Re: Maximum DNS packet size?

2014-09-29 Thread Mark Andrews
is list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___

Re: Putting weird characters into zone files ?

2014-09-27 Thread Mark Andrews
ere is no way to escape a wildcard in the DNS. As for the exclamation point just enter it. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users

Re: BIND NXDOMAIN {REP=5.1}

2014-09-25 Thread Mark Andrews
doesn't work as that is not how DNS wildcards work. Mark > -Original Message- > From: Mark Andrews [mailto:ma...@isc.org] > Sent: Tuesday, 23 September 2014 9:49 AM > To: Neil > Cc: bind-us...@isc.org > Subject: Re: BIND NXDOMAIN {REP=5.1} > > > You jus

Re: BIND NXDOMAIN

2014-09-23 Thread Mark Andrews
ooverride.com.au > > *.nxreturn.com.au > > > > Is this possible? If not a modification to query.c is the only option. > > Has anyone got a src patch for this feature? > > > > Thanks > > Neil > > > > > > -- Mark Andrews, ISC 1 Seymour St.

Re: Parsing dig output consistently

2014-09-17 Thread Mark Andrews
lines showing me the RCODE and the question, which I can match up > and determine whether a server is returning NOERROR, REFUSED or SERVFAIL > for a given zone. Is this possible? > > Regards, > > Anand > ___ > Please visit https://list

Re: Change in behaviour regarding ndots and searchlist

2014-09-15 Thread Mark Andrews
x93A0B9CE (F4F6 B1A3 866B 26E9 450A 9D82 58A2 D94A 93A0 B9CE) > 'Are you Death?' ... IT'S THE SCYTHE, ISN'T IT? PEOPLE ALWAYS NOTICE THE SCYT > HE. > -- Terry Pratchett, The Fifth Elephant > ___ > Please visit https:/

Re: nsupdate, semicolon, backslash

2014-09-13 Thread Mark Andrews
gt; So, I have to do more troubleshooting about this case. > > Thanks for your help > Zeppi -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visi

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Mark Andrews
> -.SUFFIXES: .py > -.py: > - cp -f $< $@ > - chmod +x $@ > - > > -- > Evan Hunt -- e...@isc.org > Internet Systems Consortium, Inc. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-user

Re: nsupdate, semicolon, backslash

2014-09-12 Thread Mark Andrews
ng of comment introducer. A backslash says the next character is a literal except when that character is a digit in which case it the start of \DDD which is the decimal value or the character. THe RHS below is without the master file escaping "\h\e\l\l\o\;\*" -> hello;*

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Mark Andrews
hieu Arnold > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrew

Re: Promoting slave to master DNS server with dynamic updates

2014-09-11 Thread Mark Andrews
** > This e-mail, attachments included, is intended solely for the addressees= > and should be considered as confidential.Should you receive this messa= > ge by error, please notify the sender immediately and destroy this e-mail a= > nd

Re: A record of domain name must be name server ?

2014-09-11 Thread Mark Andrews
e admins will remember to do > it; many won't). No, it's more like formalising existing practice. Universal adoption would be a long time off but there is a large existing base of MTA's that will do the right thing. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, N

Re: Two domains reporting errors

2014-09-09 Thread Mark Andrews
fix named.conf because that is where the error is. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/listinf

Re: Two domains reporting errors

2014-09-09 Thread Mark Andrews
.tld:16: ignoring out-of-zone data (www.bt.tld) > zone dw.tld/IN: has 0 SOA records > zone dw.tld/IN: has no NS records You are trying load the bt.tld zone into dw.tld. Fix named.conf. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: .prod issues

2014-09-05 Thread Mark Andrews
t away with it until the introduction of prod. Your machine names are host.prod.mydomain.com not host.prod. Stick to unqualified + search list and fully qualified. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: dnssec automatic signing

2014-08-28 Thread Mark Andrews
gering record. > Sincerely, > > Mr.Jittinan Suwanrueangsri -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/lis

Re: dnssec automatic signing

2014-08-28 Thread Mark Andrews
The next node to be signed is based on RRSIG expire times. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/listinfo

Re: recursive lookups for UNSECURE names fail if dlv.isc.org is unreachable and dnssec-lookaside is 'auto'

2014-08-26 Thread Mark Andrews
In message <53fc827e.7090...@redhat.com>, Tomas Hozza writes: > > On 08/26/2014 02:27 PM, Mark Andrews wrote: > > Why would you expect them to succeed? > > Because validation using root servers and authoritative servers proved > that the domain is intentionally uns

Re: recursive lookups for UNSECURE names fail if dlv.isc.org is unreachable and dnssec-lookaside is 'auto'

2014-08-26 Thread Mark Andrews
o2JbNejoFd1gj0WTNphlL2tSoE > QECltLCbCHSZj8vo7dOoN9kusRKSuKi9rP0Lp/DXCDvhqJ+Woq8y5cgvkLRT5snA > lgR3hfc44Rc9Tp4K6NoLX7pBVt1nWRWp4hFyJUuZ5B0qXWMCNyBioeNSe2yIFowE > uV33TazpImavG4qXUjwV1f4EXSgjuSzEUUn2sAm9LdD6knMAOYPpCXw203mtSCan > +JoXUcwxN+gZHEQaMSBoTsw7DxZS8NVtfdMxrvpL+Ro+LTzs3CJZioc

Re: rndc zonestatus meaning

2014-08-07 Thread Mark Andrews
e timestamps in the RRSIGs. In the example above the NSEC record for ns.example.com is the next RRset that needs to be re-signed. > 6. Where can I get more information about DNSSec of Bind 9.10-P2 > beside BIND 9 Administrator Reference Manual because personally, I think > it does

Re: bind 9.10-P2 dnssec keys management

2014-08-07 Thread Mark Andrews
gned with new key. No. Once a key is activated it will be used to sign rrsets as they fall due for re-signing. Named does NOT walk the zone and re-sign every rrset. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: m

Re: ISP caching server setup

2014-08-06 Thread Mark Andrews
WER: 1, AUTHORITY: 0, ADDITIONAL: 0 > > ;; QUESTION SECTION: > ;losscontrol360.com. IN A > > ;; ANSWER SECTION: > losscontrol360.com. 586 IN A 74.208.98.80 > > ;; Query time: 174 msec > ;; SERVER: 8.8.8.8#53(8.8.8.8) > ;; WHEN: Wed Aug 6 16:01:

Re: Metazones or Something Else?

2014-08-05 Thread Mark Andrews
nt. Anything you say will be misquoted, > then used against you. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https:

Re: BIND and listening on interfaces

2014-08-01 Thread Mark Andrews
6_pktinfo then we bind to every interface. If named is only listening on a subset of interface we bind to each interface so that the one can run multiple instances and also so that the correct ICMP messages are emitted. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Au

Re: Reload BIND to listen on additional interface?

2014-07-31 Thread Mark Andrews
9.10 also has "rndc scan" for platforms without a routing socket or if you want to do it manually. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma.

Re: Reload BIND to listen on additional interface?

2014-07-31 Thread Mark Andrews
and does that? Does a rndc > reconfig tell BIND to newly bind to the interfaces? > > Thanks in advance. > > Regards, > Johannes Use BIND 9.10. It uses the routing socket to detect interface coming and going and will automatically rescan the list of interfaces and rebuild th

Re: Bind 9.9.5 high CPU and when will Bind9.8 EOL?

2014-07-26 Thread Mark Andrews
) to get the fix. As time goes on it becomes "please reproduce with a current release" Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please v

Re: named memory usage

2014-07-25 Thread Mark Andrews
ist > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___

Re: Bind and ZSK-Rollovers: Changing salt automatically?

2014-07-24 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 98

Re: newsrss.bbc.net.uk slightly broken?

2014-07-18 Thread Mark Andrews
YEARECAAYFAlPJg6wACgkQL6j7milTFsEROgCdHomLrHWP8tdMD6uIBR4Q0iJi > IlEAoIKUYHGxBhGPxe97tGzJdpPKlZ/T > =7y62 > -END PGP SIGNATURE- > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > fro

Re: unable to obtain neither an IPv4 nor an IPv6 dispatch

2014-07-16 Thread Mark Andrews
-horizon configuration. I would appre= > ciate any help. > > > --089e013a044a72db8004fe551784-- > > --===1218088129802327245== > Content-Type: text/plain; charset="us-ascii" > MIME-Version: 1.0 > Content-Transfer-Encoding: 7bit > Content-Disposition: inlin

Re: Does bind read /etc/hosts?

2014-07-15 Thread Mark Andrews
Ok, I stand corrected. That said both named and dnsmasq as well as other products can override data from outside. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org

Re: Does bind read /etc/hosts?

2014-07-15 Thread Mark Andrews
n the other hand has no bind-like > zonefiles Neither dnsmasq nor named read /etc/hosts. Both can be used to override data from outside. They just have different configuration methods. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: Does bind read /etc/hosts?

2014-07-15 Thread Mark Andrews
, it does not even seem to access /etc/hosts. But someone > tells > > > me Bind can access /etc/hosts first. Can you pls tell me how to > config > > > Bind to access /etc/hosts fist? > > > > > > Thanks, > > > Guanghua > > > > No.

Re: Can someone please translate entries from query.log file?

2014-07-15 Thread Mark Andrews
ul-2014 16:24:34.100 queries: XX / > 206.117.120.84/129.118.117.206.in-addr.arpa/PTR/IN > > I'm running BIND 8.2.4 on Solaris 8 > > root@bmw:/export/home/dns # in.named -v > in.named BIND 8.2.4 Tue Jul 13 06:04:59 PDT 2004 > Generic Patch-5.8-July 2004 >

Re: problem registering DS records with EDUCAUSE, sanity check please

2014-07-15 Thread Mark Andrews
e child a validating > client might consider the zone bogus and refuse to resolve it. There has to a working combination of DS/DNSKEY/RRSIG for each DNSSEC algorithm listed in the DS RRset. DS records without a matching DNSKEY or matching RRSIG cause validators to do more work. -- Mark Andr

Re: BIND 9.10.0-P2 prefetch problem

2014-07-15 Thread Mark Andrews
OA flbflb-= > gtm-qydc.intuit.com. hostmaster.flb.intuit.com. 2014022110 10800 3600 60480= > 0 86400  MsoNormal>Flushing the cache fixes the problem. Disabling prefetch prevents= > the problem from happening.  = > ; <= > b>Tedd >= >

Re: Does bind read /etc/hosts?

2014-07-15 Thread Mark Andrews
ind to access /etc/hosts fist? > > Thanks, > Guanghua No. getaddrinfo, gethostbyname etc. however may access /etc/hosts, NIS, mDNS, DNS and other databases. You need to read the documentation that comes with your system for how to control these. Mark -- Mark Andrews, ISC 1 Seymour S

Re: problem registering DS records with EDUCAUSE, sanity check please

2014-07-14 Thread Mark Andrews
In message <20140715004923.gg31...@bender.unx.csupomona.edu>, "Paul B. Henson" writes: > On Tue, Jul 15, 2014 at 10:19:10AM +1000, Mark Andrews wrote: > > > The new key does not sign the DNSKEY RRset. > [...] > > Make sure the DNSKEY RRset is signed with t

Re: problem registering DS records with EDUCAUSE, sanity check please

2014-07-14 Thread Mark Andrews
me records are generated by dnssec-dsfromkey. Yet, when I try to > register these DS records with EDUCAUSE, their system claims they cannot > find a matching key in our published zone. > > Does anybody see anything out of place? Fortunately, the key is not > scheduled to be used until 2015, so there's plenty of time

Re: slave zone files unreadable

2014-07-11 Thread Mark Andrews
ontent. If we could get people away from wanting to use a editor on master files directly we would. The practice is highly error prone even for experts. > -- > Barry Margolin > Arlington, MA > ___ > Please visit https://lists.isc.org/m

Re: Caching Nameserver and BIND RPM Compatibility

2014-07-11 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NS

Re: own IPv6 zones but no IPv6 uplink

2014-07-11 Thread Mark Andrews
27;ve been using HE for the last 12 years. Just about every application he is running is trying IPv6 then after getting network unreachable going on to try IPv4. For the record it isn't the zone. It's enabling IPv6 locally without having a working upstream link. You would get that messag

Re: DLV dnssec setup

2014-07-11 Thread Mark Andrews
In message , Wolfgang Rosenauer writes: > On Fri, Jul 11, 2014 at 1:32 AM, Mark Andrews wrote: > > > > Then all of the following should succeed. Please let the > > list know how you go. > > > > dig soa . @198.41.0.4 +norec > >

Re: DLV dnssec setup

2014-07-10 Thread Mark Andrews
cp +norec dig com @198.41.0.4 +dnssec +tcp +norec dig dnskey org +dnssec @199.19.56.1 +ignore +norec dig dnskey org +dnssec @199.19.56.1 +tcp +norec -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INT

Re: DLV dnssec setup

2014-07-10 Thread Mark Andrews
info/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma..

Re: eia.gov chokes on edns options

2014-07-09 Thread Mark Andrews
sH/bgCfbDb2WinhfC6mY4epKr5rlro/ > l3wAnREhW3tJptOhBDB+02V/BoiseAdv > =oJ7i > -END PGP SIGNATURE- > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-us

Re: problem resolving ardownload.adobe.com

2014-07-07 Thread Mark Andrews
ags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 > ;; WARNING: recursion requested but not available > > ;; QUESTION SECTION: > ;ardownload.wip4.adobe.com.INA > > ;; ANSWER SECTION: > ardownload.wip4.adobe.com. 300INCNAME > ardownload.adobe.com

Re: Doub about bind9 configuration

2014-07-06 Thread Mark Andrews
ists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871

Re: problem resolving ardownload.adobe.com --enable-sit harmful?

2014-07-03 Thread Mark Andrews
//lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: problem with NS record resolution

2014-07-02 Thread Mark Andrews
empty */ }; }; Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-use

Re: daemon warning

2014-07-01 Thread Mark Andrews
y reason for starting as root. Read your OS's documentation. For FreeBSD i have the following in /etc/sysctl.conf security.mac.portacl.port_high=1023 net.inet.ip.portrange.reservedlow=0 net.inet.ip.portrange.reservedhigh=0 security.mac.portacl.suser_exempt=1 security.mac.portacl.rules=uid:53:tcp:53,uid:53:

Re: Using a DynDNS hostname in master-statement for a bind slave?

2014-06-27 Thread Mark Andrews
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia P

Re: Default query type of dig

2014-06-25 Thread Mark Andrews
Can this easily be done (I did not find a > switch for .digrc nor another option) or is there a source code change > needed? > > Thanks > Teddy -t Note this will also affect -x -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2

Re: Bad owner name on hidden primary

2014-06-10 Thread Mark Andrews
In message , Raymond Drew Walker writes: > On 6/9/14, 9:05 PM, "Mark Andrews" wrote: Input error > > > > > >In message , Raymond Drew Walker > >writes: > >> > >> Apologies, > >> > >> Our workaround was act

Re: tsig-key

2014-06-10 Thread Mark Andrews
>>HEADER<<- opcode: QUERY, status: NOTAUTH, id: 15607 ;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 2 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;dv.isc.org.IN AXFR ;; TSIG PSEUDOSECTION: transfer. 0 ANY

Re: Bad owner name on hidden primary

2014-06-09 Thread Mark Andrews
ad owner name (check-names)" In the past > (pre hidden primary) they did not fail. > > In the past we have not used the `check-names' option, so behavior should > be default... > odd since the default behavior is to fail for master zones. > > Could this hav

Re: SPF RR type

2014-06-05 Thread Mark Andrews
ransition from TXT to SPF. i.e. publish a RFC and hope people follow it. It takes years to do transitions like this. TXT to SPF was actually ramping up but that is now water under the bridge. > * - Mark doubtless feels differently. > -- Mark Andrews

Re: stub zones

2014-06-02 Thread Mark Andrews
d between zones stubs provided a method to keep the delegation data up to date. This is no longer supported as it can lead to stale data in slaves which isn't in any master due to timing issues. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 211

Re: RPZ and www.rackspace.com

2014-05-30 Thread Mark Andrews
in several different DNS zones. > > > > > > www.domain.com NSns1.domain1.com > > > NSns2.domain2.com > > > NS ns3.domain3.net . > > > > > > These are the most frustrating as there is really nothing &

Re: Reply Code 0x8083 vs 0x8080

2014-05-30 Thread Mark Andrews
In message <1401433477.99469.yahoomail...@web121601.mail.ne1.yahoo.com>, Jiann- Ming Su writes: > > > > > On Friday, May 30, 2014 12:34 AM, Mark Andrews wrote: > > > > > In message > <1401424053.51486.yahoomail...@web121604.mail.ne1

Re: Reply Code 0x8083 vs 0x8080

2014-05-29 Thread Mark Andrews
made a "." query. Named returns the query it was asked. It it pointless to return anything else as the client is supposed to check and discared answers that don't match. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Au

Re: Reply Code 0x8083 vs 0x8080

2014-05-29 Thread Mark Andrews
users > > > > > > > > > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.o

Re: KSK signing all records; NSEC3 algorithm status?

2014-05-28 Thread Mark Andrews
In message <20140528151909.ga66...@redoubt.spodhuis.org>, Phil Pennock writes: > On 2014-05-28 at 13:02 +1000, Mark Andrews wrote: > > In message <20140528012734.ga55...@redoubt.spodhuis.org>, Phil Pennock > > writes: > > > The registrar for my zone "

Re: Bad performance from BIND 9.10 on RHEL 6.5

2014-05-28 Thread Mark Andrews
users > > > > ___ > > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscri > be from this list > > > > bind-users mailing list > > bind-users@lists.isc.org > > https://lists.isc.

Re: Architecture Questions

2014-05-28 Thread Mark Andrews
Thanks, > > Josh > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-

Re: KSK signing all records; NSEC3 algorithm status?

2014-05-27 Thread Mark Andrews
--- > > iQEcBAEBCAAGBQJThTt4AAoJEKBsj+IM0duFFq4IAJ+dn1+0Vkm7XnN+r70QDWmD > fgEN0G9D72TRJ0lYqkd19W/qwctfKDkCUaTt3BIjRwBDV3bQXxqLQkXxH7jWFNXK > czZEEm6mOKCQWcBEKAMtfWM5cGKGAjSjfvbA2ZOAvuUIkDfYN0s4kcWYFTre7Zyk > SSnZi909xs1ZPiuz447dmUBr3gg5wNJAuUNiNJJP9DHriu6542DdRzUtbu3zmABG > rBAjS/bud

Re: TSIG afxr failed while receiving responses: REFUSED

2014-05-26 Thread Mark Andrews
In message <5382eb30.6040...@ripe.net>, Anand Buddhdev writes: > On 26/05/2014 01:53, Mark Andrews wrote: > > Hi Mark, > > > Actually that isn't the mistake as they are both run through > > dns_name_fromtext which will normalise them before comparison. >

Re: TSIG afxr failed while receiving responses: REFUSED

2014-05-25 Thread Mark Andrews
key"; }; > > }; > _______ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark

Re: TSIG afxr failed while receiving responses: REFUSED

2014-05-25 Thread Mark Andrews
esponses: REFUSED > 21-May-2014 09:34:12.068 transfer of 'example.net/IN' from ip.address.of.mast > er#53: Transfer completed: 0 messages, 0 records, 0 bytes, 0.080 secs (0 byte > s/sec) > > and I see on the master: > > 21-May-2014 16:34:12.031 client ip.address.of.slave#4

Re: bind 9.10..0-P1 rndc: 'retransfer' failed: not found; other rndc commands are ok

2014-05-22 Thread Mark Andrews
finding the zone? Presumably it is not a slave or a stub. retransfer is only applicable to slave and stub zones. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-u

Re: bind 9.10..0-P1 rndc: 'retransfer' failed: not found; other rndc commands are ok

2014-05-22 Thread Mark Andrews
; parse message > rndc: 'retransfer' failed: not found > > I've looked around online, and 'retransfer' seems to still be a valid > command. > > What's wrong with my usage of retransfer? >

Re: Handling of expired RRSIG records - ise.gov

2014-05-21 Thread Mark Andrews
se.gov and th > e date on the SOA RRSIG record is indeed in the future. > > How is BIND deciding it is okay to return the A and MX records, and that this > is not some sort of DNS replay attack? > > > > > > ___ > Please visit

Re: About the prefetch function within bind 9.10.

2014-05-18 Thread Mark Andrews
If there is a query in that 9 second window then named will make a query to repopulate the cache. If there is not a query then the records will expire. You only want to prefetch records that are being queried for regularly. On 18/05/2014, at 17:18, Hongyi Zhao wrote: > What do you mean by s

Re: isc domain lookup

2014-05-14 Thread Mark Andrews
;Thanks for your help > ns-serif;font-size:12px;line-height:18px"> =3D"font-family:'Helvetica Neue',Arial,Helvetica,sans-serif;font-si= > ze:12px;line-height:18px">Y.E. > ns-serif;font-size:12px;line-height:18px">=C2=A0 > > --001

Re: Slave zone intermittently not refreshing

2014-05-12 Thread Mark Andrews
ribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___

Re: bin 9.10 verbose logging

2014-05-09 Thread Mark Andrews
> > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/list

Re: Bind 9.10 64 bit

2014-05-09 Thread Mark Andrews
sion preserving data. Install the 64 bit version. 9.10.0 changes the default install location so you may want to move your data across. x86: CSIDL_PROGRAM_FILESX86 x64: CSIDL_PROGRAM_FILES -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PH

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-08 Thread Mark Andrews
In message <536c0392.3020...@hireahit.com>, Dave Warren writes: > On 2014-05-08 15:09, Mark Andrews wrote: > > In message <536bcced.8060...@hireahit.com>, Dave Warren writes: > >> On 2014-05-08 07:45, Barry Margolin wrote: > >>> In article , > >&

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-08 Thread Mark Andrews
is impossible, but I would > hazard a guess that since DNAMEs already return a matching CNAME and > nothing explodes, the problems would be minor and limited in scope. > > -- > Dave Warren > http://www.hireahit.com/ > http://ca.linkedin.com/in/davejwarren > > >

Re: No-Sync-at-Slave

2014-05-08 Thread Mark Andrews
out > > May 7 21:43:31 ns2 named[1381]: [ID 873579 daemon.error] transfer of > 'domain.com/IN' from 212.93.192.4#53: failed to connect: timed out > > > > > > Any one's help would be highly appreciated thanks in advance. > > > &

Re: Point domain name of my zone to name in somebody else's zone?

2014-05-07 Thread Mark Andrews
gt; = > > > bind-users@lists.isc.org <mailto:bind-users@lists.isc.org> > > = > > > https://lists.isc.org/mailman/listinfo/bind-users > > = > > > = > > > = > > > = > > > = > > > __

Re: RPZ and www.rackspace.com

2014-05-07 Thread Mark Andrews
erif">www.rackspace.com ize=2 face="sans-serif">. >             IN     >  A > > > ;; ANSWER SECTION: > face="sans-serif">www.rackspace.com t size=2 face="sans-serif">. >      298     IN      CNAME   > face="sans-serif

Re: BIND 9.10.0 is now available

2014-05-06 Thread Mark Andrews
.isc.org/isc/bind9/9.10.0 ftp://ftp.isc.org/isc/bind9/9.10.0 Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https://lists.isc.org/mailman/li

Re: bind 9.10.0 xfer test failing

2014-05-06 Thread Mark Andrews
recently. If you roll back Net::DNS to version 0.72 the test should succeed. "ans" needs to be rewritten in parts to work with the with the new Net::DNS. > - J=F8rgen Thomsen > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscri= > be from

Re: BIND 9.10 compilation problem for FreeBSD 6.x/7.x

2014-05-06 Thread Mark Andrews
yne, Northwest Dogger: Southerly or > southwesterly 4 or 5. Slight or moderate. Showers. Good, occasionally > moderate. > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org

Re: GSS-TSIG updates from Windows clients

2014-05-02 Thread Mark Andrews
See tkey-gssapi-credential ; tkey-gssapi-keytab ; grant ms-subdomain ; -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please

Re: How to disable DNSSEC/EDNS for lwresd

2014-04-29 Thread Mark Andrews
gt; Regards, > -- > Tomas Hozza > Software Engineer - EMEA ENG Developer Experience > > PGP: 1D9F3C2D > Red Hat Inc. http://cz.redhat.com > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-u

Re: Cross compile bind failing, vis3 ???

2014-04-29 Thread Mark Andrews
s3 -mt -m64" ./configure --with-openssl=/usr/local/ssl --enab > le-full-report --without-gost --exec-prefix=/usr > --libexecdir=/usr/lib/libexec --includedir=/usr/include > > Even after I edit the configure script to have cross_compile=yes, it still > responds with no during the config

Re: Promoting a slave to master gives syntax error

2014-04-28 Thread Mark Andrews
e' > '--with-libtool' '--enable-shared' '--enable-static' > '--with-openssl=/usr' '--with-gssapi=/usr' '--with-gnu-ld' > '--with-geoip=/usr' '--with-atf=no' '--enable-ipv6' '--enable-rrl'

Re: Cross compile bind failing, vis3 ???

2014-04-28 Thread Mark Andrews
(cd $i; make DESTDIR="/blah/blah/bind-9.9.5-S1/lib" all ) || exi > t 1; \ > fi; \ > done > make: Fatal error: Command failed for target 'subdirs' > " > > Does bind not support Vis 3 architecture? > -- Mark Andrews, ISC 1 Seymour St., Dunda

Re: All, do bind9.9.5 support edns0-client-subnet?

2014-04-23 Thread Mark Andrews
server and recursive server. No. edns0-client-subnet will require a significant re-write of the resolver and cache to support. This is currently unfunded work. > thanks. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: Example of classless reverse-lookup zone

2014-04-07 Thread Mark Andrews
out the rdata content if the owner name ends in "in-addr.arpa" or "ip6.arpa". Mark > On Mon, Apr 7, 2014 at 7:08 PM, Mark Andrews wrote: > > > > > You should read all the error messages. > > > > dns_rdata_fromtext: junk:3: near 'i...@exa

Re: Example of classless reverse-lookup zone

2014-04-07 Thread Mark Andrews
e escaped. Also how do you expect anyone to solve the rest of your problems when you don't give a example and you don't give the real names involved. We are not mind readers. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

Re: socket error on ipv6 link local

2014-04-01 Thread Mark Andrews
uilt with > > '--enable-rrl' > > > > > > > > > > > > Thanks, Paul > > > > > > > > > > > > > > ___ > > Please visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: High recursive client counts

2014-03-27 Thread Mark Andrews
domains when > Internet connection is down. Slave the local zones is the simplest solution. > -- > Who: Lawrence K. Chen, P.Eng. - W0LKC - Sr. Unix Systems Administrator > For: Enterprise Server Technologies (EST) -- & SafeZone Ally > _______ > Please visit https://lists.isc.org/

Re: Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Mark Andrews
Rylink > System Administrator > > Dial Telecom a. s. > Kikova 36a/237 > 186 00 Praha 3, esk Republika > Tel.:+420.226204627 > daniel.rysl...@dialtelecom.cz > --- > www.dialtelecom.cz > Dial Telecom, a.s. > Jednodue se pipojte > ------

Re: DNS64 and DNSSEC - AD bit not set (RFC 6147)

2014-03-26 Thread Mark Andrews
In message , Tom Lanyon wri tes: > On 27 Mar 2014, at 14:48, Mark Andrews wrote: > > No. If the answer is secure and DO=1 then it won't synthesis. > > > > RFC 6147 just gets DO and CD semantics completely wrong. The WG > > wanted there to be signaling that

Re: DNS64 and DNSSEC - AD bit not set (RFC 6147)

2014-03-26 Thread Mark Andrews
gt; Thanks, > Tom > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org >

Re: High recursive client counts

2014-03-26 Thread Mark Andrews
if there are too many. It also drops duplicates where the source port and address are duplicated. Named still has to reply to all the clients which is why they are on the recursing list. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742

<    5   6   7   8   9   10   11   12   13   14   >