b19...@anl.gov wrote: This morning on a Solaris 9 system, I issued these comands: JINMEI Tatuya / jin...@isc.org replied: I believe I found the cause of the bug. Please try the patch copied below. I tested the patch on Solaris 9 and 10, and no

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread Mark Andrews
In message slrni1ea5q.10j.j...@rwpc12.mby.riverwillow.net.au, John Marshall w rites: On Tue, 15 Jun 2010 16:52:05 +1000, Mark Andrews wrote: So what was in config.log? With libgssapi_krb5 you are trying to link against MIT kerberos. Sorry, s/_krb5// (Heimdal) The config.log is here,

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread John Marshall
On Wed, 16 Jun 2010, 09:12 +1000, Mark Andrews wrote: In message slrni1ea5q.10j.j...@rwpc12.mby.riverwillow.net.au, John Marshall w rites: On Tue, 15 Jun 2010 16:52:05 +1000, Mark Andrews wrote: So what was in config.log? With libgssapi_krb5 you are trying to link against MIT

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread Mark Andrews
In message 20100615233907.gd1...@rwpc12.mby.riverwillow.net.au, John Marshall writes: On Wed, 16 Jun 2010, 09:12 +1000, Mark Andrews wrote: In message slrni1ea5q.10j.j...@rwpc12.mby.riverwillow.net.au, John Marsha ll w rites: On Tue, 15 Jun 2010 16:52:05 +1000, Mark Andrews wrote:

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread Mark Andrews
In message 20100615233907.gd1...@rwpc12.mby.riverwillow.net.au, John Marshall writes: On Wed, 16 Jun 2010, 09:12 +1000, Mark Andrews wrote: In message slrni1ea5q.10j.j...@rwpc12.mby.riverwillow.net.au, John Marsha ll w rites: On Tue, 15 Jun 2010 16:52:05 +1000, Mark Andrews wrote:

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread John Marshall
On Wed, 16 Jun 2010, 10:06 +1000, Mark Andrews wrote: libgssapi_krb5 is from MIT Kerberos. ...and from FreeBSD's implementation of Heimdal rwsrv05 cat /usr/src/kerberos5/include/version.h /* $FreeBSD: src/kerberos5/include/version.h,v 1.15.2.1.4.1 2010/06/14 02:09:06 kensmith Exp $ */

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread Mark Andrews
In message 20100616004753.ge1...@rwpc12.mby.riverwillow.net.au, John Marshall writes: On Wed, 16 Jun 2010, 10:06 +1000, Mark Andrews wrote: libgssapi_krb5 is from MIT Kerberos. ...and from FreeBSD's implementation of Heimdal rwsrv05 cat /usr/src/kerberos5/include/version.h /*

Re: Can't get BIND to use GSSAPI from /usr/local on FreeBSD

2010-06-15 Thread John Marshall
On Wed, 16 Jun 2010, 11:04 +1000, Mark Andrews wrote: The alternative is to edit configure.in to only have the libraries in the port version where configure checks for which set of libraries needed and run autoheader + autoconf followed by configure. Thanks. configure.in looks like the place