Re: location for master file dump

2018-05-27 Thread /dev/rob0
under /etc. > However, PowerDNS seems a good server I am willing to explore the > option. Indeed, and I know some PDNS developers; they're good folks and highly competent. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___

Re: Queries regarding Master/Slave

2018-05-05 Thread /dev/rob0
rsion, because it hyperlinks to relevant syntax documentation in chapter 6. And again, see the KB. TSIG can be used for any form of query, including the notify sent from master to slave[s]. See the section in ARM chapter 6, on "server Statement Grammar". -- http://rob0.nodns4.us/ Offl

Re: Fwd: Re: BIND Server running but not responding

2018-04-18 Thread /dev/rob0
1 cannot be routed to on the Internet, so this is not really an urgent matter. > but what is a quick way for me to change/recreate the key/secret? See the rndc-confgen manual. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0

Re: Queries to DNS Blackholes don't respond

2018-04-18 Thread /dev/rob0
aware of the feature, so they distribute named.conf with kludges. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this

Re: BIND Server running but not responding

2018-04-18 Thread /dev/rob0
this, so you need Windows help. I'm unable to provide that. Good luck. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

expired SSL certificate

2018-04-10 Thread /dev/rob0
The certificate for lists.isc.org expired today, and because of STS my browser does not allow a security exception. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lis

Re: Different forwarder for certain response ip (result ip )

2017-09-16 Thread /dev/rob0
t's very easy to run your own caching resolver. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from thi

Re: Different forwarder for certain response ip (result ip )

2017-09-16 Thread /dev/rob0
dns, why not just use those forwarders for all queries? What benefit could there be in querying the ISP nameservers first? -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit h

Re: How to pause master zone updates to slave for couple of minutes

2017-09-07 Thread /dev/rob0
n "rndc reconfig". When testing is completed, remove that and "rndc reload". -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/b

Re: email notification in bind?

2017-08-30 Thread /dev/rob0
(1)? Or are you talking about a slave receiving a notify and pulling a zone transfer? "Zone update fails" is an ambiguous phrase. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please

Re: filter-aaaa-on-v4 not available in Windows binary?

2017-08-30 Thread /dev/rob0
n article on compiling BIND for Windows. But again, I doubt that could be the problem. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-u

Re: How do I reset a DNSSEC zone ?

2017-08-20 Thread /dev/rob0
u would need to share it with us: "named-checkconf -px" (leave off "x" if you're using RHEL who like to stay back from useful "new" features added to software they distribute.) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0"

[ot] Re: botched KSK rollover

2017-08-18 Thread /dev/rob0
s nice mailing list. :) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

botched KSK rollover

2017-08-17 Thread /dev/rob0
rding to both DNSViz and Verisign's dnssec-debugger this has put me back in business for the time being. For some reason I am not successful in wrestling with Godaddy over the new DS, but that's not a matter for this list. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only i

Re: need to look up short names

2017-08-10 Thread /dev/rob0
r search configuration in /etc/resolv.conf > > man resolv.conf Note that this still work for dig(1) and host(1) as per the OP's examples. But things like ping(1) and browsers will work with a search domain. -- http://rob0.nodns4.us/ Offlist GMX mail is s

Re: bind-chroot, runs, works, dies

2017-08-09 Thread /dev/rob0
nger listening on 127.0.0.1#53 Aug > 8 16:00:19 FedoraServer named[10120]: no longer listening on > 50.124.80.106#53 Aug 8 16:00:19 FedoraServer named[10120]: exiting And named obediently did a clean shutdown. Your issue might more effectively be dealt with in a Fedo

Re: DNSSEC DS Record

2017-07-14 Thread /dev/rob0
thing will use it. > Does zbc.com (for example) need DS, or is just passed by the TLD? Zbc.com. is not a zone, it is a CNAME in the com. TLD. There would be no NS to delegate to, therefore no DS. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/r

Re: wildcard not working after record deleted

2017-06-20 Thread /dev/rob0
On Tue, Jun 20, 2017 at 09:29:59AM -0500, /dev/rob0 wrote: > On Tue, Jun 20, 2017 at 09:17:58AM -0400, Maria Iano wrote: > > Thanks for your answer. There are no other records with that name > > in the zone, and an ANY query comes back empty but still with > > status of NOER

Re: wildcard not working after record deleted

2017-06-20 Thread /dev/rob0
.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: wildcard not working after record deleted

2017-06-19 Thread /dev/rob0
is still there, and your wildcard A record in the zone would not be used for that name. > Has anyone else come across this? That's the best guess I can come up with without seeing the query and the zone data. If you need more help you will have to share that information. -- htt

Re: Stop Reverse resolution query Logging

2017-06-02 Thread /dev/rob0
ke to log everything else but not the reverse > resolution queries. Why (and why not?) What's the actual problem? And what do you plan to do with all those query logs? Query logging has a substantial impact on server performance. -- http://rob0.nodns4.us/ Offlist GMX mail is seen

Re: Catalog "reconfig" calamity

2017-05-27 Thread /dev/rob0
";" inside the catalog-zones option. I spoke to Witold, who told me the syntax was modeled after response-policy. Fine, but note that another multi-setting option, rate-limit, terminates subordinate options semicolons. So I still think there is some inconsistency. -- h

Re: Resolve specified DNS name in a caching-only name server

2017-05-26 Thread /dev/rob0
#x27;t be resolved theough the regular authority for example.com (or whatever subzone might be delegated.) This is, however, a feature of dnsmasq. Simply list the name and address in /etc/hosts and that name [only] is served out via DNS to your local resolver clients. -- http://rob0.nod

Catalog "reconfig" calamity

2017-05-26 Thread /dev/rob0
n carrying the President (or for any USMC aircraft which might happen to transport the President, for that matter. [2] Similarly, this would be the designation of a USMC aircraft transporting the Vice President.[3] [3] And all this is terribly o

Re: [Ext] Re: Redirect only second and third level domains

2017-02-24 Thread /dev/rob0
ular rabid > weasels and that pair of pants. >---maf LOL, perfect, thanks for that one. I've seen you use it before, but it's especially fitting in this thread. :) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject:

Re: Redirect only second and third level domains

2017-02-24 Thread /dev/rob0
ou implement your "courteous" NXDOMAIN abuse? -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: trouble delegating a subdomain via NS record

2017-02-16 Thread /dev/rob0
use this format (missing owner names) you should keep all the same names together. I suggest always using an owner name on every line. It might not look as pretty, but it is definitely more grep-friendly. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in

Re: Need of 2 $ORIGIN Directives

2016-12-21 Thread /dev/rob0
; > 86400 ; minimum (1 day) > > ) > > NS local.atlanta.com. > > NS kabulvm8.atlanta.com. and these, likewise. NS local NS kabulvm8 > > ;A Records > > local

Re: internal/external view problem

2016-12-14 Thread /dev/rob0
e-key; 192.168.1.0/24; }; This way, any query ("query" being a generic term including nsupdates) signed by the update-key is not routed to your "internal" view. > }; > }; > }; -- http://rob0.nodns4.us/ Offlist GMX mail is seen only i

Re: query time logging

2016-12-02 Thread /dev/rob0
it might not be worth it. You might also want to look at dnstap. NOTE: I have not tried either, so I don't know if they'll report what you want to see. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___

Re: Blocking reverse lookup queries for private ips

2016-11-22 Thread /dev/rob0
.html (Users of BIND 9.8 and earlier versions would need to contact their distributor for support.) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/

Re: ip6tables with raw table(no conntrack) drop fragmented packet

2016-10-01 Thread /dev/rob0
isy, very quickly. Coincidentally, I happen to be working on this very issue, with a different approach: shortened TTL for conntrack entries for UDP DNS. It came up on the Netfilter mailing list recently. I'll be sure to post here when that (a documentation patch) is completed. -- http

Re: broken trust chain on forwarder

2016-09-30 Thread /dev/rob0
On Fri, Sep 30, 2016 at 01:32:29PM -0400, jratl...@bluemarble.net wrote: > On Fri, 30 Sep 2016 11:37:39 -0500, /dev/rob0 wrote: > >> > >> This seems to indicate that the servers at 10.21.0.100 and 101 > >> are telling me that stc.corp domain is DNSSEC enabled.

Re: Multiple IPs Associated With A Single Name

2016-09-30 Thread /dev/rob0
ct 127.0.0.1:53 (both TCP and UDP) to :1035 (or other such non-privileged port as needed.) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-u

Re: broken trust chain on forwarder

2016-09-30 Thread /dev/rob0
r of my config if it would be of use. > > zone "stc.corp" IN { > type forward; > forwarders { 10.21.0.100; 10.21.0.101; }; > forward only; > }; Oh, another thing you can try; offhand I don't know if it will work, but try a zone of type "

Re: root.hind or named.hint file update

2016-09-23 Thread /dev/rob0
es into detail.[1] My personal recommendation, however, is that if you wish to learn more about how DNS works, consult a book such as the Cricket book. [1] Sorry, I am too lazy this morning to look it up for you. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "

Re: replicate a whole master

2016-09-19 Thread /dev/rob0
d it won't handle modern CDN systems properly. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this

Re: High performance DNS server configuration?

2016-09-15 Thread /dev/rob0
t; about 500 or even more. > > Does anyone have ideas how recude server loads because bind is > problem... If that is so, how did you determine that? How could we know? > Thank you for answers or ideas. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob

Re: DNS views and zone transfers

2016-09-07 Thread /dev/rob0
gt;> match-clients { > >> // this list must match 127.0.0.1 > >> any; > >> }; > >> zone "itd.umich.edu" {// this zone is different in the two views > >> type master; > >> file &q

Re: Forwarding via different external networks

2016-08-27 Thread /dev/rob0
ttp://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Allowable reverse mapping zone file names

2016-08-27 Thread /dev/rob0
your IP address is and we might be able to tell you who to contact. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe f

Re: forward first and fallback not working

2016-08-24 Thread /dev/rob0
this fallback isn't a very good idea anyway; you'll probably be better off just doing the recursion without forwarders in the picture. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: __

Re: BIND 9 API & GUI

2016-07-25 Thread /dev/rob0
r 19 years ago!) Various commercial DNS appliance vendors have implemented GUI frontends, but those are now within reach of mere mortals. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please vi

Re: Questions on bind-chroot

2016-06-14 Thread /dev/rob0
e distributor if we don't know the distro & version. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: ISC considering a change to the BIND open source license

2016-06-14 Thread /dev/rob0
t. :/ Or start eating bugs? ;) /me stares at a lightning bug going by the window (a light meal) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/l

Re: Reverse Zone CIDR

2016-05-25 Thread /dev/rob0
tually run that /16 zone ... 168.192.in-addr.arpa. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-

Re: Forward zone not working

2016-05-16 Thread /dev/rob0
e. > > Does anyone have any insights or suggestions? A query will only be forwarded if RD is set and recursion is permitted for that client, as you have already discovered. Perhaps a zone of type "stub" or "static-stub&quo

Re: Maintain task frequency

2016-05-10 Thread /dev/rob0
also the ISC KB article on best practices for resolvers. I probably missed something, but that's a good start. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.is

Re: Maintain task frequency

2016-05-09 Thread /dev/rob0
the "rndc stats" output, in real time as needed, and designed to be easily parsed by automated tools. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mai

Re: Nsupdate usage scenario

2016-05-04 Thread /dev/rob0
e statement. My personal recommendation: get over the idea of looking at zone files; use "dig axfr example.com. | less". Let named manage and serve the DNS data as it will. Comments can be included as TXT records if you like. --

Re: 'succesful' nsupdate of remote server not persistent across nameserver restart?

2016-04-24 Thread /dev/rob0
messages 1, bytes 178) > > cd > grep -rlni acme . > (empty) > > What am I failing to do to make this update persistent across flush/restart, > as intended? What is deleting your journal? It's not named doing that. Why was the journal not written to the z

Re: Recursive bind becomes unresponsive with high load

2016-04-01 Thread /dev/rob0
= 512 > net.ipv4.neigh.default.gc_thresh2 = 1024 > net.ipv4.neigh.default.gc_thresh3 = 2048 > net.ipv4.tcp_max_syn_backlog = 4096 > net.ipv4.tcp_fin_timeout = 30 > net.ipv4.tcp_tw_recycle = 1 -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in

Re: *Reminder of the* L-Root IPv6 address renumbering

2016-03-21 Thread /dev/rob0
ed upthread: > New hints files will be available at the following URLs once > the change has been formally executed on March 23, 2016: > > * http://www.internic.net/domain/named.root > * http://www.internic.net/domain/named.cache -- h

Re: about NS server authorize

2016-03-21 Thread /dev/rob0
can help you. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Multiple A records and reverse DNS

2016-03-18 Thread /dev/rob0
irly easy in Linux, albeit not particularly well documented. For other OSs, I wouldn't know. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailma

Re: Database driven ACL

2016-02-29 Thread /dev/rob0
7;s what you meant about "reading/writing into a text file".) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscr

Re: root hints operation

2015-11-16 Thread /dev/rob0
> Will someone take a moment and confirm, or correct, my > understanding of how root hints work in BIND? I think this should answer your questions: https://www.isc.org/blogs/h-root-will-change-its-addresses-on-1-december-2015-what-does-this-mean-for-you/ -- http://rob0.nodns4.us/

Re: Bind and views

2015-10-07 Thread /dev/rob0
;s the right one? If you want to share a zone in more than one view, do as Mark suggested: upgrade to 9.10.3 and use "in-view". You probably ought to consider upgrading anyway, because of recent security patches. > Important: i need the views binded to differents ips. -- h

Re: Caching and upper case issue with BIND 9.9.7-P3

2015-09-26 Thread /dev/rob0
r choices: rndc flush rndc flushtree example.com -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: Install BIND 9.9.7-P2 to fix vulnerability CVE-2015-5477

2015-09-07 Thread /dev/rob0
sion. I would suggest that you invest some time in learning Red Hat basic administration skills, and with it some shell basics, and you will become able to diagnose and fix these problems on your own. Good luck. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0&q

Re: Installing bind is not very clear for me

2015-09-04 Thread /dev/rob0
On Fri, Sep 04, 2015 at 05:27:18PM +, Mike Hoskins (michoski) wrote: > On 9/4/15, 1:12 PM, "bind-users-boun...@lists.isc.org on behalf > of /dev/rob0" r...@gmx.co.uk> wrote: > > >On Thu, Sep 03, 2015 at 11:02:23PM +0200, Reindl Harald wrote: > >>

Re: Installing bind is not very clear for me

2015-09-04 Thread /dev/rob0
nvolved a compromise of any kind? I cannot say with authority that BIND9 has never had a compromise, but I am confident in saying I have never seen one. https://www.isc.org/blogs/summer_security_vulnerabilities/ is a recent blog posting which discusses this in det

Re: More On Split Horizon & Slaves

2015-08-22 Thread /dev/rob0
y, so that the slave knows > which view is which, but I am not clear on how to do this when both > views are in the same namespace. https://kb.isc.org/article/AA-00296/0 https://kb.isc.org/article/AA-00851/0 -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/ro

Re: DNSSEC secondary (free)

2015-08-20 Thread /dev/rob0
ut 3.1 forevers. Does anyone know if exploration was successful? > experience, but we’ve been considering using them for the same > purpose, and they seem to have a good community reputation). -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0&q

Re: Can I run two name servers on one host with two IP addresses?

2015-08-20 Thread /dev/rob0
r service here.) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.o

Re: configuration error in lists.isc.org

2015-08-06 Thread /dev/rob0
s. Some of them use it for such things as killfiling. But thank you for bringing this issue up. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: bind 9.8 named_stats parser

2015-08-04 Thread /dev/rob0
gt; If not I will need to deploy by my self ... then of > course will share it. There too, if you're doing things the old way on abandoned old software versions, I wouldn't expect to find much interest. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/r

correction

2015-08-04 Thread /dev/rob0
On Tue, Aug 04, 2015 at 07:14:38AM -0500, /dev/rob0 wrote: > It would require some reworking of things, but you might be > interested in the new BIND 9.10 feature of "in-view" zone option. > This lets you literally include a zone from another view. See > BIND 9 ARM chap

Re: ERROR : - writeable file 'data/udalgurijudiciarygov.hosts': already in use: /etc/nicnet2007.govdomain:15424 - loading configuration: failure

2015-08-04 Thread /dev/rob0
t everything per zone.) > To hold us/me over until they decide if its going to be > BlueCat or Infoblox that replaces everything. IIUC both of those are BIND under the hood. :) > Sadly, I missed both presentations due to other issuesmore sad > because I found my "named.

Re: About CVE-2015-5477 ("An error in handling TKEY queries can cause named to exit with a REQUIRE assertion failure")

2015-07-28 Thread /dev/rob0
another server. But if you're thinking it's okay because you're going to deny the query, no! This happens before named gets to that point. Your nameserver must be closed to ALL potentially hostile queries. -- http://rob0.nodns4.us/ Offlist GMX mail is seen

Re: dynamic zone file "style"

2015-07-08 Thread /dev/rob0
> single file. And, luckily, it uses the "full" style :) So this > should be fine for me. > > But before I try to re-invent the wheel: > Does anyone know if there is already a parser for multiple > zone_files/zone_dumps/zone_transfers? I'm trying to filter all DNS >

Re: file descriptor exceeds limit

2015-06-19 Thread /dev/rob0
f conntrack for UDP DNS upstream, unless you're using DNAT > (yuck.) Oh ... hahaha ... I missed the @cisco.com, so I don't suppose you're using Linux on your upstream routers. :) The same idea applies regardless of implementation, of course. -- http://rob0.nodns4.us/ Offli

Re: file descriptor exceeds limit

2015-06-19 Thread /dev/rob0
ply to Cathy...more detail on that > there. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: [bind-users] Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2015-05-10 Thread /dev/rob0
nobody's done it yet. Oops, sorry. When I suggested it I was unemployed, and now [thankfully] am not. $Dayjob keeps me busy, but now I have more clue about the docbook, so I'll try to do what I can. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" i

Re: Getting an error on a very simple DNS configuration

2015-04-08 Thread /dev/rob0
e which covers compiling from source and running a simple named for recursion: https://kb.isc.org/article/AA-00768/ -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit http

Re: com.google how did they do that

2015-04-01 Thread /dev/rob0
nd more coming. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-u

Re: behavior of dnssec-enable in relation to dnssec-validation

2015-03-27 Thread /dev/rob0
ation Enable DNSSEC validation in named. Note dnssec-enable also needs to be set to yes to be effective. ... " This does not seem to be the case. I think bug, whether it's the documentation or the behavior. > misinterpreting the apparent behavior? something else? -- http:

Re: BIND not loading into memory on first transfer

2015-03-27 Thread /dev/rob0
pened, and while this sounds more reasonable, I am not sure that the zone transfer actually does take place if named is unable to open a temporary file to write. (What would be the point in talking to the master when you know you are unable to handle the data?) -- http://rob0.nodns4.us/ Offl

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread /dev/rob0
On Wed, Mar 18, 2015 at 06:11:56PM +0300, Konstantin Stefanov wrote: > On 18.03.2015 17:41, /dev/rob0 wrote: > > On Wed, Mar 18, 2015 at 11:48:40AM +0300, Constantin Stefanov wrote: > >> I see why it may lead to problems. > >> > >> But in fact the confi

Re: Single slave zone definition for two view (cache file name problem)

2015-03-18 Thread /dev/rob0
that would be to have some kind of variable in the named.conf syntax to refer to the name of the current view. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Single slave zone definition for two view (cache file name problem)

2015-03-17 Thread /dev/rob0
a good workaround for that. But there are tools like make(1) which can do this for you? I would suggest a script to generate the common.zones file from whatever you're using for the "common" view. Maybe someone else will have a better suggestion? -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: forwarder and cache

2015-03-16 Thread /dev/rob0
e SOA), the NXDOMAIN result is cached. For more help show your actual dig commands and results. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/

Re: unable-resolving

2015-03-09 Thread /dev/rob0
can't find www.twitter.com: Server failed Two suggestions: first, get rid of nslookup. Use dig and share the dig query and result with the list. Second, check your logs for the exact time of these SERVFAIL responses you're seeing. Sometimes these will be logged. -- http://rob0

Re: Too many connections on the same IP

2015-03-04 Thread /dev/rob0
ork > interface. This could explain, why your second IP is still > responding. There is a single conntrack table for the system, and all entries therein are based on packet header information: source and destination IP address (and ports if applicable.) We really don't have enough info

Re: dynamic update of split view acl

2015-02-28 Thread /dev/rob0
the serial of view1.zone and view2.zone, but > 204.57.0.0/24 is still matched by view1. Is there any way to > accomplish this? Right. So you redo your acl statements and do "rndc reconfig". The acls are simply there to make it easier to manage. The real answer is reconfig. That wil

Re: Share RPZ Zones between views

2015-02-20 Thread /dev/rob0
GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Setup our OWN DNS Server

2015-01-30 Thread /dev/rob0
lly, of course, this mailing list has a lot of experienced people, willing to help you out if you get stuck. Good luck! -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.

Re: Bind in FreeBSD 10

2015-01-22 Thread /dev/rob0
rsion (ESV), so it's likely to outlive 9.10. If you're after long-term stability, ESV might be important to you. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit ht

Re: Disable DNSSEC Validation for selected Domains

2015-01-17 Thread /dev/rob0
; Documentations etc... I wouldn't be surprised if they are not even > aware of the problem, yet. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/

Re: DNSSEC

2015-01-17 Thread /dev/rob0
ob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.i

Re: slave fail to ixfr from master

2014-09-14 Thread /dev/rob0
aster and slave, if this wasn't enough to get it figured out. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscri

Re: Two domains reporting errors

2014-09-10 Thread /dev/rob0
oad as any zone name. You might want to use some fully-qualified names on the RHS, such as "root.covisp.net." as the SOA RNAME. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: A record of domain name must be name server ?

2014-09-08 Thread /dev/rob0
st have either or both A and records for those NS names. Here is the same zone without the XXX and with all relative names: > @ IN SOA ns1 root.ns1 ( > 2014090801 ; serial > 2h ; refresh > 10m; retry > 1w ; expiry >

Re: DNS reverse sub delegation NXDOMAIN problem, Class C

2014-08-19 Thread /dev/rob0
That said, sure, typically you're going to host such internal-only zones on a server that also does recursion. That's not required, however. The recursive server could have stub or static-stub zones, or even an alternate root zone, which points to the authoritative server. Pedantr

Re: Root servers

2014-08-15 Thread /dev/rob0
ND version. If the OS is so old to be have a 2008020400 hint file, it probably means no updates have been done along the way. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Root servers

2014-08-14 Thread /dev/rob0
t; ; on server FTP.INTERNIC.NET > ; -OR-RS.INTERNIC.NET > ; > ; last update:Feb 04, 2008 > ; related version of root zone: 2008020400 That's old, but not so old as to prevent you from reaching an actual root server.

Re: Metazones or Something Else?

2014-08-05 Thread /dev/rob0
mply have the web form do the "rndc addzone" remotely. Lots of choices, not easy to say what's best. Except that addzone (and delzone also) works at runtime, not requiring a separate "rndc reconfig" to load (or remove) zones. -- http://rob0.nodns4.us/ Offli

Re: rndc (and now nsupdate too)

2014-07-31 Thread /dev/rob0
On Thu, Jul 31, 2014 at 05:56:08PM +0200, Reindl Harald wrote: > Am 31.07.2014 um 17:41 schrieb /dev/rob0: > > On Thu, Jul 31, 2014 at 01:32:03PM +0200, Reindl Harald wrote: > >> i am doing reloads of named with "killall -HUP named" just > >> because i disable

Re: rndc

2014-07-31 Thread /dev/rob0
-- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://

rndc (was: Re: Reload BIND ...)

2014-07-31 Thread /dev/rob0
e it. :) -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

  1   2   >