Re: CH/TXT/VERSION.SERVER queries

2022-11-21 Thread Ray Bellis
On 21/11/2022 17:26, Petr Špaček wrote: Speaking of default CHAOS zones, I have another idea: Do we need them after NSID was standardized? Yes. There is a lot of special code just for built-in CH zones, and IIRC we have had at least one CVE which affected default config only because of

Re: CH/TXT/VERSION.SERVER queries

2022-11-21 Thread Petr Špaček
Speaking of default CHAOS zones, I have another idea: Do we need them after NSID was standardized? There is a lot of special code just for built-in CH zones, and IIRC we have had at least one CVE which affected default config only because of default CH usage. Anand, what would be missing if

Re: dnssec-policy - CSK rollover help

2022-11-21 Thread vom513
> On Nov 21, 2022, at 3:29 AM, Matthijs Mekking wrote: > > Hi, > > It is hard to see what the problem is without any configuration or state > information. Also, log level debug 3 gives you probably more useful logs when > investigating a problem. > > Can you share (privately if you wish)

Re: dnssec-policy - CSK rollover help

2022-11-21 Thread Matthijs Mekking
Hi, It is hard to see what the problem is without any configuration or state information. Also, log level debug 3 gives you probably more useful logs when investigating a problem. Can you share (privately if you wish) the key **state** files, and the output of 'rndc dnssec -status' for the