Re: DNSSEC and forwarding

2022-03-30 Thread Tony Finch
Duchscher, Dave J via bind-users wrote: > We have an internal DNS server that we would like to forward its > outgoing queries to a main DNS server that connects to the outside world > and is doing DNSSEC validation. The problem is that the DNSSEC > validation doesn't work for queries from the

DNSSEC and forwarding

2022-03-30 Thread Duchscher, Dave J via bind-users
We have an internal DNS server that we would like to forward its outgoing queries to a main DNS server that connects to the outside world and is doing DNSSEC validation. The problem is that the DNSSEC validation doesn't work for queries from the internal DNS server. Doing DNSSEC validation on

Re: Periodic SERVFAIL for TLD .BY

2022-03-30 Thread Dzmitry Shykuts
"servfail-ttl 0" doesn't help. вт, 29 мар. 2022 г. в 18:16, Ondřej Surý : > The .by domain is kind of bonkers… > > Step 1: get nameservers for 103.by: > > $ dig +noall +authority IN NS 103.by. @a.root-servers.net > by. 172800 IN NS dns1.tld.becloudby.com. > by.

Expired secondary zone retry-interval?

2022-03-30 Thread Oskar
Hi! I just experienced an outage where a zone is defined via catalogzone and the following is set: SOA Refresh 900 SOA Retry 300 SOA Expiry 3600 (i'm aware it's very short) Primary was intermittently unreachable and had wrong config for about 1.5h. According to logs the Secondary was retrying

Re: Question about missing bind.keys

2022-03-30 Thread Evan Hunt
On Wed, Mar 30, 2022 at 12:16:05AM -0400, J Doe wrote: > I have a question about the bind.keys file and what happens when it is > not available. [...] > ** If I don't have bind.keys in my BIND directory but have: > dnssec-validation auto in my named.conf, is BIND automatically getting > the