Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-26 Thread jasonsu
On Tue, Apr 26, 2016, at 11:18 AM, Matthew Pounsett wrote: > Both things together are better than either one alone. Thanks for the explanation. upstream bind-chroot with systemd should be easier and better documented ___ Please visit

Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-26 Thread Matthew Pounsett
On 25 April 2016 at 11:44, wrote: > > > > I completely gave up on chroot'd ntpd because of the endless weirdness. > Finally just moved to openntpd as (1) it had safe privsep, (2) no chroot > req'd, and (3) did the job I need. > Privsep doesn't actually fix the same

Re: Reload only ACL

2016-04-26 Thread Bob Harold
On Tue, Apr 26, 2016 at 10:22 AM, Ali Jawad wrote: > Hi Bob > I did have a look at > http://www.zytrax.com/books/dns/ch7/rpz.html#policy-client-ip-trigger , > and while in theory it can be used in a way similar to ACL I cant see how > it accommodates for faster changes,

Re: Reload only ACL

2016-04-26 Thread Ali Jawad
Hi Bob I did have a look at http://www.zytrax.com/books/dns/ch7/rpz.html#policy-client-ip-trigger , and while in theory it can be used in a way similar to ACL I cant see how it accommodates for faster changes, would you please elaborate ? On Tue, Apr 26, 2016 at 4:46 PM, Bob Harold

Re: Reload only ACL

2016-04-26 Thread Bob Harold
On Mon, Apr 25, 2016 at 5:30 PM, Carl Byington wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On Mon, 2016-04-25 at 23:23 +0300, Ali Jawad wrote: > > based on a user tool the users "hundreds in corporate environment" get > > either public or private zone, > >