Re: DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2021-12-30 Thread raf
On Fri, Dec 31, 2021 at 10:45:12AM +1100, raf wrote: > On Thu, Dec 30, 2021 at 09:07:54AM +0100, Danilo Godec via bind-users > wrote: > > > On 29. 12. 21 19:24, tale wrote: > > > On Wed, Dec 29, 2021 at 5:31 AM Danilo Godec via bind-users > > > wrote: > > > > I have an authoritative DNS

Re: DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2021-12-30 Thread raf
On Thu, Dec 30, 2021 at 09:07:54AM +0100, Danilo Godec via bind-users wrote: > On 29. 12. 21 19:24, tale wrote: > > On Wed, Dec 29, 2021 at 5:31 AM Danilo Godec via bind-users > > wrote: > > > I have an authoritative DNS server for a domain, but I was also going to > > > use the same server as

Re: DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2021-12-30 Thread Reindl Harald
Am 30.12.21 um 09:07 schrieb Danilo Godec via bind-users: On 29. 12. 21 19:24, tale wrote: On Wed, Dec 29, 2021 at 5:31 AM Danilo Godec via bind-users wrote: I have an authoritative DNS server for a domain, but I was also going to use the same server as a recursive DNS for my internal

No "notify" category debug log entries anymore with Bind 9.11.3

2021-12-30 Thread Hildegard Meier
On old server with Ubuntu 12 and Bind 9.8.1 I got the following "notify" category log entries as expected (domain names and IP addresses redacted): 27-Dec-2021 12:58:51.786 notify: debug 3: zone example.com/IN: sending notify to 1.2.3.4#53 27-Dec-2021 12:58:51.816 notify: debug 3: zone

Re: Spurious failures in a dynamically updated to a sub /24 reverse DNS domain P.S.

2021-12-30 Thread Mirsad Goran Todorovac
Dear Tony, Yes, the CARNet network guys have replied with an email acknowledging the have corrected the bug in configuration ;-) They thanked for the pointer to the actual bug. I just tested the settings from three available servers (though all in .hr domain), and it works now like it never

Re: DNS cache poisoning - am I safe if I limit recursion to trusted local networks?

2021-12-30 Thread Danilo Godec via bind-users
On 29. 12. 21 19:24, tale wrote: On Wed, Dec 29, 2021 at 5:31 AM Danilo Godec via bind-users wrote: I have an authoritative DNS server for a domain, but I was also going to use the same server as a recursive DNS for my internal network, limiting recursion by the IP. Apparently, this is a bad