DNSSEC: validation with dnssec-must-be-secure AND dnssec-lookaside fails

2015-02-26 Thread Robert Senger
Hi all, I am struggling with weird behaviour of bind9 acting as authenticating resolver, when querying DNSSEC enabled domains that are using DLV. My registrar is still unable to sign DS records. Everything works fine if only dnssec-lookaside auto option is set in the resolver's

Re: order of masters IP addresses in slave/stub zone?

2015-02-26 Thread Barry Margolin
In article mailman.1698.1424913638.26362.bind-us...@lists.isc.org, Hillary Nelson nelsonhilla...@gmail.com wrote: I was asked to add some backup master IP addresses to a slave zone file for some HCP system, but those IPs not active and can't do zone transfer until system failover. My

Re: Have question using bind9 for local dns proxy

2015-02-26 Thread Tony Finch
Junyoung Park killers2...@gmail.com wrote: but i want to send query to clients original dns server instead of root ns. (if client pc DNS server set 8.8.8.8, i want to send 8.8.8.8 instead of root dns servers) (i can't use forward / forwarders options because clinets PC DNS server setting is