Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Phil Mayers
On 04/15/2012 11:40 PM, Tobias Krais wrote: Hi Ben, hmm. How can I manage what google suggests: Information for school network administrators about the No-SSL option To utilize the no SSL option for your network, configure the DNS entry for www.google.com to be a CNAME for

How to stop ANY zone transfer

2012-04-16 Thread Chiesa Stefano
Hello all. I'm developing a web application to apply massive dns changes automatically. I have a master dns server and three slaves. To test the application I'm going to create an identical copy of the master server (in the same network too). What is scaring me is the update of the slaves. If I

Re: How to stop ANY zone transfer

2012-04-16 Thread Phil Mayers
On 16/04/12 10:35, Chiesa Stefano wrote: Hello all. I'm developing a web application to apply massive dns changes automatically. I have a master dns server and three slaves. To test the application I'm going to create an identical copy of the master server (in the same network too). What is

Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Lyle Giese
On 4/16/2012 3:30 AM, Phil Mayers wrote: On 04/15/2012 11:40 PM, Tobias Krais wrote: Hi Ben, hmm. How can I manage what google suggests: Information for school network administrators about the No-SSL option To utilize the no SSL option for your network, configure the DNS entry for

RE: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Matthew Huff
Actually, this can be done. Create a zone file for www.google.com, not google.com. The zone file should like this (replace THIS_HOSTNAME with the name of your nameserver: @ IN SOA localhost root@localhost. ( 2012041100

Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Alan Clegg
On 4/16/2012 9:40 AM, Matthew Huff wrote: Actually, this can be done. Create a zone file for www.google.com, not google.com. The zone file should like this (replace THIS_HOSTNAME with the name of your nameserver: @ IN SOA localhost root@localhost. (

RE: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Ben Croswell
This is incorrect. It is illegal to have a cname and any other record on the same name in dns. The ns and soa count as records. On Apr 16, 2012 9:41 AM, Matthew Huff mh...@ox.com wrote: Actually, this can be done. Create a zone file for www.google.com, not google.com. The zone file should

Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread /dev/rob0
On Mon, Apr 16, 2012 at 09:40:16AM -0400, Matthew Huff wrote: Actually, this can be done. Create a zone file for www.google.com, not google.com. The zone file should like this (replace THIS_HOSTNAME with the name of your nameserver: @ IN SOA localhost

Split DNS and zone transfers

2012-04-16 Thread Eric Chandler
I have a situation where I need to filter out our private infrastructure from our public-facing DNS servers. This is certainly something that should have been done a long time ago, but I just recently took over the spot. Now, I've seen plenty of examples using views and separate zonefiles, but

Re: Split DNS and zone transfers

2012-04-16 Thread Phil Mayers
On 16/04/12 16:36, Eric Chandler wrote: Now, what I would like to have are slave servers that would zone-xfer both the internal and external-flavored files for example.com and serve You need to use TSIG keys, and match on key rather than IP address. This comes up on the list from time to

RE: Split DNS and zone transfers

2012-04-16 Thread Eric Chandler
I've been pointed to the right place to figure this out. The answer is in using TSIG. That saved me a lot of time. I searched everywhere but the most-obvious place - the bind9 faq. Eric Chandler Systems Architect From: bind-users-bounces+eric.chandler=vonage@lists.isc.org

Re: Configuring CNAME for nosslsearch.google.com

2012-04-16 Thread Chris Buxton
On Apr 15, 2012, at 3:40 PM, Tobias Krais wrote: Hi Ben, hmm. How can I manage what google suggests: Information for school network administrators about the No-SSL option To utilize the no SSL option for your network, configure the DNS entry for www.google.com to be a CNAME for

RE: Split DNS and zone transfers

2012-04-16 Thread Lightner, Jeff
You can also do it by IP in views but need separate IPs for each view. You can do that with virtual IPs on the same NICs as the primary IPs. Such virtual IPs of course have to be in the same subnet as the primary and also you’d need to insure firewall (including host level if any) is opened

Test DNSSEC validation

2012-04-16 Thread Augie Schwer
What is the best way to log DNSSEC failures in Bind without enforcing DNSSEC validation? That is I want to see what Bind would have rejected because of failed DNSSEC validation, but I do not want to return SERVFAIL to my client. -- Augie Schwer    -    au...@schwer.us    -    http://schwer.us