Re: BIND 9.8.2 is now available

2012-04-10 Thread Mark K. Pettit
I will take this opportunity now to point out that upgrading to 9.9.X from any release prior to it might cause problems if you have any slave zones. 9.9.X by default saves slave zone files using masterfile-format raw;, and 9.8.X and earlier defaults to masterfile-format text;. It's easy to

Re: Feature request for dig

2012-03-07 Thread Mark K. Pettit
That's a little more output, but when you try it, notice that there's no dig org. DNSKEY in the output, which is the query that was hanging in my case. On Mar 6, 2012, at 9:10 PM, Mark Andrews wrote: dig +trace +qr +comment +question -- Mark Andrews, ISC 1 Seymour St., Dundas

Re: Feature request for dig

2012-03-07 Thread Mark K. Pettit
On Mar 7, 2012, at 6:23 PM, Mark Andrews wrote: Compile in +sigchase support and give it a root key. Evan Hunt told us (regarding +sigchase) in its current state it's terrible and you really shouldn't use it. I'm not sure who to believe. TCP has *never* been optional for DNS. Unfortunately

Feature request for dig

2012-03-06 Thread Mark K. Pettit
Hi, fellow BIND users. The other day I was attempting to diagnose a problem on a recursive resolving name server. I had just enabled DNSSEC Validation, and certain digs (such as www.isc.org, www.dnssec-failed.org) were failing. Even queries to non-signed domains such my own personal domain

Re: Bind to INADDR_ANY

2012-01-10 Thread Mark K. Pettit
There are some caveats to trying to use interface-interval to pick up new IPs. If your BIND drops privileges (e.g., by using the -u command-line option to named), you might have a problem getting BIND to bind() to the new IP addresses. For example, on FreeBSD if you use -u to drop privileges,

Re: Bind to INADDR_ANY

2012-01-10 Thread Mark K. Pettit
On Jan 10, 2012, at 5:53 PM, Doug Barton wrote: On 01/10/2012 17:34, Mark K. Pettit wrote: In my environment (FreeBSD) we've worked around this problem (just recently, in fact), and I can provide more details if there's any interest. well I'm definitely interested. :) The short answer

Re: epza.gov.tw. MX

2011-08-08 Thread Mark K. Pettit
On Aug 8, 2011, at 1:50 PM, Chris Thompson wrote: On Aug 8 2011, Mark K. Pettit wrote: My resolvers, running BIND 9.7.3P3, are having a difficult time resolving the MX record for the zone epza.gov.tw.. [...] Any idea why this might be happening? The delegation for epza.gov.tw from

Re: big improvement in BIND9 auth-server startup time

2011-08-08 Thread Mark K. Pettit
Not sure where to report this, but there's a problem in the documentation of BIND 9.7.4, as distributed by ISC. The Release Notes included in the bind-9.7.4 tarball, as well as the release notes on the web site: ftp://ftp.isc.org/isc/bind9/9.7.4/RELEASE-NOTES-BIND-9.7.4.html state that the

Re: bind 9 performance

2011-06-15 Thread Mark K. Pettit
One of the things that got us is we didn't know BIND 8 automatically created delegation records in a zone at the zone cut, if the nameserver knew of the existence of the cut. For example, if we have the following zones in our named.conf: zone example.com { ... }; zone sub.example.com { ...