Re: Option in named to turn off EDNS Globally

2016-08-04 Thread Mark Andrews
t all the bits are significant. server 0.0.0.0/0 { edns no; }; server ::/0 { edns no; }; But why do you need to turn off EDNS? Its almost always not what is needed. Mark > But does not seem to work > > Any other options? > > Thanks > > Harshith -- Mark Andrews, ISC 1 Se

Re: change response cache ttl (--enable-cache-ttl)

2016-08-04 Thread Mark Andrews
. Or add a counter to the rdataset and once so many queries for the rdataset have been made just prefetch it. This will cause the ttl to be renewed and desyncronise down stream caches. Or both. > - Kevin > > > > > -Original Message-

Re: change response cache ttl (--enable-cache-ttl)

2016-08-04 Thread Mark Andrews
llion clients each with a local cache they all expire the record simultaniously and if it is a popular address then you get a million DNS queries in the second after the ttl has expired as all those local caches refresh. This is a attempt to distribute the query load from those caches uniformly rather

Re: outgoing-traffic

2016-07-26 Thread Mark Andrews
://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: Query on the Order in which RR are answered by Bind of Order/preference are Same

2016-07-18 Thread Mark Andrews
liberty to obtain a little temporary > safety deserve neither liberty nor safety. -- Benjamin Franklin, 1759 > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bin

Re: SOA record not signed with new key at key-rollover

2016-07-16 Thread Mark Andrews
r this domain > key-directory "keys"; > auto-dnssec maintain; > }; > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list

Re: Breaking trusted chain in dnssec

2016-07-13 Thread Mark Andrews
In message , rams writes: > > Greetings...! > Is any one explain how to break trusted chain in dnssec with example how to > create zone or data with trusted chain break. > > Thanks & Regards, > ramesh You have a delegation without a DS record. -- Mark Andrews,

Re: Automatic DNSSEC signing workflow

2016-07-05 Thread Mark Andrews
om the server and strips out the most of the DNSSEC records prior to editing. Really large changes need to be done in smaller chucks but for day to day changes it should be not significantly different from what is currently being done and you don't have to remember to update the serial. Mark

Re: bind-users Digest, Vol 1727, Issue 1

2016-07-04 Thread Mark Andrews
sdns-06.net. ;; Received 209 bytes from 205.251.196.138#53(ns-1162.awsdns-17.org) in 100 ms -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://l

Re: mail.protection.outlook.com queries to ns1-proddns.glbdns.o365filtering.com

2016-07-01 Thread Mark Andrews
h3VLL > =WiA/ > -END PGP SIGNATURE- > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.is

Re: any tool or command to find/verify the closest encloser NSEC3 record

2016-06-28 Thread Mark Andrews
& Regards, > Ramesh named :-) By hand: 'nec3hash' and a little knowledge of the zone's structure. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _

Re: DNSSEC validation failures for www.hrsa.gov

2016-06-25 Thread Mark Andrews
In message , Jay Ford writes: > On Sat, 25 Jun 2016, Mark Andrews wrote: > > The servers for webfarm.dr.hrsa.gov are not EDNS and DNSSEC compliant. > > They are returning FORMERR to queries with EDNS options. Unknown > > EDNS options are supposed to be ignored (RFC 6

Re: DNSSEC validation failures for www.hrsa.gov

2016-06-24 Thread Mark Andrews
ut it doesn't say it's bogus. > > If anybody can spot something broken for www.hrsa.gov, I'd be very glad to > hear about it. > > > Jay Ford, Network Engineering Group, Information Technology Service

Re: disable ipv6 source query

2016-06-21 Thread Mark Andrews
> 2001:dcd:1::7.53: 33940% [1au] A? > example.com. (48) > 21:04:34.146521 IP 1.1.1.1.58822 > 2.2.2.2: 55501% [1au] A? example.com. > (48) > > > My question is how to config named to only using v4 address to query other > nameserver, but still keep an listening v6 addres

Re: Issues resolving outlook.office365.com

2016-06-19 Thread Mark Andrews
nes once the cache TTL of the queried record expires. We can > reproduce it with the latest patch levels of both 9.10 and 9.9. > > > > Regards, > > Thomas > > > > > > [1] > http://intodns.com/geo.office365.com__

Re: Reverse Name Resolution Zone File

2016-06-13 Thread Mark Andrews
- > Ron Wingfield, > CEO WaterMark Marine Industries, Inc. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users ma

Re: DS record update via nsupdate

2016-06-13 Thread Mark Andrews
site that a NS rrset exists at the name. It the prerequiste fails you will get a error. > Best regards, > > -- > > *CS Catalin LEANCA* > ICI ROTLD - Serviciul Tehnic > Bd. Maresal Averescu 8-10, > Sector 1, Bucuresti > Mobil: +40 744 81 -- Mark Andrews, ISC 1 S

Re: Does BIND-9.9.9-P1 change the control command log to not show the zone name?

2016-06-12 Thread Mark Andrews
> > https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=blobdiff;f=bin/named > /control.c;h=b1b744f2ceabf4bdeb706e3c5f145adc0d6a0843;hp=aacb0884fde0a85b386 > 0f37c70714bde1e49ac22;hb=3bbb17429d53ba42ef9356c9b5dfcbf5d9647fcc;hpb=6cd768 > 47a19cbafadad349fd90a216e8807bc461 &g

Re: Why isn't my Bind server answering this query

2016-06-08 Thread Mark Andrews
me: 0 msec > ;; SERVER: 127.0.0.1#53(127.0.0.1) > ;; WHEN: Wed Jun 8 15:24:09 2016 > ;; MSG SIZE rcvd: 85 > > ------ > -- Which is correct for that zone. Try &quo

Re: Ability to limit memory usage for zones on an authoritative server.

2016-06-02 Thread Mark Andrews
out 10 Gig. Didn't expect that. Some mallocs use mmap to work past datasize limits. > Appreciate anyone aware of a config setting that would > limit usage. > Many thanks! > John > > > John Murtari - jm5...@att.com<mailto

Re: BIND 9.10.4 may have a fatal crash defect.

2016-05-17 Thread Mark Andrews
assertion failure) > > > Would love to assist in troubleshooting in any way we might be able to. > > Benjamin > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users

Re: Forward zone not working

2016-05-16 Thread Mark Andrews
In message , Alan Clegg writes: > On 5/16/16, 6:30 PM, "Mark Andrews" wrote: > > >Ideally every machine should be registering its own PTR record in > >the DNS and addresses without machines shouldn't have PTR records. > >The only reason ISP did this is t

Re: Forward zone not working

2016-05-16 Thread Mark Andrews
bnet. > > > > This is silly. Don't do this. > > Why? > > Most ISPs set up reverse & forward domain names for pool addresses. > OK, I'm not an ISP, but it really seems to be a widely accepted and > endorsed policy, to the point that addresses not ha

Re: Logging question about message 'update-security: error: client update denied'

2016-05-16 Thread Mark Andrews
t I > can get more detail of what specifically the DNS slave server is trying to > update the master with (maybe via more verbose output on the slave itself)? > > Master BIND version: BIND 9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1 > Slave BIND version: BIND 9.8.2rc1-RedHat-9.8.2-0.17.rc

Re: New type of DDoS? Anyone saw it?

2016-05-16 Thread Mark Andrews
w up outbound connections. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from th

Re: Forward zone not working

2016-05-16 Thread Mark Andrews
If you want to delegate space to another server DELEGATE it. Add NS records for the other server. Forward "zones" are NOT designed to do this. Doing actual delegations is *not* hard and works with every server in the world. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley

Re: New type of DDoS? Anyone saw it?

2016-05-16 Thread Mark Andrews
ries is a bad idea as most machines actually have a addresses (loopback and linklocal) so just about every application makes queries. If you drop queries you slow up every address lookup in your network. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NS

Re: NOTAUTH errors in a hidden Master with two Slaves setup

2016-05-06 Thread Mark Andrews
on the slaves named.conf. > > Thank you. > > On May 6, 2016, at 8:26 PM, Mark Andrews > mailto:ma...@isc.org>> wrote: > > > Stop with this "myzone.com<http://myzone.com>" garbage. IT DOES NOT > HELP. You almost > certainly have a typo which we

Re: NOTAUTH errors in a hidden Master with two Slaves setup

2016-05-06 Thread Mark Andrews
/myzone.com.db"; > notify yes; > allow-transfer { intnameservers; }; > allow-update { key "DHCP_UPDATER"; }; > }; > > Slaves Configuration: > zone "wfme2106.com.br<http://wfme2106.com.br>" { > type slave; > file "/usr/local/etc/namedb/slav

Re: Monitor DNS queries toward Root severs

2016-05-04 Thread Mark Andrews
tcpdump -n \( host a.root-servers.net or host b.root-servers.net \) and dst port 53 fill in with the rest of the root servers names. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org

Re: Multiple SERVFAIL/REFUSED unexpected RCODE

2016-05-03 Thread Mark Andrews
for the zone but doesn't have a current copy. You could use whois to try to contact the administrators of these zones to correct the servers or remove the delegations. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET:

Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-29 Thread Mark Andrews
one files > > grep Y \ >/var/chroot/named/namedb/master/example.com.zone \ >/etc/named/namedb/master/example.com.zone > (empty) > > It's official. This is driving me nuts. > > Jason > _

Re: bind 9.10.3-P4 listener exits unceremoniously - bug?

2016-04-29 Thread Mark Andrews
gt; Mark Boolootian > UC Santa Cruz > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listin

Re: 9.10.4 build fails in dlz/modules/filesystem; 9.10.3-P4 ok.

2016-04-28 Thread Mark Andrews
*dlzname, unsigned int argc, char *argv[], dlz_destroy(cd); /* return error */ - return (ISC_R_NOMEMORY); + return (result); } void -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma

Re: named DNS resolution latency

2016-04-26 Thread Mark Andrews
c-validation auto;" so you are not depending upon dlv for all your validation. The root was signed years ago. Secondly have you changed firewall setting lately? Thirdly check you logs. Look at packet traces of port 53 traffic. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, A

Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-24 Thread Mark Andrews
that. > > Why was the journal not written to the zone file on exit? That's > something named DOES do. It depends on how named is stopped. "rndc stop" will write out the zone file as will "kill -TERM". "rndc halt" doesn't. In either case the journ

Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-24 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St.,

Re: when i check resolver.log just now , i found some error info about AAAA ( ipv6)

2016-04-13 Thread Mark Andrews
e > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this

Re: when i check resolver.log just now , i found some error info about AAAA ( ipv6)

2016-04-12 Thread Mark Andrews
; resolving dlb.g5.letvlb.com/ for client 127.0.0.1#53325: > non-improving referral > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users

Re: BIND started replying to queries for .com with .COM

2016-03-30 Thread Mark Andrews
In message <56fbbe83.6080...@imperial.ac.uk>, Phil Mayers writes: > On 30/03/2016 12:25, Mark Andrews wrote: > > > The recent change was to record and return the learnt case of > > ownernames (to the RRset level) rather than use whatever was used > > to build the r

Re: BIND started replying to queries for .com with .COM

2016-03-30 Thread Mark Andrews
In message <56fbb385.5070...@imperial.ac.uk>, Phil Mayers writes: > On 30/03/16 01:19, Mark Andrews wrote: > > > > Your monitoring probe is broken. > > > > STD 13 says that that the DNS is case preserving. The problem is > > that lots of servers aren&#

Re: BIND started replying to queries for .com with .COM

2016-03-29 Thread Mark Andrews
lease visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW

Re: Configuring different TTLs in multiple RRs for the same domain name, TYPE, and CLASS

2016-03-24 Thread Mark Andrews
; ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Sey

Re: Regarding compiling BIND 9.10.3-p4 on a SystemD Distro

2016-03-23 Thread Mark Andrews
ny. > -- > f.anthony.n.finchhttp://dotat.at/ - I xn--zr8h punycode > Fair Isle, Faeroes: South or southwest 5 or 6, occasionally 7 later. Moderate > or rough, occasionally very rough. Rain or showers. Moderate or good, > occasionally poor. > ___ > Please vi

Re: Can bind be configured to not drop RR's from the cache when the upstream DNS server is unresponsive

2016-03-19 Thread Mark Andrews
YKvzz/4KXf8ABO3VpPFupfEbwHps2rWerObjXdHtYvMuIJ2+ > /cwoBmRJDy6AF1clwGVm8vyf4D/8FUPid8FvDUGiyyaT4u0uyHlQDVkka7tlXgRidGBZR/00DsOA > CAAK+jzXLf7chDH4GS5rWlFvbr9+vXRrVHm4PFfUJPD4hO17pn6yMwRSzHCjkk9q+M2/4LCabrfx > gXwr4c8D3Wvx3msLpGnX6askceoF5hEkyr5RwjEhhk/dIJx0Hyz+0H/wUp+Jn7R+hyeH

Re: Cannot get ./configure to create Makefile for Bind 9.10.3-P4. Please help!

2016-03-19 Thread Mark Andrews
--no-create is for when you want to tinker with the final results built into config.status prior to building the Makefiles. I've committed changes to no run "make clean" if --no-create is set. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE:

Re: Cannot get ./configure to create Makefile for Bind 9.10.3-P4. Please help!

2016-03-19 Thread Mark Andrews
uot;us-ascii" > MIME-Version: 1.0 > Content-Transfer-Encoding: 7bit > Content-Disposition: inline > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users ma

Re: strange response to the DS request

2016-03-04 Thread Mark Andrews
In message , =?UTF-8?B?56We5piO6YGU5ZOJ?= writes: > At Sat, 05 Mar 2016 07:23:46 +1100, > Mark Andrews wrote: > > > There is nothing strange here beyond a missing delegation. > > I'm not opposed to this conclusion itself, but: > > > > If so, I agr

Re: strange response to the DS request

2016-03-04 Thread Mark Andrews
> JINMEI, Tatuya > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users

Re: force re-sign of individual host record?

2016-02-25 Thread Mark Andrews
he zone to be fully re-signed now irrespectived of when the records are due for re-signing. > Mathew Eis > Northern Arizona University > Information Technology Services > > -----Original Message- > From: Mark Andrews > Date: Thursday, February 25, 2016 at 5:14 PM > T

Re: force re-sign of individual host record?

2016-02-25 Thread Mark Andrews
uld be a better way was that the "best" approach? > ( Even better, it seems like named could automagically correct for this > particular problem if we can put it on the wishlist ;-) ) > > Thoughts? > > Thanks in advance, > > Mathew Eis > Northern Arizona Un

Re: Interesting behavior with wildcard domains

2016-02-23 Thread Mark Andrews
In message , Mathew Ian Eis write s: Illegal character '-' in input file. > Hi BIND, > > Ive encountered (quite by accident) an interesting behavior in BIND with > wildcard domains: > > The relevant configuration is a zone; e.g. bar.com, with what Ill call a > second level wildcard host, e.g. *.fo

Re: A Zone Transfer Question

2016-02-22 Thread Mark Andrews
any downside if I > don't have PTR records in my zone files? > > David > > > > > > On Mon, Feb 22, 2016 at 4:04 PM, Mark Andrews wrote: > > > > This is named trying to talk to nameservers over IPv6 and being > > told by the OS that they are

Re: A Zone Transfer Question

2016-02-22 Thread Mark Andrews
;> > >> Any idea why it's denied? > > > > VM1 has the option: > > > > allow-query { > >10.4.1/24; > > 127.0.0.1; > > }; > > > > 10.4.3.101 isn't in 10.4.1/24. The slave has to be allowed to query t

Re: Intermittent NXDOMAIN for a name we are forwarding

2016-02-21 Thread Mark Andrews
n (NXDOMAIN) - Garbage Out (NXDOMAIN). > Alternatively, I can have a local query for this and flush cache if error cod > e is NXDOMAIN, but is hacky.. I would like a config option > > ___ > Please visit https://lists.isc.org/mailman/list

Re: Intermittent NXDOMAIN for a name we are forwarding

2016-02-20 Thread Mark Andrews
__ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- M

Re: Tuning for lots of SERVFAIL responses

2016-02-18 Thread Mark Andrews
t; Another question: Is it just the master and slave zone types that > bypass the recursive-clients limit? They don't bypass. The query gets answered without needing to recurse. > Presumably forward and stub types > still come up against the limit b/c BIND still has to track a back

Re: Tuning for lots of SERVFAIL responses

2016-02-18 Thread Mark Andrews
In message , John Miller writes: > On Thu, Feb 18, 2016 at 5:06 PM, Mark Andrews wrote: > > For some reason people are afraid to slave internal zones. Back > > when I was working for CSIRO I used to slave all the internal zones > > for all of the sites the div

Re: ZSK rollover detail needed.

2016-02-18 Thread Mark Andrews
rndc. > Tom Schulz > Applied Dynamics Intl. > sch...@adi.com > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https:

Re: Tuning for lots of SERVFAIL responses

2016-02-18 Thread Mark Andrews
volume and wide variety of lookup > s they generate. And the typical OS-level caching mechanisms (nscd, etc.) don > 't usually help much, I don't believe, since many of the lookups are for MX r > ecords which, AFAICT, nscd and friends don't cache. > >

Re: Tuning for lots of SERVFAIL responses

2016-02-18 Thread Mark Andrews
es where as humans tend to stop doing external lookups when they know the external links are down. Mark > John > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users maili

Re: pre heat cache

2016-02-18 Thread Mark Andrews
onds > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC

Re: CVE-2015-7547: getaddrinfo() stack-based buffer overflow

2016-02-17 Thread Mark Andrews
e manufacture is not on the list, contact the manufacture and ask them to provide a status update. The list may have a lot of "affected if run on a vulnerable OS" responses. For most of these the solution will be "fix the OS, relink if statically linked, and reboot the machine&

Re: How to check slave zone freshness

2016-02-09 Thread Mark Andrews
In message , Barry Margolin writes: > In article , > Klaus Darilion wrote: > > > On 08.02.2016 20:49, Mark Andrews wrote: > > > With a modern nameserver that supports the expire edns option you can > > > also do "dig +expire soa zone @server" which

Re: How to check slave zone freshness

2016-02-08 Thread Mark Andrews
t didn't need to transfer any changes. > > Thanks for the info > Klaus > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing l

Re: separation of authoritative and recursive functions on internal networks

2016-02-07 Thread Mark Andrews
In message <56b7cdfb.5070...@tnetconsulting.net>, Grant Taylor writes: > I know that this is an older thread, but I've been holding onto it for a > while with the intent of asking a related question. > > On 08/10/2015 12:12 PM, Mark Andrews wrote: > > Authoritative

Re: Using bind and ad blocking

2016-02-05 Thread Mark Andrews
% And a example of a shared master file being processed cleanly. % cat shared.conf zone "a" IN { type master; file "x"; }; zone "b" { type master; file "x&

Re: Intended usage of dnssec-must-be-secure?

2016-02-03 Thread Mark Andrews
> resolving forwarded local zones (non-existing TLD), however, above > example should make the question more obvious. > > Thanks for any input. > > Cheers, > Thomas > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list >

Re: separation of authoritative and recursive functions on internal networks

2016-01-31 Thread Mark Andrews
Services > mathew@nau.edu > (928) 523-2960 > > > > > > > > > -Original Message- > From: on behalf of Mark Andrews > > Date: Monday, August 10, 2015 at 11:12 AM > To: Gary Carr > Cc: "bind-us...@isc.org" > Subject: Re: sepa

Re: Using bind and ad blocking

2016-01-23 Thread Mark Andrews
from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users Presumably you have a zone which which has pri/null.zone as a slave or you have a global/view level dynamic updating of all master zones turned on as just shar

Re: About query response on a view

2015-12-10 Thread Mark Andrews
chor-file: root.anchors.txt" to unbound.conf > (Confirm the authenticity of the root dnskey/KSK from > https://dnssec.co.za and other sources) > > DNSSEC Signing your Zones is easy enough but I've never tried to sign an > Internal and External version of the same Zone. Why c

Re: inline dnssec signing fails

2015-12-08 Thread Mark Andrews
de auto; > listen-on-v6 { ::1; 2001:19f0:6c00:8141:5400:ff:fe05:5309;}; > listen-on { 127.0.0.1; 108.61.190.64;}; > max-cache-ttl 1600; > version none; > auth-nxdomain no;# conform to RFC1035 > al

Re: New installation of BIND on Oracle Linux

2015-12-01 Thread Mark Andrews
kconfig: 345 55 45 > # description: named (BIND) is a Domain Name Server (DNS) \<= > /p> > # that is used to resolve host names to IP addresses. > # probe: true > > # Source function library. > . /etc/rc.d/init.d/functions > > # Source networking configuration. > . /etc/sysconfig/n

Re: Is there other methods or APIs to monitor qps?

2015-11-30 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NS

Re: SUSE 12 bind 9.9.6 Active Directory

2015-11-24 Thread Mark Andrews
em in place. > > Thank you > Best regards > Stefano > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to > unsubscribe from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.is

Re: Resolution differences for getaddrinfo versus host/dig/delv

2015-11-18 Thread Mark Andrews
Mark Andrews writes: > > Mark Andrews writes: > > > > And whomever added underscorechar() to that should be shot. There > > are good reasons to be able to distingish hostnames from other sorts > > of text. Adding '_' doesn't help one d

Re: Resolution differences for getaddrinfo versus host/dig/delv

2015-11-18 Thread Mark Andrews
Mark Andrews writes: > > And whomever added underscorechar() to that should be shot. There > are good reasons to be able to distingish hostnames from other sorts > of text. Adding '_' doesn't help one do that as it is impossible to > distinguish und

Re: Resolution differences for getaddrinfo versus host/dig/delv

2015-11-18 Thread Mark Andrews
return (0); > } > pch = ch, ch = nch; > } > return (1); > } > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to >

Re: Resolution differences for getaddrinfo versus host/dig/delv

2015-11-18 Thread Mark Andrews
the data returned. > If you're of a sensitive disposition I'd avoid digging (pardon the pun) > into the minutiae of the zone surrounding those records e.g. enclosing > SOA - they're very seriously odd. > > Cheers, > Phil > __________

Re: Query on ignoring additional section returned in replies

2015-11-18 Thread Mark Andrews
my need to fix their nameservers. The NS records need to be made consistent. There needs to be address records for the nameservers. Mark > -Original Message- > From: Mark Andrews [mailto:ma...@isc.org] > Sent: Wednesday, November 18, 2015 6:26 PM > To: Elias Ahmed Kamal > Cc

Re: Query on ignoring additional section returned in replies

2015-11-18 Thread Mark Andrews
ORITY: 1, ADDITIONAL: 0 > ;; WARNING: recursion requested but not available > > ;; QUESTION SECTION: > ;ns1.wip.fis.com.my.IN A > > ;; AUTHORITY SECTION: > wip.fis.com.my. 3600IN SOA ns1.wip.fis.com.my. webmaster > . 2015111825 16384 2048 104

Re: root hints operation

2015-11-17 Thread Mark Andrews
In message <564be747.40...@tnetconsulting.net>, Grant Taylor writes: > On 11/17/2015 03:22 PM, Mark Andrews wrote: > > Given the root zone is signed and most of the TLD's are also signed > > there is little a rogue operator can do besides causing a DoS if > > y

Re: root hints operation

2015-11-17 Thread Mark Andrews
In message <564ba6e9.2050...@hireahit.com>, Dave Warren writes: > On 2015-11-17 14:13, Mark Andrews wrote: > > In message <564ba3e3.9060...@hireahit.com>, Dave Warren writes: > >> On 2015-11-16 18:09, Grant Taylor wrote: > >>> It's my understan

Re: root hints operation

2015-11-17 Thread Mark Andrews
nd-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.o

Re: auth-nxdomain yes

2015-11-15 Thread Mark Andrews
mine the query stream and the answer stream because named both consolidates multiple queries and caches negative answers. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _

Re: auth-nxdomain yes

2015-11-15 Thread Mark Andrews
r. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users

Re: How to make bind/named to listen for requests on both IPV4 and IPV6

2015-11-09 Thread Mark Andrews
Did you remember to restart named? B.T.W. that is a very old version of named. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https

Re: Adding DNS ALG support to Bind?

2015-11-06 Thread Mark Andrews
local. For the public side you can filter out the ULA and RFC 1918 addresses. > > [1] http://fmepnet.org/osx_dyndns.html > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from th

Re: Adding DNS ALG support to Bind?

2015-11-05 Thread Mark Andrews
In message <563c3477.6070...@tnetconsulting.net>, Grant Taylor writes: > On 11/05/2015 03:44 PM, Mark Andrews wrote: > > You may want to add a "_dns-update._udp.example.net SRV" record > > pointing to the nameservers as someone convinced the router vendor(s) > &

Re: BIND-9.10.2-P4: Cannot use in-view to refer to RPZ zone definitions: "'$RPZ_ZONE' is not a master or slave zone"

2015-11-05 Thread Mark Andrews
In message <563c015c.1020...@gmail.com>, Kenneth Lakin writes: > > On 11/05/2015 04:32 PM, Mark Andrews wrote: > > RPZ zones are hooked deeper into the view than just a single > > attachment point. There is lots of auxillary data that needs to > > be built and mai

Re: BIND-9.10.2-P4: Cannot use in-view to refer to RPZ zone definitions: "'$RPZ_ZONE' is not a master or slave zone"

2015-11-05 Thread Mark Andrews
n v1 and v2, > but remove the response-policy block from v1 and v2 and move it into > zone-defs, named-checkconf and BIND both accept the config file, but > -naturally- RPZ does not work for the v1 and v2 views. > > Unrelated to all that, remember how we can have RPZ master zones in

Re: Adding DNS ALG support to Bind?

2015-11-05 Thread Mark Andrews
't want to buy a router you can use a Linux or BSD box and configure the DHCP client to update the nameserver on renumbering. I did that for many years with FreeBSD with two ethernet card, running named and ISC's dhcp client using the dhcp client hooks. Mark > On Wednesday 04 Novemb

Re: Adding DNS ALG support to Bind?

2015-11-04 Thread Mark Andrews
his functionality. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-use

Re: Question about name resolution.

2015-10-26 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61

Re: Adding DNS ALG support to Bind?

2015-10-24 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117,

Re: Why two lookups for a CNAME?

2015-10-21 Thread Mark Andrews
ding: 7bit > Content-Disposition: inline > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@list

Re: bind-users Digest, Vol 2230, Issue 1

2015-10-20 Thread Mark Andrews
ind of messages are required by the client to be sent towards > server to determine if the DNS IP is reachable or not? Ask your application vendor. They dreamt up this scheme. No one here can help you beyond they will be DNS messages. > Thanks > Harshith -- Mark Andrews, ISC 1 Seymou

Re: How does a Client Verify if the DNS server is Alive or down

2015-10-19 Thread Mark Andrews
S IP is reachable or not? > > what is your problem? My bet this a question from some course that Harshith has been requested to answer. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org

Re: Best practices for coding new RR Types

2015-10-16 Thread Mark Andrews
ely notify the > sender by reply e-mail and destroy all copies of the communication and > any attachments. > -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___

Re: SRV Request to DNS

2015-10-14 Thread Mark Andrews
limpse, it's peripheral; mere fragments > of mad-doctor chrome, confining themselves to the corner of the eye. All protocols that use SRV do. It's the operators that decide the port to put in the SRV record, not the protocol. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Vall

<    3   4   5   6   7   8   9   10   11   12   >