Re: Master file permission denied

2023-06-28 Thread Danilo Godec via bind-users
ne unau.edu.ar/IN: loading from master file /etc/bind/zonas/db.unau.edu.ar failed: permission denied zone unau.edu.ar/IN: not loaded due to errors.   Named is running as bind user I would be grateful for

Changing DNS servers (name only) for a DNSSEC enabled domain

2023-02-13 Thread Danilo Godec via bind-users
Hello, in the near future I will have to change NS records for one of my domains, as DNS servers currently use an old domain (not mine), that will be phased out. DNS servers will actually remain the same, only the domain name will change. So, basically: * mydomain currently uses

Re: Changing the DNSSEC algorithm

2022-04-06 Thread Danilo Godec via bind-users
, Petr 1. https://bind9.readthedocs.io/en/v9_16_27/dnssec-guide.html 2. https://ftp.isc.org/isc/bind9/cur/9.11/doc/arm/Bv9ARM.ch04.html#dnssec.dynamic.zones On 4/5/22 09:07, Danilo Godec via bind-users wrote: Hello

Re: Changing the DNSSEC algorithm

2022-04-06 Thread Danilo Godec via bind-users
On 6.4.2022 8:52, Daniel Stirnimann wrote: Hello Danilo, A simple schema to change DNSSEC algorithms is as follows: 1. Add new KSK/ZSK and double sign DNSKEY and all zone RRs with both the new and old algorithm 2. Replace DS at parent 3. Remove old DNSKEY and all RRSIGs from the old

Changing the DNSSEC algorithm

2022-04-05 Thread Danilo Godec via bind-users
Hello, I implemented DNSSEC for my personal domain a good while ago with an older Bind and back then, I used RSASHA1-NSEC3-SHA1 algorithm, which by now is not recommended... So I'm going to change the algorithm, probably to ECDSAP256SHA256, which should also be NSEC3 capable. Since my

dnssec rookie question

2022-01-10 Thread Danilo Godec via bind-users
Hello, today I implemented DNSSEC for a domain - by that I mean that the DS records have been published / added to TLD DNS today, while the zone has been signed a couple of days ago. So a couple of hours later I went to https://dnsviz.net to see if everything seems OK and it reports one

Re: DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2021-12-30 Thread Danilo Godec via bind-users
On 29. 12. 21 19:24, tale wrote: On Wed, Dec 29, 2021 at 5:31 AM Danilo Godec via bind-users wrote: I have an authoritative DNS server for a domain, but I was also going to use the same server as a recursive DNS for my internal network, limiting recursion by the IP. Apparently, this is a bad

DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2021-12-29 Thread Danilo Godec via bind-users
Hello, I have an authoritative DNS server for a domain, but I was also going to use the same server as a recursive DNS for my internal network, limiting recursion by the IP. Apparently, this is a bad idea that can lead to cache poisoning... After watching a Computerphile Youtube video

Millions of './ANY/IN' queries denied

2021-12-15 Thread Danilo Godec via bind-users
Hello, I'm noticing some unusual activity where 48 external IPs generated over 2M queries that have all been denied (just today): 15-Dec-2021 00:01:42.023 security: info: client @0x7f96180b3fe0 194.48.217.14#59698 (.): view outside: query (cache) './ANY/IN' denied 15-Dec-2021 00:01:42.023

Re: CNAME query

2021-09-23 Thread Danilo Godec via bind-users
ort subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Danilo Godec | Sistemska podpora / System Administration AGENDA d.o.o. | Ul. Poh

Problem resolving

2021-09-16 Thread Danilo Godec via bind-users
Hello, I recently stumbled upon a problem trying to update my root hints file from *ftp.rs.internic.net*. For some reason, one of my DNS servers running on Alpine Linux, can't resolve this name properly and always fails: # ping ftp.rs.internic.net ping: ftp.rs.internic.net: Try again nslookup

Re: Insufficient DNS Source Port Randmoization

2011-07-28 Thread Danilo Godec
://lists.isc.org/mailman/listinfo/bind-users -- Danilo Godec, sistemska podpora / system administration Predlog! Obiscite prenovljeno spletno stran www.agenda.si ODPRTA KODA IN LINUX STORITVE : POSLOVNE RESITVE : UPRAVLJANJE IT : INFRASTRUKTURA IT : IZOBRAZEVANJE : PROGRAMSKA OPREMA Visit our

Problem resolving one particular domain

2011-07-27 Thread Danilo Godec
Hi, I'm running three DNS servers (1 master, 2 slaves) running bind 9.7.3, hosting about 150 domains, while also providing DNS service for my network. Recently a customer complained that they cannot send an email (they use my SMTP server) to a specific domain 'rabobank.com' - Postfix logged

Re: Problem resolving one particular domain

2011-07-27 Thread Danilo Godec
On 07/27/2011 10:31 AM, Stephane Bortzmeyer wrote: On Wed, Jul 27, 2011 at 09:59:32AM +0200, Danilo Godecdanilo.go...@agenda.si wrote a message of 247 lines which said: Weirdness number 2 - using dig directly with their servers works: Nothing weird here: dig does not behave like the BIND