Re: Email migration and MX records

2023-01-06 Thread Bruce Johnson via bind-users
ists.isc.org<mailto:bind-users@lists.isc.org> https://lists.isc.org/mailman/listinfo/bind-users -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely customs -- Visit https://lists.isc.org/mailman/listinfo/bind-users to un

Email migration and MX records

2023-01-03 Thread Bruce Johnson via bind-users
the main campus tenant cannot start accepting email for our domain until we’ve transferred the email domain between tenants, so we cannot just change the MX record in our DNS server to the University’s (a Cisco Ironport setup) -- Bruce Johnson University of Arizona College of Pharmacy

Re: Move from Development to Production

2022-08-26 Thread Bruce Johnson via bind-users
ists.isc.org/mailman/listinfo/bind-users -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely customs -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the develo

Re: Setting Up An Running Your Own Dmarc using Bind DNS

2022-06-27 Thread Bruce Johnson via bind-users
netassoc.net<http://netaccoc.net> as the domain the dmarc record is for. At least I do not have that CNAME set for my domain and DMARC passes all the tests. -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely cu

Re: Probably stupid simple question...

2022-06-01 Thread Bruce Johnson via bind-users
Thanks! On Jun 1, 2022, at 1:48 PM, Sandro mailto:li...@penguinpee.nl>> wrote: On 01-06-2022 20:07, Bruce Johnson via bind-users wrote: I am migrating our BIND system to a new server/BIND version, and have a question about dynamically updated zone files (we have one dynamic zone). I a

Probably stupid simple question...

2022-06-01 Thread Bruce Johnson via bind-users
or will just stopping the bind service properly deal with updating the zone file? Also do I need to copy over the .jnl file when I do this or will a new one get generated as needed? -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have

Has anyone run Sophos Server Protection on a linux system running bind?

2022-02-18 Thread Bruce Johnson via bind-users
kind I’m thinking that there's no real avenue for malware to get on this system (beyond some sort of 0-day in the software that is running…) so it’s probably not necessary; but if we get told we have to, does anyone foresee any issues with it interfering with DNS? -- Bruce Johnson University

odd MX entry error in zone file

2022-02-03 Thread Bruce Johnson via bind-users
2d::30 l.gtld-servers.net. 53266 IN 2001:500:d937::30 ;; Query time: 15 msec ;; SERVER: 128.196.116.5#53(128.196.116.5) ;; WHEN: Thu Feb 03 10:26:49 MST 2022 ;; MSG SIZE rcvd: 907 And I don’t see anything in the logs about this. -- Bruce Johnson University of Arizona College of P

Re: Error staring named, permissions denied on named.ca

2021-12-09 Thread Bruce Johnson via bind-users
Ugh, forgot about that…that was it. Thanks! On Dec 9, 2021, at 3:48 PM, Mark Andrews mailto:ma...@isc.org>> wrote: Almost certainly SELinux or AppArmor on the new platform getting in the way. On 10 Dec 2021, at 06:08, Bruce Johnson via bind-users mailto:bind-users@lists.isc.org&g

Error staring named, permissions denied on named.ca

2021-12-09 Thread Bruce Johnson via bind-users
e way in named.conf, but that’s running and ancient version BIND 9.8.2rc1-RedHat-9.8.2-0.68.rc1.el6_10.1 (and why I’m building a new one!) -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opin

Re: named service suddenly fails to start

2021-11-04 Thread Bruce Johnson via bind-users
of zone files is disabled"; fi (code=exi this nonsense of bash in systemd units typically comes from distributions and so you should at least name which one you are using In this case it is CentOS8. -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Ins

Re: named service suddenly fails to start

2021-11-04 Thread Bruce Johnson via bind-users
On Nov 4, 2021, at 12:01 PM, Bruce Johnson mailto:john...@pharmacy.arizona.edu>> wrote: This morning our server started failing to reload or start. checking the status reveals not a lot of info: systemctl status named-chroot ● named-chroot.service - Berkeley Internet Name Domain (DNS)

named service suddenly fails to start

2021-11-04 Thread Bruce Johnson via bind-users
of zone files; is there a particular order in which they’re loaded at startup? I’ve made no changed to named.conf or anything else on this server. -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely customs ___

DKIM setup

2021-08-11 Thread Bruce Johnson via bind-users
-00725 ) alice._domainkey.itverx.com.ve.86400 IN TXT “v=…ZZZ” Is alice, in this case, the server with the MTA and private keys and itverx.com the base domain of the zone? IE alice.itverx.com is the server that is signing the emails? what is the .ve. part? -- Bruce Johnson University

Re: Odd A record in our hosts zone file

2021-06-25 Thread Bruce Johnson
r-fqdn} is only valid for 60 seconds. As you say, a cheap load balancing attempt! Best, Richard. -Original Message- From: bind-users On Behalf Of Bruce Johnson Sent: 25 June 2021 6:56 pm To: bind-users@lists.isc.org Subject: Odd A record in our hosts zone file I ran across these A r

Odd A record in our hosts zone file

2021-06-25 Thread Bruce Johnson
’ notation? I haven’t been able to find that in my searching of the manual. (We’re adding new servers and I need to make sure our DNS is properly set for them.) -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely

Re: BIND 9.16.13 and Mac OS X 10.13.6 - problems with ./configure

2021-03-26 Thread Bruce Johnson
f named. (probably /usr/local/opt/bind/sbin judging from the screen shot) If the previous version was installed as part of Mac OS Server, or MacPorts, for example that binary will live somewhere other than /usr/local. -- Bruce Johnson University of Arizona College of Pharmacy Informatio

Re: Dynamic zone update problems, continued

2021-03-05 Thread Bruce Johnson
Turne out to be a dumdum mistake on my part. SELinux was set to enforce…set it to permissive and voila! the .jnl file was created. I coulda sworn I’d fixed that before... > On Mar 5, 2021, at 12:39 PM, Grant Taylor via bind-users > wrote: > > On 3/5/21 12:07 PM, Bruce J

Re: Dynamic zone update problems, continued

2021-03-05 Thread Bruce Johnson
:39 PM, Grant Taylor via bind-users mailto:bind-users@lists.isc.org>> wrote: On 3/5/21 12:07 PM, Bruce Johnson wrote: Fixing the permissions and restarting named got dynamic updating working again, but new systems (ie names that are NOT already in the Zone file ) are throwing errors

Re: Dynamic zone update problems, continued

2021-03-05 Thread Bruce Johnson
t; journal open failed: unexpected error BJ> Is there a specific command to create the .jnl file? I thought BJ> named created it automatically as needed. (at least the BJ> named-journalprint man page indicates this…) -- Bruce Johnson University of Arizona College of Pharmacy Information

Dynamic zone update problems, continued

2021-03-05 Thread Bruce Johnson
it automatically as needed. (at least the named-journalprint man page indicates this…) -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely customs ___ Please visit https

Re: Zone set for dynamic updating isn't updating

2021-03-04 Thread Bruce Johnson
update and move them into place once they are complete. If you are running Linux also se SELinux settings as they add additional constraints. Additionally if you are running as root named does not have permission to override file permissions root normally has. -- Bruce Johnson University of A

Zone set for dynamic updating isn't updating

2021-03-04 Thread Bruce Johnson
of our (name) vlans, but checking the config syntax with named-checonf -z shows all are properly loading, and the zone transfers after the manual update did work. -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opin

Possibly stupid Q

2021-01-20 Thread Bruce Johnson
print-time yes; print-category yes; print-severity yes; severity info; }; in named-chroot do these go to the actual system /var/named/log or does the named-chroot process put them in /var/named/chroot/var directory? -- Bruce Johnson University of Arizo

Re: BIND through COPR after CentOS

2020-12-18 Thread Bruce Johnson
ists.isc.org/mailman/listinfo/bind-users -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely customs ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsub

Re: Serial number question..

2020-12-17 Thread Bruce Johnson
Thanks, that worked perfectly! > On Dec 17, 2020, at 12:02 PM, Reindl Harald wrote: > > > > Am 17.12.20 um 19:56 schrieb Bruce Johnson: >> Someone updated out name server and messed up the serial number on the >> primary; as a result our secondaries are not up

Serial number question..

2020-12-17 Thread Bruce Johnson
1209600 86400 Is the fix here just setting the serial number on the primary to 1762233708 ? The various things online I’ve found are all based on “you accidentally set the primary more than 2^32 ahead” so you have to do a bunch of modulo arithmetic... -- Bruce Johnson University of Arizona College

Re: Testing a new master server...

2020-11-19 Thread Bruce Johnson
kes me feel a lot more confident that I'm on the right track. Regardless, I do hope your migration goes smooth! John -Original Message- From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Bruce Johnson Sent: Wednesday, November 18, 2020 11:35 AM To: bind-users@

Testing a new master server...

2020-11-18 Thread Bruce Johnson
that would actually talk to it would be ones that specify that IP address for resolution. Am I missing something or overcomplicating things? -- Bruce Johnson University of Arizona College of Pharmacy Information Technology Group Institutions do not have opinions, merely customs