Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-11 Thread Mark Andrews
> On 11 Sep 2020, at 22:22, Rob McEwen wrote: > > On 9/11/2020 2:46 AM, Mark Andrews wrote: >> validate-except (I typo’d it the second time, unfortunately expect and >> except are both valid words). > > I got so far down the rabbit trail with your other points, somehow I missed > that.

Help us weed out the old crap in the ISC KB

2020-09-11 Thread Victoria Risk
BIND-users, I am doing a review of the older articles in our Knowledgebase, updating those I can and unpublishing those I cannot update. I am sure everything in there was accurate when it was written, but of course the software, and the overall Internet, have evolved. I found articles in there

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-11 Thread Rob McEwen
On 9/11/2020 2:46 AM, Mark Andrews wrote: validate-except (I typo’d it the second time, unfortunately expect and except are both valid words). I got so far down the rabbit trail with your other points, somehow I missed that. Thanks. This should solve my problem! If you actually used a

RRSIG and TTL

2020-09-11 Thread Scott Nicholas
I was hoping someone's experience could save me as I've spent too much time down this rabbit hole. Primary nameserver is behind a cache/proxy on enterprise network such that all external traffic hits this. Zone went bogus. I blame policy but on further inspection 2/3 proxys had differing TTL

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-11 Thread Mark Andrews
validate-except (I typo’d it the second time, unfortunately expect and except are both valid words). https://downloads.isc.org/isc/bind9/9.16.6/doc/arm/Bv9ARM.pdf validate-except This specifies a list of domain names at and beneath which DNSSEC validation should not be performed, regardless