Re: Followup: BIND 9.10.6-P1 dnssec update zone A record

2018-03-29 Thread Kim Culhan
un "rndc zonestatus " on it. > Then I look for the "serial:" and "signed serial:" values.On Thu, Mar 29, 2018 at 5:17 PM, Douglas C. Stephens wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Kim, > > I run BIND 9.11 so this might or might not translate down to

Re: Followup: BIND 9.10.6-P1 dnssec update zone A record

2018-03-29 Thread Douglas C. Stephens
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Kim, I run BIND 9.11 so this might or might not translate down to BIND 9.10. When this happens to me, I run "rndc zonestatus " on it. Then I look for the "serial:" and "signed serial:" values. Normally, you would be correct in only needing to

Followup: BIND 9.10.6-P1 dnssec update zone A record

2018-03-29 Thread Kim Culhan
Some additional info here, from named.conf, dnssec config: options { directory "/var/named"; [lines omitted] dnssec-validation auto; managed-keys-directory "/var/named/keys"; >From the zone section; file "domain.com.signed"; key-directory "/var/named/keys/domain.com";

Cause BIND 9.10.6-P1 running dnssec to update zone A record

2018-03-29 Thread Kim Culhan
Made a change to an ip address in an A record and bind is still showing the old address. Updated the serial and it doesn't show the new serial either. How can I get bind to update from the data in the zone file? I 've restarted named and used rndc to reload and have not found how to get it to

RPZ for A and AAAA queries

2018-03-29 Thread Job via bind-users
Dear Guys, is it possible to configure two different replies, related to A or query? For example, in a RPZ zone, i would like this scenario: www.site.com A 1.2.3.4 www.site.com (CNAME to www.site.com) -> in order to resolve regularly the query Is there a way to