RHEL, Centos, Rocky, Fedora rpm 9.18.27

2024-05-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.18.26

2024-04-17 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.18.25

2024-03-22 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.18.24

2024-02-13 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

HEL, Centos, Rocky, Fedora rpm 9.18.21

2023-12-23 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.44

2023-09-20 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.42

2023-06-22 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.41

2023-05-17 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.40

2023-04-20 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.38

2023-02-15 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.37

2023-01-25 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.35

2022-11-16 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

Re: Reverse lookups not working when Internet connection failed.

2022-11-06 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sun, 2022-11-06 at 14:39 +0100, Matus UHLAR - fantomas wrote: > alternatively they can choose to 0/28.66.136.193.in-addr.arpa. or > 0-15.66.136.193.in-addr.arpa. > instead of 0-28.66.136.193.in-addr.arpa. or use

RHEL, Centos, Rocky, Fedora rpm 9.16.33

2022-09-21 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.31

2022-07-22 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Rocky, Fedora rpm 9.16.30

2022-06-21 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Fedora rpm 9.16.28

2022-04-23 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

Re: Can an RPZ record be used for a non-existed domain?

2022-03-24 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2022-03-24 at 16:13 -0600, Grant Taylor via bind-users wrote: > But there seems to be a disconnect. > I was talking about adding a domain that is outbound.example.com. and > put the A / records in that domain's apex. Thus you are

Re: Can an RPZ record be used for a non-existed domain?

2022-03-24 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2022-03-24 at 12:16 -0600, Grant Taylor via bind-users wrote: > What advantage does RPZ have in this case over just hosting the > domain(s) locally? In general, the domain exists with a bunch of existing names - www, mail, etc. We just need

Re: Can an RPZ record be used for a non-existed domain?

2022-03-24 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2022-03-24 at 16:48 +0100, Benny Pedersen wrote: > > Is it possible to add records for non-existing domains to the RPZ? I think so. > what is the point ? Presumably to create those domains locally. Of course the rest of the world won't

RHEL, Centos, Fedora rpm 9.16.24

2021-12-15 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Fedora rpm 9.16.23

2021-11-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Fedora rpm 9.16.22

2021-10-28 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

Re: force nameserver(bind) information exchanges with clients via tcp only

2021-09-30 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2021-09-30 at 16:30 -0700, Fred Morris wrote: > https://github.com/m3047/tcp_only_forwarder So what exactly are the media devices doing to screw up dns resolution between the osx laptop and the local dns server? -BEGIN PGP

RHEL, Centos, Fedora rpm 9.16.20

2021-08-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Fedora rpm 9.16.18

2021-06-22 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

RHEL, Centos, Fedora rpm 9.16.17

2021-06-16 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

Re: Any interest in a write-up showing how to configure BIND 9.17x with DoH and LetsEncrypt?

2021-05-30 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sun, 2021-05-30 at 15:24 +, Richard T.A. Neal wrote: > Is there any interest in me writing this up as a web article, or has > everyone who's interested in DoH already got it running comfortably in > their test environment? I am interested.

RHEL, Centos, Fedora rpm 9.16.16

2021-05-25 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpm, and build instructions. This .src.rpm contains a .tar.gz file with the ARM documentation, so the rpm rebuild process does not need sphinx- build and associated dependencies.

Re: Preventing a particular type of nameserver abuse

2021-04-14 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2021-04-14 at 12:58 -0400, Paul Kosinski via bind-users wrote: > Interesting, although we host different domains, in and from different > geographic areas, we got the same queries as yours on the same day, > with some at about the same time

Re: FW: Preventing a particular type of nameserver abuse

2021-04-13 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2021-04-13 at 22:42 +, Richard T.A. Neal wrote: > Yes, another individual & I were discussing this off-list today. We > wonder if those queries are from malware on infected hosts that are > trying to determine whether a given nameserver

Re: Preventing a particular type of nameserver abuse

2021-04-13 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2021-04-13 at 22:32 +0200, Julien Salort wrote: > Reading this thread, I considered simply enabling the fail2ban > named-refused jail, but they advise against it because it would end > up > blocking the victim rather than the attacker. In

Re: 9.16.13 overwrote master files

2021-04-11 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Issue #2623 opened at gitlab. It appears to be tied to attempts to use the old journal format: zone local/IN/normal: retried using old journal format -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCYHM0bhUcY2FybEBmaXZl

Re: 9.16.13 overwrote master files

2021-03-30 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2021-03-30 at 15:45 +1100, Mark Andrews wrote: > can you add a "#" in front of "dnssec-policy" in bin/named/config.c > and see how that goes for you. That will comment out the default > 'dnssec-policy "none";'. I have not been able to

9.16.12 tries to read keys that it does not need?

2021-03-29 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 dns_dnssec_findmatchingkeys: error reading key file Kfive-ten- sg.com.+008+39376.private: permission denied Those key files are 0600 root:root. Bind should never need to read them since we are not doing in-line signing or key rotation within bind.

Re: 9.16.13 overwrote master files

2021-03-28 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Mon, 2021-03-29 at 12:54 +1100, Mark Andrews wrote: > What do you have in options? options { directory "/var/named"; allow-recursion { "friends"; }; dnssec-enable yes; dnssec-validation auto; bindkeys-file

9.16.13 overwrote master files

2021-03-27 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I just updated from 9.16.12 to 9.16.13. zone "naturediscovery.org" { type master; file "named.naturediscovery.org"; }; 9.16.13 has overwritten the master file with the current zone contents, replacing the $INCLUDE statements with the contents of

RHEL, Centos, Fedora rpm 9.16.12

2021-02-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCYC6iThUcY2FybEBmaXZl

RHEL, Centos, Fedora rpm 9.16.10

2020-12-17 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX9uRhRUcY2FybEBmaXZl

RHEL, Centos, Fedora rpm 9.16.9

2020-11-26 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX8APLhUcY2FybEBmaXZl

RHEL, Centos, Fedora rpm 9.16.8

2020-10-23 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. Thanks to Espen Stefansen for spec updates, this should work on EL8 systems with ipa-client. -BEGIN PGP SIGNATURE-

RHEL, Centos, Fedora rpm 9.16.7

2020-09-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCX2ToIhUcY2FybEBmaXZl

Re: Do not cache certain domains

2020-09-10 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2020-09-10 at 15:35 +0100, Ben Lavender wrote: > Anyone think they may know the answer to this? With the cooperation of the "certain domains" master servers, just slave the zones. The masters should be configured to send you notify messages

Re: RHEL, Centos, Fedora rpm 9.16.6

2020-09-04 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2020-08-20 at 12:20 -0700, PGNet Dev wrote: > Are they otherwise unrelated? Mine are intended as an in-place replacement/update from the bind versions in RHEL/Centos 7 and 8. The same file layout, etc. This is as close as I can come to a

Re: Response Policy Zone: disabling "leaking" of lookups

2020-09-02 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2020-09-02 at 17:47 -0700, Fred Morris wrote: > how do I disable the (useless) resolution directed at upstream > servers? Isn't that just "qname-wait-recurse no;" -BEGIN PGP SIGNATURE-

Re: rpmbuild problem with 9.11.22 on Centos

2020-08-29 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sat, 2020-08-29 at 19:06 +0100, Matthew Richardson wrote: > My guess (which may be wrong) is that something is wrong with the > line:- > %set_build_flags > in bind.spec. It looks like isc is depending on some rpm macros from epel yum

RHEL, Centos, Fedora rpm 9.16.6

2020-08-20 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCXz7EtRUcY2FybEBmaXZl

RHEL, Centos, Fedora rpm 9.16.5

2020-07-22 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- iHMEAREKADMWIQSuFMepaSkjWnTxQ5QvqPuaKVMWwQUCXxiM4BUcY2FybEBmaXZl

RHEL, Centos, Fedora rpm 9.16.4

2020-06-17 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. geoip support is not available, since geoip2 is not available in the epel repositories. libuv is in the EL7 epel repository; for EL6 a link is

9.16.3 make tests on centos 8

2020-05-31 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Trying to build on centos 8, all the tests except one pass. I get a failure in bin/tests/system/runtime/tests.sh I:runtime:checking that named logs an ellipsis when the command line is larger than 8k bytes (13) I:runtime:verifying that named

RHEL, Centos, Fedora rpm 9.16.3

2020-05-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. geoip support is not available, since geoip2 is not available in the epel repositories. libuv is in the EL7 epel repository; for EL6 a link is

RHEL, Centos, Fedora rpm 9.16.2

2020-04-23 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. geoip support is not available, since geoip2 is not available in the epel repositories. libuv is in the EL7 epel repository; for EL6 a link is

RE: NAT and Question Section Mismatch

2020-04-21 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2020-04-21 at 14:08 -0400, John Wiles wrote: ;; ;; Question section mismatch: got 17.1.1.10.in-addr.arpa/PTR/IN tcpdump is your friend. Dump the outgoing packets from your home connection to see exactly what you are sending for: dig

Re: bind 9.16.2 on centos6

2020-04-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sun, 2020-04-19 at 09:07 +0200, Ondrej Sury wrote: > I would suggest starting with vanilla libuv from sources, or at least > review the patches the RPM applies on top of the RPM. There are none. That rpm is just a wrapper around the stock

Re: bind 9.16.2 on centos6

2020-04-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 > Is this the same issue previously reported against 9.16.1? That was > apparently resolved by downgrading to libuv 1.35. In my case, I can > try > to upgrade to 1.35. Nope, libuv 1.35.0 does not change the crash. -BEGIN PGP SIGNATURE-

bind 9.16.2 on centos6

2020-04-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Centos6, although old, is still supported, so it would be nice to get 9.16.2 running on that. This is my first attempt at building 9.16.x. I pulled the libuv source rpm from Centos7, made some minor changes to the spec file, and built libuv 1.34.0.

RE: Slow recursive query performance on Windows x64

2020-01-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sun, 2020-01-19 at 21:54 -0500, Steve Farr via bind-users wrote: > Does anyone know of a functionality that replaced the now-obsolete > filter--on-v4? plugin query "filter-.so" { filter--on-v4 yes; }; -BEGIN PGP

RHEL, Centos, Fedora rpm 9.14.8

2019-11-20 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl3VnVMACgkQL6j7milTFsGv4ACfZBdGLuzuSS+5n1+yU4XGlH3u

RHEL, Centos, Fedora rpm 9.14.7

2019-10-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl2qWNcACgkQL6j7milTFsF8BwCfYQAStqPziT2iCMWxyquxo/3n

RHEL, Centos, Fedora rpm 9.14.6

2019-09-29 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl2Q8rYACgkQL6j7milTFsHbqQCfW4iTTxaJUcvuRphFj5ALnctC

Re: SERVFAIL when looking up TXT from particular domain

2019-06-26 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2019-06-26 at 13:16 +, Dennis via bind-users wrote: > dig TXT cleanmail4.capgeminioutsourcing.nl @localhost dig TXT cleanmail4.capgeminioutsourcing.nl +nodnssec @ns1.capgeminioutsourcing.nl. ;; MSG SIZE rcvd: 124 dig TXT

RHEL, Centos, Fedora rpm 9.14.3

2019-06-19 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl0KrX8ACgkQL6j7milTFsFuyQCfZyov2lJnPYxKngKucU8eNw+z

Re: [External] Re: Request assistance configuring RPZ

2019-05-29 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2019-05-29 at 09:05 -0400, David Bank wrote: > Re-reading the ARM, it seemed to me that I needed to add a After adding the zone and the response-policy statement to named.conf, I presume you did: rndc reconfig To test that you can:

Re: [External] Re: Request assistance configuring RPZ

2019-05-28 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2019-05-28 at 13:13 -0400, David Bank wrote: > Perhaps I'm missing something, but I don't see how to make zurg reply > with 192.168/16 IPs for andy and sid, but correctly resolve the rest > of *.internal.local On zurg, add a new dns zone

Re: BIND 9.11.6-P1 build fails on Solaris

2019-05-02 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Fri, 2019-04-26 at 10:41 +1000, Nick Edwards wrote: > lots of things failing in recent times, even with CentOS, mostly > because of openssl min version changes, and most recently even latest > releases wont build now because of a change in min

bind 9.14.1 qname-minimization

2019-04-26 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 The default for the qname-minimization option is relaxed, but with that, we cannot resolve the PTR for 142.136.234.134. dig -x 142.136.234.134 @localhost ; <<>> DiG 9.14.1 <<>> -x 142.136.234.134 @localhost ;; global options: +cmd ;; Got answer:

RHEL, Centos, Fedora rpm 9.14.1

2019-04-24 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlzA/HQACgkQL6j7milTFsG5CgCfROG2P4f8SbtEA8GUWC6cv3rs

9.14.0 filter-aaaa

2019-04-14 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 view "normal" { plugin query "filter-.so" { filter--on-v4 yes; filter- { "brokenv6"; }; }; named-checkconf likes that, but named gets a segfault in filter-.so. Anyone using filter-.so in a working

RHEL, Centos, Fedora rpm 9.12.4

2019-03-02 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlx0X4IACgkQL6j7milTFsGukwCfRSD9xFL5WHo0bZYi+6aOHBYY

RHEL, Centos, Fedora rpm 9.12.3-P4

2019-02-25 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlx0X4IACgkQL6j7milTFsGukwCfRSD9xFL5WHo0bZYi+6aOHBYY

Re: dig @ipv6-address

2018-11-29 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2018-11-29 at 15:26 -0500, Barry Margolin wrote: > But it also seems like it's using its own form of abbreviation, since > there aren't 8 hex fields before that. "man netstat" on centos6 -T --notrim Stop trimming long addresses.

RHEL, Centos, Fedora rpm 9.12.2-P2

2018-09-20 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEUEAREKAAYFAlujy2cACgkQL6j7milTFsG/FgCXXEW71A92n5oOeMXP+K1F9kAt

Re: Frequent timeout

2018-09-11 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2018-09-11 at 14:19 -0400, Alex wrote: > This is when our 20mbs cable upstream link was saturated and resulted > in DNS query timeout errors. resulting in these SERVFAIL messages. Not specific to dns, but this looks like a bufferbloat

RE: [BIND] RE: KSK Rollover

2018-09-06 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2018-09-06 at 20:58 +, Brent Swingle wrote: > I left all of the permissions the same and I think they should be > lenient enough: > [root@ns3 named]# ls -lh named.secroots > -rw-rw-rw-. 1 named named 0 Sep 6 13:52 named.secroots Does

Re: Frequent timeout

2018-09-03 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sun, 2018-09-02 at 21:54 -0400, Alex wrote: > Do you have any other ideas on how I can isolate this problem? Run tcpdump on the external ethernet connection. tcpdump -s0 -vv -i %s -nn -w /tmp/outputfile udp dst port domain -BEGIN PGP

Re: Frequent timeout

2018-09-02 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sat, 2018-09-01 at 23:45 -0400, Alex wrote: > (71.161.85.209.hostkarma.junkemailfilter.com): query failed (SERVFAIL) > (71.161.85.209.bl.score.senderscore.com): query failed (SERVFAIL) > When trying to resolve any of these manually, it just

Re: Frequent timeout

2018-09-01 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Fri, 2018-08-31 at 17:18 -0400, Alex wrote: > ../../../lib/dns/resolver.c:3927 for support.coxbusiness.com/A in After 4 seconds, I get SERVFAIL on that name. > ../../../lib/dns/resolver.c:3927 for dell.ns.cloudflare.com/A in That name

Re: SRV record not working

2018-08-17 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Fri, 2018-08-17 at 12:27 -0500, Thomas Strike wrote: > I need a 2nd pair of eyes on this one. Works for me. dig _minecraft._tcp.skyblock.mc-game.us srv ;; ANSWER SECTION: _minecraft._tcp.skyblock.mc-game.us. 300 IN SRV 0 5 25567 skyblock.mc-

Re: Need help on RPZ sever, bit urgent

2018-08-10 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Fri, 2018-08-10 at 13:17 +0530, Blason R wrote: > Nah I dont think that is the answer since you need a termination after > clause. Did you actually try the answer below? > On Fri, Aug 10, 2018 at 12:58 PM Vadim Pavlov wrote: > Should be: >

RHEL, Centos, Fedora rpm 9.12.2-P1

2018-08-08 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAltrXDoACgkQL6j7milTFsFHjwCeIIzxI2y9ih+Y7rJ2diq75m5Y

Re: Dropping queries from some well-known ports

2018-08-03 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Fri, 2018-08-03 at 20:00 +0200, Petr Mensik wrote: > 1. > https://gitlab.isc.org/isc- > projects/bind9/commit/05d32f6b0f6590ca22136b753309f070ce769000 If I am reading the code correctly, that commit implies that building bind with

RHEL, Centos, Fedora rpm 9.12.1-P2

2018-05-18 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlr/TNkACgkQL6j7milTFsHqPQCfVCKLfx5wzLjm+UkCkJx2C6f1

Re: Fwd: Facing weird issue with DNS-RPZ

2018-04-26 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2018-04-25 at 19:30 +0530, Blason R wrote: > I tried that couple of times on CentOS and it fails :(. http://www.five-ten-sg.com/mapper/bind I just updated the instructions. It looks like the built-in tests (that are normally run as part of

Re: Fwd: Facing weird issue with DNS-RPZ

2018-04-25 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2018-04-25 at 19:30 +0530, Blason R wrote: > I tried that couple of times on CentOS and it fails :(. http://www.five-ten-sg.com/mapper/bind I just updated the instructions. It looks like the built-in tests (that are normally run as part of

Re: BIND question

2018-04-11 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2018-04-11 at 21:06 +, praveen via bind-users wrote: > Is an "A" record mandatory entry for top-level domain (zone) when > using DNSSEC, DKIM, SPF and DMARC configuration? No. I have zones with all of that, with no A record at the apex,

Re: EDNS, 9.12 and archives.gov

2018-04-11 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2018-04-11 at 11:28 -0700, Mark Boolootian wrote: > I'm wondering if anyone from this august group > can clue me in to how I might config around this > issue for the archives.gov servers (assuming that > is possible). //

RHEL, Centos, Fedora rpm 9.12.0

2018-01-31 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlpx93oACgkQL6j7milTFsGfCACeLvDHoWvmTAGe28j/C7tIw99n

RHEL, Centos, Fedora rpm 9.11.2-P1

2018-01-17 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlnS18UACgkQL6j7milTFsGZfgCbBIUaYjY+AbTUz6X6xHJN4m1M

Re: head scratcher: nsupdate, Bind views, and TLSA record updates

2017-10-31 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Tue, 2017-10-31 at 17:16 -0700, Kevin via bind-users wrote: > $ dig TLSA _25._tcp.mail.thesandiegos.com @75.149.33.153 +dnssec > +short > > I'm really at a loss as to what's going on inside of Bind. dig TLSA _25._tcp.mail.thesandiegos.com

RHEL, Centos, Fedora rpm 9.11.2

2017-10-02 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlnS18UACgkQL6j7milTFsGZfgCbBIUaYjY+AbTUz6X6xHJN4m1M

Re: botched KSK rollover

2017-08-18 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 > Sigh, it sure would be nice if I had a registrar with a means to > automate DS submission. You might want to look at gkg.net -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux)

Re: "spare hosts" as personal DNS nameservers for 'mynew.org'

2017-07-12 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Wed, 2017-07-12 at 16:21 -0500, b...@zq3q.org wrote: > OK, I'm ready to consider other registrars, any suggestions > would be appreciated. I like gkg.net - they have an API so you can automatically upload new DS records when you do DNSSEC key

RHEL, Centos, Fedora rpm 9.11.1-P2

2017-06-29 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAllVdXcACgkQL6j7milTFsG/SQCggBDFBEwmgOb92nESct8cg3IS

RHEL, Centos, Fedora rpm 9.11.1-P1

2017-06-14 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlj6vdIACgkQL6j7milTFsHerACfQB+wrypAkmqxjX/4vw/PY5XG

Re: Resolve specified DNS name in a caching-only name server

2017-05-26 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Sat, 2017-05-27 at 09:11 +0800, Rui Mao wrote: > 1. Resolve test.a.com to 192.168.1.1 > 2. Still forward other *.a.com to outside DNS servers With bind, you have at least two choices. a) create test.a.com zone, so your server becomes

Re: Unable to build BIND 9.11.1 with dnstap support

2017-05-04 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 2017-05-04 at 18:01 +, greg.ra...@bt.com wrote: > I am trying to build BIND 9.11.1 on a CentOS 7 64-bit system, > including dnstap support. You might try my .spec file, extracted from the source rpm:

RHEL, Centos, Fedora rpm 9.11.1

2017-04-21 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlj6vdIACgkQL6j7milTFsHerACfQB+wrypAkmqxjX/4vw/PY5XG

RHEL, Centos, Fedora rpm 9.11.0-P5

2017-04-12 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAljuy1oACgkQL6j7milTFsEeqgCfQh4Gka99/IOh7XkQ1+c0qmqI

Re: Unable to build BIND 9.11.0-P3 on RHEL 6.0 64-bit

2017-03-28 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 > I am having trouble getting BIND 9.11.0-P3 to build on RHEL 6.0 > 64-bit. I am linking it with static OpenSSL (1.0.2j) and GeoIP > (1.6.6) libraries. Here are my configure options: First, openssl is already at 1.0.2k - I don't know if any of

RHEL, Centos, Fedora rpm 9.11.0-P3

2017-02-08 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAlibpa8ACgkQL6j7milTFsFi5gCfSEhAyxLOEgFDY8aoSkuLnXvD

  1   2   >