Re: rDNS for RFC1918 network fails

2021-01-24 Thread Mark Andrews
Use the correct zone name. 1.168.192.IN-ADDR.ARPA You have the full /24 so you don’t need to use RFC2317 techniques. -- Mark Andrews > On 25 Jan 2021, at 08:04, Alex wrote: > > Hi, I have a fedora32 system with bind-9.11.25 and having a problem > with setting up a revers

Re: Secure Active Directory updates and allow-update-forwarding issues

2021-01-19 Thread Mark Andrews
Forwarding is designed for TSIG and works for SIG(0). It doesn’t work for GSS-TSIG. -- Mark Andrews > On 19 Jan 2021, at 22:23, Nagesh Thati wrote: > >  > Hi, > I am getting update failed on master DNS appliance when I am using > allow-update-forwadin

Re: "not subdomain of zone {XXXX} -- invalid response" errors found in named.run log

2021-01-13 Thread Mark Andrews
bdomain of zone {} -- invalid response" errors > found in named.run log > > Thanks mark, but why this issue is related to load balancer? > > > > -- Original Message -- > From: "Mark Andrews"; > Date: 2021-01-06

Re: SRV Record Server Availability

2021-01-06 Thread Mark Andrews
act/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from thi

Re: unsubscribe

2021-01-06 Thread Mark Andrews
ct/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org __

Re: "not subdomain of zone {XXXX} -- invalid response" errors found in named.run log

2021-01-06 Thread Mark Andrews
Complain to the administrators of the zone. They have not properly delegated it. We see this often with load balancers. The zone a.b.example has been delegated but the answer is as if it is from b.example. -- Mark Andrews > On 6 Jan 2021, at 21:02, 同屋 <39223...@qq.com> wrote: >

Re: check-names conflicts with SPF macro definition

2021-01-04 Thread Mark Andrews
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list

Re: Quick dynamic DNS?

2020-12-24 Thread Mark Andrews
See draft-ietf-dnssd-srp -- Mark Andrews > On 25 Dec 2020, at 12:22, Grant Taylor via bind-users > wrote: > > On 12/24/20 3:05 PM, Mark Andrews wrote: >> TSIG, GSS-TSIG and SIG(0) are all secure mechanisms to update DNS zones. > > Thank you for the follow up Mark

Re: Quick dynamic DNS?

2020-12-24 Thread Mark Andrews
means as long as the KEY records where added at the same time. -- Mark Andrews > On 25 Dec 2020, at 07:46, Grant Taylor via bind-users > wrote: > > On 12/24/20 8:48 AM, @lbutlr wrote: >> That is what example.com always is, yes. > > Sorry. I'm so used to people no

Re: special solution needed please

2020-12-20 Thread Mark Andrews
but this can't be, as this throws away the cached part in memory ... > > nslookup www.lan.home.arpa2001:db8:0:0:0::10 > this works from any client > > how can I face this? > > any hints/suggestions would be great; > > Thanks, > Walter > > >

Re: Forwarded lookup failing on no valid RRSIG

2020-12-20 Thread Mark Andrews
ve to > disable validation yourself, or select a better upstream. Personally I'd go > looking for a better upstream (or just stop using a forwarder entirely, and > do your own direct recursion, if that's possible in your environment). -- Mark Andrews, ISC 1 Seymour St., Dundas Val

Re: bind refusing update [never mind]

2020-12-19 Thread Mark Andrews
Stop using IP addresses for UPDATE authentication. Use TSIG instead between the DHCP server and named. -- Mark Andrews > On 19 Dec 2020, at 18:25, Dan Egli wrote: > > I guess sometimes you just need to look at it in a differnet way. I never > noticed it was using the 10.0.2.

Re: Forwarded lookup failing on no valid RRSIG

2020-12-18 Thread Mark Andrews
Correct it is not validating. Additionally it isn’t even DNSSES aware. It will need to be updated for you to validate through it. -- Mark Andrews > On 19 Dec 2020, at 05:07, Nicolas Bock wrote: > > Hi Mark, > > Thanks so much for the reply. I ran this command and a

Re: Forwarded lookup failing on no valid RRSIG

2020-12-17 Thread Mark Andrews
s software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW

Re: How Zone Files Are Read

2020-12-16 Thread Mark Andrews
tion is required, it should be present. 4. Information present outside of the authoritative nodes in the zone should be glue information, rather than the result of an origin or similar error." Those of use with long memories have seen all the errors scenarios reported here

Re: query-source and recursive options

2020-12-16 Thread Mark Andrews
Nameservers generate their own requests. Nameservers have to translate names to addresses as part of the notify process. -- Mark Andrews > On 16 Dec 2020, at 19:18, Xinyu Wang wrote: > >  > > > Hi guys, I noticed query-source takes effect even recursive is set false.

Re: Bind: named can't listen while using VRF

2020-12-14 Thread Mark Andrews
rt subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 211

Re: Weird DNS behaviour resolution issues when more labels are present in a zone

2020-12-13 Thread Mark Andrews
/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc

Re: How to selectively skip DNSSEC validation?

2020-12-07 Thread Mark Andrews
" and "dnssec-validation" options inside a zone definition. > > I look forward to your advice in this matter. > > Andrew Pavlin, KA2DDO > member, Amateur Radio Emergency Service > ___ > Please visit https://lists.

Re: Two copies of recent posts

2020-11-25 Thread Mark Andrews
://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lis

Re: Servfail on Bind -9.16.1

2020-11-22 Thread Mark Andrews
t; ;; flags: qr rd ra cd; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 1 > > ;; OPT PSEUDOSECTION: > ; EDNS: version: 0, flags: do; udp: 4096 > ; COOKIE: 028fb4fde9f61d5301005fbb1fcca2b3cd29887d7e13 (good) > ;; QUESTION SECTION: > ;www.facebook.com. IN DNS

Re: Servfail on Bind -9.16.1

2020-11-22 Thread Mark Andrews
tps://lists.isc.org/mailman/listinfo/bind-users > > > -- > upen, > emerge -uD life (Upgrade Life with dependencies) > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > >

Re: "in-view" behavior

2020-10-30 Thread Mark Andrews
__ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/conta

Re: How do I insert "CDS 0 0 0 0"?

2020-10-04 Thread Mark Andrews
All the fields must exist. NET_DNS2 is wrong. There must only be the delete cds/cdnskey records and not any other cds/cdnskey records. Publish and delete instructions at the same time is not consistent. -- Mark Andrews > On 5 Oct 2020, at 00:02, Mark Andrews wrote: > Use up t

Re: How do I insert "CDS 0 0 0 0"?

2020-10-04 Thread Mark Andrews
Use up to date software. -- Mark Andrews > On 4 Oct 2020, at 23:48, Mark Elkins wrote: > >  What is the magic incantation to inserting a "CDS 0 0 0 0" record in BIND. > Version - BIND 9.16.6 (Stable Release) > I've read RFC8070 - which says... (https://tool

Re: bind 9.16.7 Odd query error (Borja Marcos)

2020-09-30 Thread Mark Andrews
> On 1 Oct 2020, at 16:30, Borja Marcos wrote: > > > >> On 30 Sep 2020, at 22:34, Mark Andrews wrote: >> >> No, it’s just fetches per query taking effect. With a empty cache there are >> just too many queries made looking up addresses of name se

Re: bind 9.16.7 Odd query error (Borja Marcos)

2020-09-30 Thread Mark Andrews
No, it’s just fetches per query taking effect. With a empty cache there are just too many queries made looking up addresses of name servers. You can raise the default slightly. -- Mark Andrews > On 1 Oct 2020, at 01:29, Borja Marcos wrote: > >  > >> On 30 Sep 2

Re: different TTLs for multiple TXT records

2020-09-26 Thread Mark Andrews
It won’t happen and there is zero point in doing so as all RRs in a RRset are deleted at the same time. -- Mark Andrews > On 26 Sep 2020, at 23:59, Verne Britton wrote: > > I see that RFC2181, written I think 20+ years ago, says in part > > >> >> 5

Re: AppArmor, DHCP, Bind9 issue

2020-09-22 Thread Mark Andrews
Put the zone file in /var/lib/bind and update named.conf. -- Mark Andrews > On 23 Sep 2020, at 00:43, Olivier wrote: >  > Hello, > > I've got one ISC-DHCP server instance (4.4.1) and one Bind9 (9.11.5) instance > installed on a Debian Buster box. > Both come from

Re: Problem building BIND 9.11.23 on SPARC Solaris 10 w/ isc_atomic_xadd

2020-09-16 Thread Mark Andrews
Platforms > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org

Re: bind v6 record

2020-09-14 Thread Mark Andrews
D Buluukhuu > > Engineer > TPD/ETSD > UNESCO street - 28, MPM Complex > Ulaanbaatar -14220, Mongolia > Mobile: (976) 94081017 > Web: www.mobicom.mn > > Before you start - Be safety smart > > > > From: Mark Andrews > Sent: Tuesday, September 15, 2020 9

Re: bind v6 record

2020-09-14 Thread Mark Andrews
G SIZE rcvd: 122 > > > > > Have a nice day :) > BR, NYAMKHAND Buluukhuu > > Engineer > TPD/ETSD > UNESCO street - 28, MPM Complex > Ulaanbaatar -14220, Mongolia > Mobile: (976) 94081017 > Web: www.mobicom.mn > > Before you start - Be safety smart

Re: bind v6 record

2020-09-14 Thread Mark Andrews
www.mobicom.mn > > Before you start - Be safety smart > > > > From: Mark Andrews > Sent: Monday, September 14, 2020 5:22 PM > To: Nyamkhand Buluukhuu > Cc: bind-users@lists.isc.org > Subject: Re: bind v6 record > > You have a out-of-date local copy of t

Re: bind v6 record

2020-09-14 Thread Mark Andrews
paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PH

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-13 Thread Mark Andrews
take that is inevitable at some point, but likely >> short-lived. That's on them, not me. But I can sleep well at night >> knowing that such MISuse of my service isn't going to take out an >> entire datacenter for hours (with MANY innocent bystanders taken out, >> too!)

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-11 Thread Mark Andrews
> On 11 Sep 2020, at 22:22, Rob McEwen wrote: > > On 9/11/2020 2:46 AM, Mark Andrews wrote: >> validate-except (I typo’d it the second time, unfortunately expect and >> except are both valid words). > > I got so far down the rabbit trail with your other point

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-10 Thread Mark Andrews
rch that more to try to figure out what exactly you were suggesting. > > Rob McEwen > > On 9/11/2020 1:32 AM, Mark Andrews wrote: >>> On 11 Sep 2020, at 15:04, Rob McEwen wrote: >>> >>> Mark, >>> >>> The whole usage of DNS by the anti-spa

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-10 Thread Mark Andrews
hat they didn't anticipate. This one of those. RFCs > were written by humans. Humans make mistakes Actually I did. I said "add validate-expect entries to named.conf”. > And it's too bad that the maintainers of BIND didn't anticipate that there > might be local-data si

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-10 Thread Mark Andrews
S record with it. > That would be EXCELLENT news! Or, if that doesn't actually fix my problem, do > you have any suggestions that actually address my actual question? I gave you a answer. See below. Mark > Rob McEwen > > On 9/10/2020 7:37 PM, Mark Andrews wrote: >&

Re: rbldnsd and DNSSEC compatibility issues - any suggestions?

2020-09-10 Thread Mark Andrews
, invaluement > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https:/

Re: Upgrading from 9.14.12 to 9.16.4 - with existing DNSSEC zones

2020-09-01 Thread Mark Andrews
m this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users

Re: dnssec-keygen getting dates wrong

2020-08-30 Thread Mark Andrews
___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list >

Re: Error "Query section mismatch : got"

2020-08-19 Thread Mark Andrews
outhpark the movie) > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https:/

Re: intermittent failures and queries sent over TCP

2020-08-18 Thread Mark Andrews
.IP6.ARPA"; > disable-empty-zone > "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA"; > > > querylog yes; > > > }; > ___ > Please visit https://lists.isc.org/mailman/lis

Re: Invalid class in dns query

2020-08-05 Thread Mark Andrews
st > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andre

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-05 Thread Mark Andrews
Unfortunately comments section on that page doesn’t work. You press preview and you get a error response back. > On 6 Aug 2020, at 02:21, Brett Delmage wrote: > > On Wed, 5 Aug 2020, Mark Andrews wrote: > >> If I use the example zone on that page *no* errors are report

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-04 Thread Mark Andrews
> On 5 Aug 2020, at 13:12, Brett Delmage wrote: > > On Wed, 5 Aug 2020, Mark Andrews wrote: > >> Your key name usage is not consistent. acmesh-ottawatch != ottawatch-acmesh > > Thank you! Fixed and working. > >> Why are you adding `check-names warn;`?

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-04 Thread Mark Andrews
time: 0 msec > ;; SERVER: 127.0.0.1#53(127.0.0.1) > ;; WHEN: Tue Aug 04 18:31:26 EDT 2020 > ;; MSG SIZE rcvd: 140 > > > What am I missing ort doing wrong, please? > ___ > Please visit https://lists.isc.org/mailman/list

Re: nsupdate apparently not working for me. What am I overlooking / doing wrong?

2020-07-28 Thread Mark Andrews
A 3.4.5.9 > > ;; Query time: 0 msec > ;; SERVER: 23.111.69.176#53(23.111.69.176) > ;; WHEN: Tue Jul 28 22:17:33 EDT 2020 > ;; MSG SIZE rcvd: 88 > > > END OF DETAILS > > ___ > Please visit https://lists.isc.or

Re: broken trust chain

2020-07-28 Thread Mark Andrews
___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users ma

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-07-21 Thread Mark Andrews
> On 22 Jul 2020, at 08:23, @lbutlr wrote: > > On 21 Jul 2020, at 06:37, Mark Andrews wrote: >> On 21 Jul 2020, at 18:23, @lbutlr wrote: >>> >>> Bind is a poor choice for desktop use. Packages like unbound are much >>> better for that sort o

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-07-21 Thread Mark Andrews
mn. > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-07-20 Thread Mark Andrews
020, at 09:05, Mark Andrews wrote: > > > >> On 21 Jul 2020, at 03:45, Ted Mittelstaedt wrote: >> >> >> >> On 7/17/2020 11:35 AM, John W. Blue wrote: >>> Speaking about things to be annoyed over .. >>> >>> I am still tick

Re: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-07-20 Thread Mark Andrews
pment of this software with paid support subscriptions. >> Contact us at https://www.isc.org/contact/ for more information. >> >> >> bind-users mailing list >> bind-users@lists.isc.org >> https://lists.isc.org/mailman/listinfo/bind-users >

Re: DNS error, from a newbee to the real experts..

2020-07-18 Thread Mark Andrews
@ IN SOA ns2.example.home. hostmaster.example.home. ( > 2 ; Serial > 604800 ; Refresh 1week > 86400 ; Retry > 2419200 ; Expire 28days > 604800; Negative Cache TTL > ) > ;; name servers (NS) > ;; only authoritative servers > @

Re: Dynamic update rejected within a view

2020-07-14 Thread Mark Andrews
Include the update keys in the view selection. -- Mark Andrews > On 14 Jul 2020, at 23:06, Per Weisteen wrote: > >  Hi > > I've a BIND setup with my ISP with two views, one external and one internal. > At the same time I also need to be able to do a dynamic update

Re: root.hints access errors with Ubuntu BIND 9.16.4 16.04 PPA

2020-07-09 Thread Mark Andrews
e file name. Mark > Brett___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support sub

Re: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Mark Andrews
Very soon you will be able to specify HTTPS records. BIND has a implementation that is just waiting for the draft to go to the RFC editor. The type codes are already allocated. This still requires clients to lookup the records but the browser vendors are on board. -- Mark Andrews > On

Re: Dumb Question is an A or AAAA record required?

2020-07-09 Thread Mark Andrews
significantly more expensive to operate compared to straight routers. -- Mark Andrews > On 9 Jul 2020, at 22:22, @lbutlr wrote: > > Given a domain that is hosted and used for email and web, is an A record for > that domain actually required? > > That is, if bob.tld is hos

Re: Fun with nsudpate and ac1.nstld.com

2020-07-06 Thread Mark Andrews
bscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailm

Re: unknown option 'trust-anchors'

2020-07-05 Thread Mark Andrews
; from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lis

Re: Zone with DNAME has no NS records

2020-06-19 Thread Mark Andrews
Choose nameserver names that don’t end in .local. -- Mark Andrews > On 19 Jun 2020, at 21:29, Dev Op wrote: > >  > Hi all! > > I have a zone, say it's "mynet.local": > > $TTL 3h ; 3 hours > $ORIGIN pluto.local. > @ IN SOA dn

Re: New BIND releases ... 9.16.4: build, 'fatal error: lmdb.h: No such file or directory'

2020-06-18 Thread Mark Andrews
b64 > │ ├── liblmdb.a > │ └── liblmdb.so > ... > > is about as simple as it gets. > > fix it, remove it, or leave it as is -- your product, your choice. > > good luck. > ___ > Please vi

Re: BIND 9 recursive queries returning SERVFAIL for 'legit' domain

2020-06-17 Thread Mark Andrews
_ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more informa

Re: A And Cname-record

2020-06-17 Thread Mark Andrews
s that issue. Mark > -Alkuperäinen viesti- > Lähettäjä: bind-users Puolesta Mark Andrews > Lähetetty: 18. kesäkuuta 2020 0:27 > Vastaanottaja: Bogdan-Stefan Rotariu > Kopio: bind-users@lists.isc.org > Aihe: Re: A And Cname-record > > > >> On 18 Jun 2020, at 0

Re: A And Cname-record

2020-06-17 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > ISC funds the development of this software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. >

Re: nsupdate: using "wildcard" TTL when removing specific record

2020-06-01 Thread Mark Andrews
at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET

Re: 9.16.3 make tests on centos 8

2020-05-31 Thread Mark Andrews
Opened ticket. That system test appears to be very linux capabilities specific when run as root. > On 1 Jun 2020, at 06:36, Carl Byington via bind-users > wrote: > > I:runtime:verifying that named switches UID (14) > I:runtime:failed -- Mark Andrews, ISC 1 Seymour St., Dun

Re: automating DS Record submit to parent with 'new' kasp/dnssec-policy support in bind?

2020-05-26 Thread Mark Andrews
is software with paid support subscriptions. > Contact us at https://www.isc.org/contact/ for more information. > > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valle

Re: Best way to force a TC=1 response?

2020-05-26 Thread Mark Andrews
you'd > need four times as many Well ~2 times as many. Each additional A record requires 16 bytes and each addition records requires 28 bytes. That means ~256 A records and ~146 records to force TCP with a 4096 byte UDP buffer size. John’s example had 187 records. Mar

Re: Increase in retry and timeout errors post 9.9.4 -> 9.11.4 upgrade

2020-05-03 Thread Mark Andrews
> increased rate is not a problem but just representing different information. > > Gareth > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists

Re: Nsupdate and TTL

2020-04-23 Thread Mark Andrews
listed below. The UPDATE message is a bit larger but it is robust. Mark > On 23/04/2020 01:06, Mark Andrews wrote: >> >>> On 23 Apr 2020, at 07:20, Evan Hunt wrote: >>> >>> On Wed, Apr 22, 2020 at 03:04:38PM -0600, @lbutlr via bind-users wrote: >>&

Re: Nsupdate and TTL

2020-04-22 Thread Mark Andrews
the NS RRset is required to always exist. Note: named only keeps a single TTL for a RRset so it will update the TTL on all the records when you add a new one with a different TTL but this is not part of the UPDATE RFC. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +6

Re: NAT and Question Section Mismatch

2020-04-21 Thread Mark Andrews
The ultimate fix for this is to move to IPv6 so every device is universally addressable. NAT is a stop gap measure that is well past its use by date. > On 22 Apr 2020, at 09:03, Mark Andrews wrote: > > https://www.networkstraining.com/dns-doctoring-cisco-asa/ > >> On 18

Re: NAT and Question Section Mismatch

2020-04-21 Thread Mark Andrews
bscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _

Re: Batch updating all DNS records on my Bind server

2020-04-20 Thread Mark Andrews
t; “Some people, when confronted with a Unix problem, think ‘I know, >> I’ll use sed.’ Now they have two problems.” jwz - 12 Dec 1992 > > LOL, yes, I thought that quote was about regular expressions, but > either way it sure fits. > > > [1] Shakespeare's death, 404 years ago; birth, 456

Re: oddity with trubuiltpambula.com.au

2020-04-19 Thread Mark Andrews
w.biplane.com.au/kauer > http://twitter.com/kauer389 > > GPG fingerprint: 2561 E9EC D868 E73C 8AF1 49CF EE50 4B1D CCA1 5170 > Old fingerprint: 8D08 9CAA 649A AFEF E862 062A 2E97 42D4 A2A0 616D > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubs

Re: oddity with trubuiltpambula.com.au

2020-04-19 Thread Mark Andrews
> On 19 Apr 2020, at 20:52, Karl Auer wrote: > > trubuiltpambula.com.au -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://list

Re: "lame-servers: info: no valid RRSIG resolving ..."

2020-04-17 Thread Mark Andrews
Apr-2020 18:14:54.009 lame-servers: info: no valid RRSIG resolving > 'facebook.com/DS/IN': 192.5.6.30#53 > 15-Apr-2020 18:16:20.039 lame-servers: info: no valid RRSIG resolving > 'pphosted.com/DS/IN': 192.5.6.30#53 > > a number of these [most?] are zones that are signe

Re: BIND 9.16.1 failing assertion

2020-04-16 Thread Mark Andrews
__ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mar

Re: 9.16.2 / DNSSEC / DS records

2020-04-15 Thread Mark Andrews
t; > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ P

Re: 9.16.2 / DNSSEC / DS records

2020-04-15 Thread Mark Andrews
@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/listin

Re: BIND-9.16.1 & KASP

2020-04-13 Thread Mark Andrews
s will be silently ignored. If the first octet is zero (this is a reserved algorithm number that should never appear in a DNSKEY record) then the record indicates changes to the NSEC3 chains are in progress. The rest of the record contains an NSEC3PARAM record. The flag field tells what operation

Re: DHCPD - BIND DDNS: dnssec-keygen hmac-md5 removed

2020-04-12 Thread Mark Andrews
Use tsig-keygen. -- Mark Andrews > On 11 Apr 2020, at 09:52, moo can via bind-users > wrote: > >  > Hello, > > For educational purpose I need to setup an DDNS between DCHPD and BIND. > > Everywhere, debian, zytrax, freeipa, veritas ... use dnssec-keygen. &g

Re: Can we provide recursion for forward zones in response to iterative queries?

2020-04-07 Thread Mark Andrews
Add delegations if they are missing. This is how DNS is designed to be managed. This should have been done as part of allocating the address space initially. -- Mark Andrews > On 8 Apr 2020, at 02:43, bind-li...@iano.org wrote: > > Currently our linux caching resolvers have a f

Re: Can we provide recursion for forward zones in response to iterative queries?

2020-04-06 Thread Mark Andrews
ere a way to tell our bind > caching resolvers to ignore the recursion desired flag and provide recursion > anyway? > > Thanks, > Maria > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from

Re: update-policy wildcard grant

2020-04-01 Thread Mark Andrews
> On 2 Apr 2020, at 11:59, Jim Popovitch via bind-users > wrote: > > On Thu, 2020-04-02 at 09:27 +1100, Mark Andrews wrote: >>> On 2 Apr 2020, at 06:53, Jim Popovitch via bind-users < >>> bind-users@lists.isc.org> wrote: >>> >>> Hello!

Re: update-policy wildcard grant

2020-04-01 Thread Mark Andrews
> ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andre

Re: Machine friendly alternative to nsupdate

2020-04-01 Thread Mark Andrews
hmac-md5.sig-alg.reg.int. 1585729721 300 16 xx== > 30709 NOERROR 0 > > > Is there any alternative to nsupdate that can do this? Or some newer version > of nsupdate that can acomplish this? > > Thanks > > > *1 https://github.com/benapetr/dnsphpadmin > > __

Re: Non-disruptive migration to dnssec-policy possible?

2020-03-26 Thread Mark Andrews
ue > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo

Re: dnssec-lookaside auto key expiration

2020-03-25 Thread Mark Andrews
egards, > > - Håvard > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.is

Re: Compile error Bind 9.16.1 on MacOS 10.14.6

2020-03-24 Thread Mark Andrews
>>> -- >>> Larry Stone >>> la...@stonejongleux.com >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> -- >>> Larry Stone >&

Re: How to get random subset of large rrset (30+ IPs for round robin)?

2020-03-20 Thread Mark Andrews
sers to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org __

Re: Can't get rid of key

2020-03-10 Thread Mark Andrews
and the content of /var/named/keys are? > On 11 Mar 2020, at 12:06, Alan Batie wrote: > > On 3/10/20 5:51 PM, Mark Andrews wrote: >> So what do you still have related to the zone? Have you examined the >> contents of those files? Some of them may be binary so grep w

Re: Bind Resign Zone behavior

2020-03-10 Thread Mark Andrews
client @0x7d61c801d000 > 172.29.62.4#43508 (45.10.0.10.in-addr.arpa): transfer of > '45.10.0.10.in-addr.arpa/IN': IXFR ended > > Best regards, > -- > Smil Milan Jeskyňka Kazatel > ___ > Please visit https://list

Re: Can't get rid of key

2020-03-10 Thread Mark Andrews
___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Aus

Re: key signing

2020-03-10 Thread Mark Andrews
sers to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___

Re: NS failover as opposed to A record failover

2020-02-25 Thread Mark Andrews
info/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.

Re: zsk rollover

2020-02-25 Thread Mark Andrews
> On 26 Feb 2020, at 08:40, Alan Batie wrote: > > On 2/25/20 1:30 PM, Mark Andrews wrote: >> Firstly unset the deletion date for the old key. It is way >> too early for incremental re-signing. Named replaces RRSIG >> *as-they-fall-due* for re-signing. With the

Re: zsk rollover

2020-02-25 Thread Mark Andrews
V86TFY5+uBd1uN8DVBtHnz > M1IBekumCyMliqHL4+7xtVrZccu2CINo6TukJvfz+SI/jQJUjXbfyuDN > uVUPE+JVeuiwPC1Y++Wg+S9oJrpsSp8Vm+j/NqdescDRknhWMYZGQ5HL > 6xXgrqGZJ6EGC3FgH7WXU6oAmYxSZE8mGZp/2IiXLTefX8Si3bDMLxOe Av7p/BAAbgM= > > > ___ > Please vis

<    1   2   3   4   5   6   7   8   9   10   >