Re: Disabling DNSSEC validation per zone?

2011-07-11 Thread Tony Finch
Daniel McDonald dan.mcdon...@austinenergy.com wrote: ; DiG 9.8.0-P4 @localhost ips.backscatterer.local ds ; (1 server found) ;; global options: +cmd ;; Got answer: ;; -HEADER- opcode: QUERY, status: NXDOMAIN, id: 26308 ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL:

Re: Disabling DNSSEC validation per zone?

2011-07-11 Thread Daniel McDonald
On 7/11/11 12:15 PM, Tony Finch d...@dotat.at wrote: Daniel McDonald dan.mcdon...@austinenergy.com wrote: ; DiG 9.8.0-P4 @localhost ips.backscatterer.local ds ; (1 server found) ;; global options: +cmd ;; Got answer: ;; -HEADER- opcode: QUERY, status: NXDOMAIN, id: 26308 ;; flags:

Disabling DNSSEC validation per zone?

2011-07-08 Thread Daniel McDonald
I have a number of zones being served by rbldnsd, with bind as a front-end. The zones are defined as forward only in named.conf. When I enable dnssec validatation, these zones report that they are insecure. 08-Jul-2011 08:55:58.700 dnssec: info: validating @0xb4260ad8: ips.backscatterer.local

Re: Disabling DNSSEC validation per zone?

2011-07-08 Thread Tony Finch
Daniel McDonald dan.mcdon...@austinenergy.com wrote: 08-Jul-2011 08:55:58.700 dnssec: info: validating @0xb4260ad8: ips.backscatterer.local SOA: got insecure response; parent indicates it should be secure I¹m not really certain which parent is reporting this The root zone says that .local

Re: Disabling DNSSEC validation per zone?

2011-07-08 Thread Phil Mayers
On 08/07/11 15:13, Daniel McDonald wrote: I have a number of zones being served by rbldnsd, with bind as a front-end. The zones are defined as forward only in named.conf. When I enable dnssec validatation, these zones report that they are insecure. 08-Jul-2011 08:55:58.700 dnssec: info:

Re: Disabling DNSSEC validation per zone?

2011-07-08 Thread Daniel McDonald
On 7/8/11 10:41 AM, Phil Mayers p.may...@imperial.ac.uk wrote: On 08/07/11 15:13, Daniel McDonald wrote: I have a number of zones being served by rbldnsd, with bind as a front-end. The zones are defined as forward only in named.conf. When I enable dnssec validatation, these zones report

Re: Disabling DNSSEC validation per zone?

2009-09-02 Thread Hauke Lampe
Mark Andrews wrote: In message 4a99abeb.7080...@hauke-lampe.de, Hauke Lampe writes: I am looking for way to disable DNSSEC lookaside validation for a given zone. For any query to this zone, BIND tries to look up example.net.dlv.isc.org DLV records. If the external internet connection is