RE: redundant bump-in-the-wire signers using BIND

2018-05-22 Thread Browne, Stuart via bind-users
Tony, Our environment has the secondary set up as a slave with 'raw' zones in the same paths, so upon primary failure, change the zone roles to 'master' and include the inline signing stanzas. They keys are duplicated using an external process. Happy days. Now if only BIND could to a true mul

nsupdate with RPZ

2018-05-22 Thread Blason R
Hi Team, Wondering if anyone have a working How-To guide for implementing nsupdate with RPZ? I mean do we need to configure any specific settings in zone of Options? Please advise TIA ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users t

Re: Saurabh: Not getting the answer with AAAA record. Error FORMERR resolving 'gim8.pl/AAAA/IN comes.

2018-05-22 Thread Tony Finch
Saurabh Srivastava wrote: > I have faced an issue on my RPZ Server. > I have added the A record Entry & record entry for some domains. > The RPZ Policy is running fine. > But the werired response that i am getting with few domains are that when I > have quered the A record for that domain, t

Saurabh: Not getting the answer with AAAA record. Error FORMERR resolving 'gim8.pl/AAAA/IN comes.

2018-05-22 Thread Saurabh Srivastava
Dear Bind-Users, Greetings of the Day!!! I have faced an issue on my RPZ Server. I have added the A record Entry & record entry for some domains. The RPZ Policy is running fine. But the werired response that i am getting with few domains are that when I have quered the A record for that doma

Re: redundant bump-in-the-wire signers using BIND

2018-05-22 Thread Tony Finch
Michael Sinatra wrote: > > My only concern is that serial numbers might get out of sync between the > two signers at some point. You can avoid this problem with `serial-update-method unixtime`. HOWEVER! I think you are going to have problems with inconsistent IXFRs depending on which signer the