AW: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records

2024-03-26 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Jan > Schaumann via bind-users > Gesendet: Dienstag, 26. März 2024 14:44 > An: bind-users@lists.isc.org > Betreff: Re: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records > > Karl Auer wrote: > > I'm puzzled by the

AW: Crafting a NOTIFY message from the command line?

2024-03-21 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Arsen > STASIC > Gesendet: Donnerstag, 21. März 2024 08:47 > An: Petr Špaček > Cc: bind-users@lists.isc.org > Betreff: Re: Crafting a NOTIFY message from the command line? > > * Petr Špaček [2024-03-20 09:32 (+0100)]: > > On

AW: Problem upgrading to 9.18 - important feature being removed

2024-02-27 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Carsten ... > It would be nice to have a "dry-run" mode in BIND 9, where BIND 9 would > report steps it would do because of "dnssec-policy", but will not execute the > changes. If this Bind9 is only a hidden primary, disable

AW: migration from auto-dnssec to dnssec-policy deletes keys immediately

2024-01-08 Thread Klaus Darilion via bind-users
Hi all! I also know a colleague which was hit by the same issue, causing problems to their zone. Migrating from auto-dnssec to dnssec-policy can lead to operational issues. For example that problem with different algos should be mentioned in

AW: Why are XFRs to Secondaries equally fast?

2023-07-27 Thread Klaus Darilion via bind-users
Hi Petr! > > For example, there are 8 secondaries (Mumbai, LosAngeles, Melbourne, > > Atlante, SaoPaulo...) to which the XFR took 2361 seconds. > > > > Are there some mechanisms in Bind that put multiple XFRs together into > a > > common stream? Or do you have any other ideas how it come that

Why are XFRs to Secondaries equally fast?

2023-07-27 Thread Klaus Darilion via bind-users
Rs are equally fast? Thanks Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscr

AW: Tools to mesure performance and benchmarking of a DNS

2023-06-21 Thread Klaus Darilion via bind-users
There are several tools with different features and behavior. I would take alook at dnsperf, kxdpgun and flamethrower regards > -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von > sami.ra...@sofrecom.com > Gesendet: Mittwoch, 21. Juni 2023 17:59 > An: bind-users@lists.isc.org >

AW: Bind not sending notifies for some time

2023-03-27 Thread Klaus Darilion via bind-users
> > On 24. 3. 2023, at 14:36, Klaus Darilion via bind-users us...@lists.isc.org> wrote: > > > > Is there some rate liming in Bind? > > https://bind9.readthedocs.io/en/stable/reference.html#namedconf- > statement-notify-rate For the records: Increasing the n

RE: Bind not sending notifies for some time

2023-03-24 Thread Klaus Darilion via bind-users
> > https://bind9.readthedocs.io/en/stable/reference.html#namedconf-statement-notify-rate Will that feature throttle Notifys or stop them completely for some minutes? Thanks Klaus -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the

Bind not sending notifies for some time

2023-03-24 Thread Klaus Darilion via bind-users
Hi! root@cc-tld-sbg1:/var/log/tld-acct-by-customer# dpkg -l|grep bind9 ii bind9 1:9.18.6-1+ubuntu22.04.1+isc+1 amd64Internet Domain Name Server Please help me debugging this issue: We have a TLD zone with ~3mio delegations and updates every

AW: Correlation between NOTIFY-Source and AXFR-Source

2023-03-09 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Mark > Andrews > Gesendet: Donnerstag, 9. März 2023 21:04 > An: Jan-Piet Mens > Cc: bind-users@lists.isc.org > Betreff: Re: Correlation between NOTIFY-Source and AXFR-Source > > Named just uses the notify to trigger an early

Correlation between NOTIFY-Source and AXFR-Source

2023-03-09 Thread Klaus Darilion via bind-users
Hello! I always was quite sure that Bind will request XFR from the Primary that sent the NOTIFY. config: masters { X.X.X.4; X.X.X.20; }; Bind Version 9.11.5.P4+dfsg-5.1+deb10u8 But I just saw this in the logs that the first NOTIFY is received from .20, but AXFR is

AW: DNS DDoS protection

2023-02-27 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Bob > Harold > Gesendet: Freitag, 24. Februar 2023 19:26 > An: bind-users > Betreff: DNS DDoS protection > > Before answering this question, can you tell me the proper place where I > should be asking this question? > > "We

AW: Simplistic serial number roll back

2023-02-20 Thread Klaus Darilion via bind-users
Yes it does. I guess all name servers offer a command to force a transfer of the zone without checking the serial. The ones I use support that: Bind: rndc retransfer NSD: nsd-control force_transfer PowerDNS: pdns_control retrieve Knot: knotc zone-retransfer regards Klaus >

Is there an rndc command to get the list of configured zones?

2022-09-20 Thread Klaus Darilion via bind-users
I checked all options of rndc to get the list of zones configured/served by bind - but I can't find any. Is it really not possible to get this list from a running Bind process? Thanks Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria

AW: BIND 9.18.6 disables RSASHA1 at runtime?

2022-09-13 Thread Klaus Darilion via bind-users
> Can you propose log line? > > Should it be one line per algorithm? Or one line with all disabled? Or > one one with all enabled? What log level? Log category? It it okay it > will be almost always logging GOST? ... I am not using Red Hat, but when debugging DNSSEC issues it would be helpful to

AW: High memory consumption in bind 9.18.2

2022-05-19 Thread Klaus Darilion via bind-users
Von: Petr Špaček > Gesendet: Donnerstag, 19. Mai 2022 12:22 > An: Klaus Darilion > Cc: bind-users@lists.isc.org > Betreff: Re: High memory consumption in bind 9.18.2 > > On 18. 05. 22 22:39, Ondřej Surý wrote: > > Hi Klarstein, > > > > Gathering the output of na

AW: AW: High memory consumption in bind 9.18.2

2022-05-18 Thread Klaus Darilion via bind-users
d the > differences are not small, for some configurations it can be even 2x or > 3x more on 9.16 than it is on 9.18. > > If you encounter it again please get back to us so we can diagnose it. > > Thank you! > Petr Špaček > > > On 18. 05. 22 8:56, Klaus Darilion via bind-u

AW: High memory consumption in bind 9.18.2

2022-05-18 Thread Klaus Darilion via bind-users
I remember we had similar issues with 9.18 (isc ppa packages) and hence wen't back to 9.16. But I can not remember the details. regards Klaus > -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Ondrej > Surý > Gesendet: Mittwoch, 18. Mai 2022 08:37 > An: Raman kumar > Cc:

AW: Why did my DNS bill go up?

2022-04-15 Thread Klaus Darilion via bind-users
Hi Andrew! DNSSEC is more costly: more Ressource Records to hold on disk, to hold in memory and more queries and more IP traffic. If the DNSSEC signing is also done by the DNS provider there would be additional ressources for the signing service and risks when doing something wrong. For a

AW: all resource record types and examples

2022-04-13 Thread Klaus Darilion via bind-users
As I have such a zone I will paste it here. But fore sure it is not complete as it was created some time ago. regards Klaus $ cat types.test $TTL 60 ; 1 minute @ IN SOA sec1.rcode0.net. rcodezero.ipcom.at. ( 36 ; serial

AW: Bind 9, dnssec, and .key .private files physical deletion after the key id becomes deleted from zone (the key becomes outdated)

2022-01-24 Thread Klaus Darilion via bind-users
IIRC, Bind needs the key as long as there are signatures in the zone generated by this key. After key deactivation I waited the RRSIG lifetime before deleting them. regards Klaus Von: bind-users Im Auftrag von egoitz--- via bind-users Gesendet: Montag, 24. Jänner 2022 13:00 An:

AW: AW: Deprecating auto-dnssec and inline-signing in 9.18+

2021-08-10 Thread Klaus Darilion via bind-users
> On 10-08-2021 13:38, Klaus Darilion wrote: > > Hi Matthijs! > > > >> We would like to encourage you to change your configurations to > >> 'dnssec-policy'. See this KB article for migration help: > >> > >> https://kb.isc.org/docs/dnssec-key-

AW: Deprecating auto-dnssec and inline-signing in 9.18+

2021-08-10 Thread Klaus Darilion via bind-users
Hi Matthijs! > We would like to encourage you to change your configurations to > 'dnssec-policy'. See this KB article for migration help: > > https://kb.isc.org/docs/dnssec-key-and-signing-policy Some comments to this KB article and dnssec-policy: - The article should mention how to

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
Do you think that we can get rid of CNAME too? regards Klaus > -Ursprüngliche Nachricht- > Von: Ondřej Surý > Gesendet: Montag, 9. August 2021 19:19 > An: Klaus Darilion > Cc: Mark Andrews ; bind-users@lists.isc.org > Betreff: Re: Does BIND supports ANAME RR &g

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
Does every application that uses gethostbyname have a benefit of HTTPS/SVCB? That is what I meant. regards Klaus > -Ursprüngliche Nachricht- > Von: Mark Andrews > Gesendet: Montag, 9. August 2021 15:55 > An: Klaus Darilion > Cc: Evan Hunt ; Gaurav Kansal ; bind- > u

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
> On 09.08.21 13:55, Klaus Darilion via bind-users wrote: > >But honestly SVCB will not solve the ANAME problem. I will take years > > until all resolvers/client would support SVCB whereas ANAME would be > > implemented in the authoritative name server > > resolving on

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Evan > Hunt > Gesendet: Samstag, 7. August 2021 20:21 > An: Gaurav Kansal > Cc: bind-users@lists.isc.org > Betreff: Re: Does BIND supports ANAME RR > > On Sat, Aug 07, 2021 at 11:05:51PM +0530, Gaurav Kansal wrote: > > I need

failed trust-anchor-telemetry queries

2021-07-27 Thread Klaus Darilion via bind-users
Hello! Bind version: 9.16.19-1+ubuntu18.04.1+isc+1 Recently I discovered these logs: 09:13:12 named[3234]: _default: sending trust-anchor-telemetry query '_ta-/NULL' 09:13:12 named[3234]: validating ./NSEC: no valid signature found 09:13:12 named[3234]: validating ./SOA: no valid

AW: New BIND releases are available: 9.11.32, 9.16.16, and 9.17.13

2021-05-20 Thread Klaus Darilion via bind-users
Nevertheless I think there is a bug. IIR the previous default was 100% (switch to AXFR if IXFR would be grater than AXFR) and we also saw plenty of AXFR although the IXFR difference was very small and far away from 100% regards Klaus > -Ursprüngliche Nachricht- > Von: bind-users Im

9.16 needs more RAM then 9.11

2021-04-19 Thread Klaus Darilion
Hello! On our servers where we use Bind 9.16, named needs approx. 29G RAM. On the servers with Bind 9.11 named needs approx. 25G RAM. Is this a known issue? Are there some config options to tune memory consumption? Thank Klaus ___ Please visit

AW: AXFR Problems sind Upgrade to 9.16.12

2021-03-15 Thread Klaus Darilion
ind-users Im Auftrag von Klaus > Darilion > Gesendet: Donnerstag, 11. März 2021 21:24 > An: bind-users@lists.isc.org > Betreff: AXFR Problems sind Upgrade to 9.16.12 > > Hello! > > Our setup: Customer Primary --> bind-1 --> bind-2 --> public secondaries > (NSD/b

AW: AXFR Problems sind Upgrade to 9.16.12

2021-03-11 Thread Klaus Darilion
I will - in the meantime: do you have older ppa packages somewhere on archive? Thanks Klaus > -Ursprüngliche Nachricht- > Von: Ondřej Surý > Gesendet: Donnerstag, 11. März 2021 21:49 > An: Klaus Darilion > Cc: bind-users@lists.isc.org > Betreff: Re: AXFR Pro

AW: AXFR Problems sind Upgrade to 9.16.12

2021-03-11 Thread Klaus Darilion
I just wanted to add, that AXFR of all other hosted zones work fine (even bigger ones). Only this single zone fails. Thanks Klaus > -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Klaus > Darilion > Gesendet: Donnerstag, 11. März 2021 21:24 > An: bind-user

AXFR Problems sind Upgrade to 9.16.12

2021-03-11 Thread Klaus Darilion
Hello! Our setup: Customer Primary --> bind-1 --> bind-2 --> public secondaries (NSD/bind) Today we upgraded bind-1 and bind-2 from: 9.16.6-3+ubuntu18.04.1+isc+3 ---> 9.16.12-2+ubuntu18.04.1+isc+1 AXFR from customer to bind-1 still works. But since the upgrade, bind-2 can not transfer

AW: AW: How to prepublish additional DNSKEY

2020-07-15 Thread Klaus Darilion
Thanks - now it works. Klaus Von: Shumon Huque Gesendet: Donnerstag, 9. Juli 2020 13:44 An: Daniel Stirnimann Cc: Klaus Darilion ; bind-users@lists.isc.org Betreff: Re: AW: How to prepublish additional DNSKEY On Thu, Jul 9, 2020 at 6:44 AM Daniel Stirnimann mailto:daniel.stirnim...@switch.ch

AW: How to prepublish additional DNSKEY

2020-07-09 Thread Klaus Darilion
> > So, how is the correct process to add an additional DNSKEY (only the public > key is known). > > I think you are looking for `dnssec-importkey`. Indeed. I imported the key and got a .key and .private file. I put those files in the same directory as the other keys, gave read permissions to

How to prepublish additional DNSKEY

2020-07-08 Thread Klaus Darilion
Hello all! A signed zone shall be moved to another DNS provider. Hence I want to add the public KSK of the gaining DNS provider as additional DNSKEY to the zone. My setup ist: Bind1 as hidden primary --> Bind2 as bump-in-the-wire signer -> public facing secondaries I tried to add the DNSKEY

AW: NSEC3 salt change - temporary performance decline

2020-06-09 Thread Klaus Darilion
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Cathy > Almond > Gesendet: Dienstag, 9. Juni 2020 14:30 > An: bind-users@lists.isc.org > Betreff: Re: NSEC3 salt change - temporary performance decline ... > > FYI this will be fixed in the June 2020 BIND releases (in 9.11.20,

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
> Am 15.04.20 um 10:08 schrieb Ondřej Surý: > > you need to stop being rude to people on the bind-users mailing list, > > personal attacks are not acceptable behaviour here. You should apologize > > to Klaus. > > it's not a personal attack to clearly point out that discussions of > distribution

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
Thanks for answer! So actually it is just a cosmetic change not addressing a real problem. I will miss the bind9 service :-( Klaus > -Ursprüngliche Nachricht- > Von: Ondřej Surý > Gesendet: Mittwoch, 15. April 2020 10:15 > An: Klaus Darilion > Cc: bind-users@lists.is

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Reindl > Harald > Gesendet: Mittwoch, 15. April 2020 09:17 > An: bind-users@lists.isc.org > Betreff: Re: Debian/Ubuntu: Why was the service renamed from bind9 to > named? > > > > Am 15.04.2

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
> > It would be great if you undo this change before release of 18.04 > > you confuse the upstream project with your distribution > > bind9 was completly wrong in the debian world as well as apache2 for > httpd, on sane distributions it's "httpt" and "named" all the years > beause it's nonsense

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
20 um 08:56 schrieb Reindl Harald: > > > > > > Am 15.04.20 um 08:51 schrieb Klaus Darilion: > >> Hello! > >> > >> What is the rationale of: > >> > >> bind9 (1:9.13.6-1) experimental; urgency=medium > >> ... > >> * R

Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
Hello! What is the rationale of: bind9 (1:9.13.6-1) experimental; urgency=medium ... * Rename the init scripts to named to match the name of the daemon Since years, Debian and Ubuntu User, and plenty of scripts and automation software (Puppet ...), know that the service is called "bind9". I

max-ixfr-ratio values

2020-03-22 Thread Klaus Darilion
max-ixfr-ratio introduced with 9.17.0 sounds like a workaround instead of a bugfix. Anyway, can you recommend a sensible settings? I.e. when does the performance problem of "large" IXFR starts to happen? Does this depend on the ratio of the IXFR-size to zone-size, or does it depend on the

What happens if the max-tcp-connections limit is reached?

2020-03-04 Thread Klaus Darilion
Hello all! Will bind refuse (close) the new TCP connections, or will it accept the new connection and closes the longest idle TCP connection? Or even better? Thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: NSEC3 salt change - temporary performance decline

2020-01-29 Thread Klaus Darilion
Am 21.01.2020 um 16:40 schrieb Ondřej Surý: > We are currently investigating performance degradation related to big IXFRs. > Do you use ixfr-from-differences in your BIND configuration? You could try > enforcing AFRX on salt change. > > This is currently tracked as >

Re: NSEC3 salt change - temporary performance decline

2020-01-29 Thread Klaus Darilion
Hello Niels! Thanks for bringing this to attention. I have reported it before [1][2] without response. We see this regulary. AFAIS it happens actually always, but if the IXFR is small, the performance decline is so short that you usually won't notice it. The bigger the zonechange ie NSEC3

Re: BIND setup for GSLB (Global Service Load Balancing)

2019-10-02 Thread Klaus Darilion
Am 12.09.2019 um 17:39 schrieb Roberto Carna: Hi people, is it possible to setup BIND in order to implement GSLB (Global Service Load Balancing) between two sites ? I need a near Active-Active scenario between two datacenters in different locations, and I want to do this with an open source

Re: journal file is out of date: removing journal file

2019-07-31 Thread Klaus Darilion
Hi Tony! Am 31.07.2019 um 12:44 schrieb Tony Finch: > Klaus Darilion wrote: >> >> What does the log message "journal file is out of date: removing journal >> file" exactly mean? Is it somehow problematic? > > After loading a zone, named discovers the seri

journal file is out of date: removing journal file

2019-07-30 Thread Klaus Darilion
Hello! BIND 9.12.2-P2, max-journal-size 1m; What does the log message "journal file is out of date: removing journal file" exactly mean? Is it somehow problematic? I have bind as bump in the wire signer, and regularly problems with slow zone updates for a specific zone which often, almost every

Re: IXFR fallback to AXFR if diff is bigger than zone

2019-07-12 Thread Klaus Darilion
Hi Tony! Am 12.07.2019 um 13:00 schrieb Tony Finch: > Yes, that is curious. Are you sure it isn't actually doing an > IXFR-flavoured AXFR of the whole zone, rather than a delta? We have a setup with severals Bind in a row: hidden master customer (software unknown) | | V

Re: Bind max socket/query per IP

2019-05-22 Thread Klaus Darilion
Am 21.05.2019 um 22:31 schrieb Ict Security: Under heavy load, Bind becomes extremely load above a certain number of Qps but, if i query an alias IP address (where normally queries don't arrive), Bind answers immediately. btw - how high is the "extremely load"? Klaus

Re: BIND 9.10 fast only on alias IP

2019-05-22 Thread Klaus Darilion
Am 20.05.2019 um 20:16 schrieb Ict Security: How could i increase the number of socket on a single IP address, since Bind is working perfectly on the secondary address, when the first one is stucked? If the incoming traffic is bursty it may happen that the receive queue of the socket is full

Re: max file size or line count for BIND zone file

2019-04-25 Thread Klaus Darilion
Am 25.04.2019 um 14:10 schrieb Martin Meadows via bind-users: Wondering if anyone is aware of a max file size or max number of lines that a given BIND zone file can contain? IF you use a journal, things may get complicated if your journal is over 2G: https://kb.isc.org/docs/aa-01627

Bind Auth responds slow during incoming XFR

2019-03-27 Thread Klaus Darilion
Hello! We have a problem with Bind [2] during incoming IXFR. When there is a huge IXFR (ie 1,8GB tranferred in 15minutes [1]), the response time heavily increases. Using dsc's newest "Reponse Time Indexer" we clearly see that Bind answers slow: Response Time normal during Window

Re: Operational Notification: Extremely large zone transfers can result in corrupted journal files or server process termination

2018-07-16 Thread Klaus Darilion via bind-users
Am 14.07.2018 um 00:38 schrieb Matthew Pounsett: > On 13 July 2018 at 06:04, Michał Kępień wrote: > >> Hopefully this will shed some light on the matter: >> >> https://gitlab.isc.org/isc-projects/bind9/issues/339#note_12805 >> >> That is helpful, thanks. That comment says the issue

Re: timestamp in journal

2018-07-09 Thread Klaus Darilion
Hi Anand! Am 09.07.2018 um 14:04 schrieb Anand Buddhdev: On 09/07/2018 13:50, Klaus Darilion wrote: Hi Klaus, named-journalprint dumps the journal without any time information. Does the journal include time information? (Timestamp of add/del) If yes, can I somehow extract the timestamps

timestamp in journal

2018-07-09 Thread Klaus Darilion
Hi! named-journalprint dumps the journal without any time information. Does the journal include time information? (Timestamp of add/del) If yes, can I somehow extract the timestamps? thanks Klaus ___ Please visit

Re: Slow reply under heavy load (on a specific NIC ip)

2018-06-15 Thread Klaus Darilion
Am 04.06.2018 um 14:20 schrieb Ict Security: Hi guys, we are running a Bind 9.x Server, everything is going fine. Under particular heavy load mometns, with some hundreds of concurrent queries coming in, sometime Bing stops answering for some seconds or answer with important delays. But, when i

Re: sporadic timeouts querying bind9

2018-04-23 Thread Klaus Darilion
This time with log file attached Thanks Klaus Am 23.04.2018 um 14:55 schrieb Klaus Darilion via bind-users: > Hi all! > > Upgrading to Ubuntu 16.04 with Bind 9.10.3 did not solved the problem. > > I enabled debug log (trace 2) and query logging. Unless my monitoring > tr

Re: sporadic timeouts querying bind9

2018-04-23 Thread Klaus Darilion via bind-users
locking operations in bind? Thanks Klaus Am 15.03.2018 um 14:45 schrieb Klaus Darilion: > Hi! > > I use bind 9.9.5.dfsg-3ubuntu0.17 with around 20 slave zones (from small > to huge). > > I query the SOA of every configured zone once a second to monitor bind. > > Once

Re: Suggestions for a distributed DNS zone hosting solution I'm designing

2018-03-17 Thread Klaus Darilion
Hi Latitude! Short answer: I think 2s delay is not possible in a distributed system with many global distributed slaves and limited ressources. Long answer: It all depends on how much money you have and time in setting up such a service - long comments inline. Am 07.03.2018 um 07:10

sporadic timeouts querying bind9

2018-03-15 Thread Klaus Darilion
Hi! I use bind 9.9.5.dfsg-3ubuntu0.17 with around 20 slave zones (from small to huge). I query the SOA of every configured zone once a second to monitor bind. Once a day my script reports timeouts (3 seconds) querying a SOA. This server is a test server, hence it is idle except the monitoring

Re: are journal files required on slave?

2018-03-15 Thread Klaus Darilion
Am 14.03.2018 um 15:20 schrieb Tony Finch: > Klaus Darilion <klaus.mailingli...@pernau.at> wrote: >> >> I have now set >> max-journal-size 50M; >> and restartet bind a few times. But the journal files are still GBytes. >> When should Bind flush

Re: are journal files required on slave?

2018-03-14 Thread Klaus Darilion
Am 14.03.2018 um 13:38 schrieb Tony Finch: > Klaus Darilion <klaus.mailingli...@pernau.at> wrote: >> >> Thanks for the detailed answer. So I will use a few MBytes. But would it >> be possible to set max-journal-size=0? > > There's a minimum journal size (

Re: are journal files required on slave?

2018-03-14 Thread Klaus Darilion
Am 14.03.2018 um 13:04 schrieb Tony Finch: > Klaus Darilion <klaus.mailingli...@pernau.at> wrote: >> >> But on a server with slave-zone only (fetched by ixfr) - do I need a >> journal at all? How can I disable it - by setting the max-size to 0? > > The journ

Re: Maximum zone file size

2018-03-14 Thread Klaus Darilion
Am 14.03.2018 um 13:10 schrieb Ray Bellis: > On 14/03/2018 12:08, Anand Buddhdev wrote: > >> Not that I know of. The amount of RAM in a server is probably the most >> significant limit for loading zones into BIND. > > Anand is correct - there's no intrinsic limit other than RAM. > > I

Maximum zone file size

2018-03-14 Thread Klaus Darilion
Hi! I couldn't find it online - is there a limit on the zone file size? Thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org

are journal files required on slave?

2018-03-14 Thread Klaus Darilion
Hi! The default setting of max-journal-size filled my disk. I do have plenty of zone from KByte to GByte. So I wonder, what would be the perfect size to configure. So, I wondered - do I need a journal at all? I know the journal is needed for ixfr-from-differences and DDNS. But on a server with

questions about rndc zonestatus

2017-12-19 Thread Klaus Darilion
Hi! I would like to use this feature to check the status of my slave zones. # rndc zonestatus nic.at name: nic.at type: slave files: /etc/bind/zones/nic.at serial: 2017121119 nodes: 77 next refresh: Tue, 19 Dec 2017 08:34:53 GMT expires: Tue, 02 Jan 2018 07:50:08 GMT secure: yes inline signing:

Re: How to check slave zone freshness

2016-02-10 Thread Klaus Darilion
On 08.02.2016 14:58, Tony Finch wrote: > Klaus Darilion <klaus.mailingli...@pernau.at> wrote: >> >> I want to monitor the freshness of my slaves zones. Is it somehow >> possible to extract the status of slave-zones from bind? > > If you are running 9.10 or l

Re: How to check slave zone freshness

2016-02-10 Thread Klaus Darilion
On 10.02.2016 09:27, Klaus Darilion wrote: > > > On 08.02.2016 14:58, Tony Finch wrote: >> Klaus Darilion <klaus.mailingli...@pernau.at> wrote: >>> >>> I want to monitor the freshness of my slaves zones. Is it somehow >>> possible to extract t

Re: How to check slave zone freshness

2016-02-09 Thread Klaus Darilion
On 08.02.2016 20:49, Mark Andrews wrote: > With a modern nameserver that supports the expire edns option you can > also do "dig +expire soa zone @server" which will tell you how long > until the zone will expire on this server. Aha, but isn't this a different kind of information? A zone which

How to check slave zone freshness

2016-02-08 Thread Klaus Darilion
Hi! I want to monitor the freshness of my slaves zones. Is it somehow possible to extract the status of slave-zones from bind? Thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: How to check slave zone freshness

2016-02-08 Thread Klaus Darilion
Am 08.02.2016 um 14:58 schrieb Tony Finch: > Klaus Darilion <klaus.mailingli...@pernau.at> wrote: >> >> I want to monitor the freshness of my slaves zones. Is it somehow >> possible to extract the status of slave-zones from bind? > > If you are running 9.10 or l

Re: How to check slave zone freshness

2016-02-08 Thread Klaus Darilion
Am 08.02.2016 um 14:59 schrieb Warren Kumari: > The standard, compatible way to do this is simply to do a lookup for the > SOA record and make sure that the serial number matches what you expect > it to be / what is on the master. I'm not sure what monitoring tool you > are using (or if you are

Re: rndc (and now nsupdate too)

2014-08-19 Thread Klaus Darilion
Am 31.07.2014 21:08, schrieb /dev/rob0: The proper tool to manage named configuration and operation, and which in the best Unix ethic is well suited for automation, is rndc(8). You can not always use rndc. For example you can add and delete zones, but you can not modify zones via rndc.

Retrying failed zone transfer

2014-07-22 Thread Klaus Darilion
Hi! I have a Bind 9.9.5 running as slave. The master is not configured correctly and rejects the zone transfer. It seems that if Bind has never received the zone yet, it tries endlessly to fetch the zone (see below), ~3 times per second. It would be nice if Bind for example retries only every

dynamically adding/removing TSIG configuration

2014-07-07 Thread Klaus Darilion
Hi! I currently use rndc addzone/delzone to manage zones on my slave. I now want to add TSIG for some of these zones and I want to be able to enable/disable TSIG dynamically per zone. Unfortunately I haven't found a nice solution yet. My results are: 1. delzone/addzone with adding the tsig key

incomplete NSEC3 chains

2014-06-30 Thread Klaus Darilion
Release: BIND 9.9.5 I regularly perform key rollovers and zone validation of an inline-signed zone. The zone validator receives NOTIFYs and then it transfers the zone and validates it (using dnssec-verify and validns). I also regularly call rndc retransfer to make sure to have an correct zone.

Re: Bind ignoring signing -nsec3param when inline-signing a zone

2014-06-05 Thread Klaus Darilion
signing nsec3param - this is not nice. Are there any workarounds for that? IMO it would be cool if Bind would store NSEC3 options outside of the zone. Thanks Klaus On 05.06.2014 14:02, Klaus Darilion wrote: Hi! Today I managed that Bind 9.9.5 created a signed zone with all RRs signed except

Re: KSK signing incomplete

2014-05-21 Thread Klaus Darilion
Further, I see that sometimes there are no private records at all. When does this happen? (I never called rndc signing -clear) It seems that this happens when Bind is restarted. So, what is the suggested (and reliable) way for external tools to get the signing status from Bind? I.e. if a key

Re: KSK signing incomplete

2014-05-21 Thread Klaus Darilion
On 21.05.2014 12:39, Phil Mayers wrote: On 21 May 2014 10:24:23 BST, Klaus Darilion klaus.mailingli...@pernau.at wrote: Further, I see that sometimes there are no private records at all. When does this happen? (I never called rndc signing -clear) It seems that this happens when Bind

KSK signing incomplete

2014-05-20 Thread Klaus Darilion
Hi! Using Bind 9.9.5. I have some questions about the private records which indicate the signing status. From my external key management and monitoring tool I query the private records to get the signing status, e.g. if the signing after a rollover is finished, if a key can be deleted from disk,

DNSSEC: recover from missing keys

2014-05-16 Thread Klaus Darilion
Hi! During rollover testing I quite often delete keys without properly settings the timestamps in the keys - it is testing only. This leads to such errors: error reading private key file example.com/NSEC3RSASHA1/64337: file not found To recover and restart my testing I: - remove the zone from

nsec3 opt-out confusion

2014-04-01 Thread Klaus Darilion
Hi! I use Bind 9.9.5 for inline signing. The zone is configured to use NSEC3 without opt-out: example.com 0 IN NSEC3PARAM 1 0 10 BEEF Nevertheless, most of the resulting NSEC3 records have the opt-out bit set and insecure delegations are indeed skipped (no NSEC3

Re: nsec3 opt-out confusion (bug report)

2014-04-01 Thread Klaus Darilion
? Thanks Klaus On 01.04.2014 15:35, Klaus Darilion wrote: Hi! I use Bind 9.9.5 for inline signing. The zone is configured to use NSEC3 without opt-out: example.com 0 IN NSEC3PARAM 1 0 10 BEEF Nevertheless, most of the resulting NSEC3 records have the opt-out bit set

Re: nsec3 opt-out confusion (bug report)

2014-04-01 Thread Klaus Darilion
On 01.04.2014 17:09, Chris Thompson wrote: On Apr 1 2014, Klaus Darilion wrote: [...] Nevertheless, it seems there are still two bugs: 1. The NSEC3 chain is not properly cleared when switching from non-opt-out to opt-out 2. The NSEC3PARAM record always has the opt-out flag clear, even if opt

Re: Sporadic but noticable SERVFAILs in specific nodes of an anycast resolving farm running BIND

2014-03-07 Thread Klaus Darilion
Answering myself: This bug is probably not your problem, as Bind has received the DNS query, otherwise it would not answer with SERVFAIL. regards Klaus On 05.03.2014 16:15, Klaus Darilion wrote: Does it only happen for IPv6 DNS requests? Maybe it is related to this: https://open.nlnetlabs.nl

Re: Sporadic but noticable SERVFAILs in specific nodes of an anycast resolving farm running BIND

2014-03-05 Thread Klaus Darilion
Does it only happen for IPv6 DNS requests? Maybe it is related to this: https://open.nlnetlabs.nl/pipermail/nsd-users/2014-January/001783.html klaus On 05.03.2014 14:16, Kostas Zorbadelos wrote: Greetings to all, we operate an anycast caching resolving farm for our customer base, based on

Bind 9.9.5 assertion failure

2014-02-11 Thread Klaus Darilion
Hi all! I just managed to crash Bind 9.9.5 with an assertion failure - see attached log file. What my script does is: 1. delete zone via rndc (in this case the zone does not exist) 2. add zone via rndc 3. rndc signing -nsec3param 4. rndc sign 5. rndc signing -nsec3param (this

Re: Bind 9.9.5 assertion failure

2014-02-11 Thread Klaus Darilion
) Only the second startup worked. Thanks Klaus On 11.02.2014 12:44, Klaus Darilion wrote: Hi all! I just managed to crash Bind 9.9.5 with an assertion failure - see attached log file. What my script does is: 1. delete zone via rndc (in this case the zone does not exist) 2. add zone via rndc 3

missing NOTIFY after rndc signing -clear all zone

2014-02-06 Thread Klaus Darilion
Hi! I just noticed that on rndc signing -clear all zone, Bind removes the private RRs, updates the NSEC3 RR, and increases the serial, but it does not send NOTIFYs. I guess this is a bug. I tested bind 9.9.5, with inline-signing of a zone. regards Klaus

Re: changing NSEC3 salt

2014-02-06 Thread Klaus Darilion
On 06.02.2014 14:58, Cathy Almond wrote: On 06/02/2014 12:58, Timothe Litt wrote: On 06-Feb-14 05:56, Cathy Almond wrote: On 05/02/2014 18:54, David Newman wrote: The Michael W. Lucas DNSSEC book recommends changing NSEC3 salt every time a zone's ZSK changes. Is this just a matter of a new

Re: changing NSEC3 salt

2014-02-06 Thread Klaus Darilion
On 06.02.2014 11:56, Cathy Almond wrote: On 05/02/2014 18:54, David Newman wrote: The Michael W. Lucas DNSSEC book recommends changing NSEC3 salt every time a zone's ZSK changes. Is this just a matter of a new 'rndc signing' command, or is some action needed to remove the old salt? thanks

NSEC3 hash collision

2014-02-03 Thread Klaus Darilion
Hi! I just stumbled across section 7.1 of RFC 5155 (http://tools.ietf.org/search/rfc5155#section-7.1): As the owner name is hashed, there is potential for a hash collision. What confuses me is: If a hash collision is detected, then a new salt has to be chosen, and the signing

How to query the incoming serial of a zone while inline signing

2014-01-30 Thread Klaus Darilion
Hi! I use Bind for inline signing between a hidden master and the public slaves. AFAIS Bind maintains 2 serials: one for the incoming unsigned zone (eg. used to match incoming NOTIFYs) and one for the outgoing signed zone. I want to monitor if my name servers are all up2date by monitoring

Re: How to query the incoming serial of a zone while inline signing

2014-01-30 Thread Klaus Darilion
On 30.01.2014 14:19, Mark Andrews wrote: In message 52ea4c56.5060...@pernau.at, Klaus Darilion writes: Hi! I use Bind for inline signing between a hidden master and the public slaves. AFAIS Bind maintains 2 serials: one for the incoming unsigned zone (eg. used to match incoming NOTIFYs

  1   2   >