Re: Postgres v MySQL v Berkely backend for BIND

2009-05-05 Thread Chris Dew
Are there performance increases/decreases involved with using a db in place of bind's normal zone files? Is there a sqlite3 backend to bind? Regards, Chris. -- http://www.finalcog.com/ 2009/5/4 David Ford da...@blue-labs.org: I use the DLZ/PG backend and it's rock solid.  I use Ant with a

Re: approach on parsing the query-log file

2009-04-29 Thread Chris Dew
You may be interested in using circular buffers, instead of a log file. http://www.finalcog.com/replace-logs-emlog-circular-buffer I've used emlog successfully in the past and been very pleased with it's performance. Hope this is useful. Chris. 2009/4/29 Scott Haneda talkli...@newgeo.com: I

Re: Psuedo-Master Zones

2009-03-25 Thread Chris Dew
I would use a #include in the zone file on the internal machine to include the contents of zone file on the external machine. (NFS mount, or cron'ed rsync copy.) You could use views/split horizon dns and run them both off of one server, but this seems unneeded and nasty.

Re: stealth master DNS Security

2009-03-25 Thread Chris Dew
You could use the ecrypt fs for the location of the zone data - it would require a passphrase when bind starts up on the slave - this could cause trouble if the slave crashes. In general there is NO way of having encrypted data on a machine AND having the keys on that same machine AND making it

Re: Psuedo-Master Zones

2009-03-25 Thread Chris Dew
No, we've had to work around these limitations of axfr/notify, so that we can take this concern away from our customers. I would love to find a nice bind-supported way of dealing with views/axfr/notify, so if you find anything, please let me know. Thanks, Chris http://www.finalcog.com

Re: stealth master DNS Security

2009-03-25 Thread Chris Dew
IPSEC really isn't too onerous between machines with static IP addresses just a thought. 2009/3/25 Ram Akuka ramak...@gmail.com: 2009/3/25 Alan Clegg alan_cl...@isc.org: Ram Akuka wrote: Is there's any way I can encrypt the zone transfer date (without using any third-party encryption

Fwd: No name resolution when slave is down

2009-03-20 Thread Chris Dew
-- Forwarded message -- From: Chris Dew cms...@googlemail.com Date: 2009/3/20 Subject: Re: No name resolution when slave is down To: Dennis J. denni...@conversis.de Asking the obvious here, but does your domain registrar list both your master and your slave as authoritative

Re: how to archieve this?

2008-12-05 Thread Chris Dew
Have you considered dynamically regenerating view definitions based on your rules? If the results of your rules are stable for minutes at a time, it may work. Regards, Chris. 2008/12/5 Ken DBA [EMAIL PROTECTED] --- On Fri, 12/5/08, Kevin Darcy [EMAIL PROTECTED] wrote: From: Kevin Darcy