Re: Multiple BIND instances

2012-02-07 Thread lst_hoe02
Zitat von sasa sasa sasasa20...@yahoo.com: Hi, I got a server with 16GB memory, want to install 2 BIND on CentOS, one cache only and another authoritative. Is it better to install 2 OS virtually and run BIND in them or run 2 instances of BIND on the same OS? I mean what is the best practice

Re: Multiple BIND instances

2012-02-07 Thread Matus UHLAR - fantomas
On 2/7/2012 11:17 AM, Matus UHLAR - fantomas wrote: You can even run a single BIND instance with two separate views and that should not affect functionality. On 07.02.12 04:02, sasa sasa wrote: Wouldn't this have mixed (one) caches? No, unless you use attach-cache directive. However, the

Re: Multiple BIND instances

2012-02-07 Thread Mark Andrews
In message 1328616138.50948.yahoomail...@web120103.mail.ne1.yahoo.com, sasa sasa writes: On 2/7/2012 11:17 AM, Matus UHLAR - fantomas wrote: You can even run a single BIND instance with two separate views and that should not affect functionality. Wouldn't this have mixed (one) caches?

Re: Multiple BIND instances

2012-02-07 Thread Steve Arntzen
On Mon, 2012-02-06 at 23:09 -0800, sasa sasa wrote: Hi, I got a server with 16GB memory, want to install 2 BIND on CentOS, one cache only and another authoritative. Is it better to install 2 OS virtually and run BIND in them or run 2 instances of BIND on the same OS? I mean what is the best

Re: Multiple BIND instances

2012-02-07 Thread /dev/rob0
On Tue, Feb 07, 2012 at 03:17:45PM +0800, Jeff Peng wrote: 于 2012-2-7 15:09, sasa sasa 写道: I got a server with 16GB memory, want to install 2 BIND on CentOS, one cache only and another authoritative. Is it better to install 2 OS virtually and run BIND in them or run 2 instances of BIND on

Re: How to validate DNSSEC signed record with dig?

2012-02-07 Thread William Thierry SAMEN
Hi everybody, sorry for my post i'm not read to bring a light to the 1st problem but to find help. I'm triying to sign a zone on Bind 9.8-P1 but i have this message: *dnssec-signzone: fatal: key myKSK.key not at origin* I just want help if someone has been confronted with this kind of message

Re: How to validate DNSSEC signed record with dig?

2012-02-07 Thread Tony Finch
William Thierry SAMEN thierry.sa...@gmail.com wrote: I'm triying to sign a zone on Bind 9.8-P1 but i have this message: *dnssec-signzone: fatal: key myKSK.key not at origin* It means the zone name in the key is not the same as the zone you are signing. Tony. -- f.anthony.n.finch

RE: How to validate DNSSEC signed record with dig?

2012-02-07 Thread Spain, Dr. Jeffry A.
dnssec-signzone: fatal: key myKSK.key not at origin What are the contents of myKSK.key? The format is mydomain.com. IN DNSKEY ... where mydomain.com is the domain origin. Jeffry A. Spain Network Administrator Cincinnati Country Day School ___ Please

Re: Multiple BIND instances

2012-02-07 Thread Doug Barton
I'm not sure why this answer has gone off into the weeds, but running 2 instances on the same host is quite simple. 1. Get 2 different (hopefully sets of v4 and v6) IP addresses, one for each instance. 2. Set up 2 different chroot environments, one for the authoritative and one for the resolver.

PLEASE READ: An Important Security Announcement from ISC

2012-02-07 Thread Michael McNally
PLEASE READ: An important security announcement from ISC ISC has been notified by Haixin Duan (a professor at Tsinghua University in Beijing China, who is currently visiting the International Computer Science Institute (ICSI) at the University of California, Berkeley) about a DNS