Re: "minimal-any" configuration query

2020-09-17 Thread Tony Finch
ShubhamGoyal wrote: > We have enabled " minimal-any yes;" in our Bind DNS Sever, Yet an ANY > query provides complete details instead of providing reduced details . Testing minimal-any with dig is tricky and very obscure! For an example of how to test it, try: dig cam.ac.uk any

Re: RRSIG and TTL

2020-09-17 Thread Tony Finch
Scott Nicholas wrote: > > Primary nameserver is behind a cache/proxy on enterprise network such that > all external traffic hits this. Zone went bogus. I blame policy but on > further inspection 2/3 proxys had differing TTL between the DNSKEY and it's > RRSIG. Hmm, that's suspicious. In the DNS,

Re: RRSIG and TTL

2020-09-17 Thread Scott Nicholas
I was just thinking to update this. The auth server on our end is Infoblox with few knobs for timing (it's not awful but could definitely be better). The caching resolver is BIND. I wasn't initially aware of the transparent cache between. That must be the thing with the implementation bug. It's

Updated: Vim syntax for zone files (as well as named.conf)

2020-09-17 Thread S Egbert
This is the first announcement of the update to Vim syntax of DNS zone data file. The syntax update entails nearly all resource record (RRset) codes possible for zone files. Also, for named.conf, I've updated the syntax file to reflect 9.16.1  and nearly all of 9.17.4. Backdrop: Vim syntax