Re: Questions on how to setup Reverse DNS in bind 9

2016-07-18 Thread Jeremy C. Reed
On Sun, 17 Jul 2016, Spork Schivago wrote: > So, in the /var/named directory, I create a file > called: 0.117.238.104.in-addr.arpa > > The contents of 0.117.238.104.in-addr.arpa are as follows: > $TTL 1D > @       IN SOA  ns1.jetbbs.com. spork.jetbbs.com. ( >                                      

Re: RES: RHEL, Centos, Fedora rpm 9.10.4-P1

2016-06-22 Thread Jeremy C. Reed
On Wed, 22 Jun 2016, Leonardo Oliveira Ortiz wrote: > Someone had success to build it? I got make test errors... What was the error? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing

Re: Nsupdate usage scenario

2016-05-02 Thread Jeremy C. Reed
Also for the generated master file, have a look at "masterfile-style full;" option. Have a look at the named-compilezone -j with -s full or -s relative so you can compare outputs. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: Nsupdate usage scenario

2016-05-02 Thread Jeremy C. Reed
What about using a specific zone file just for the purpose of the single A record you want to maintain using dynamic updates? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Re: Cannot get BIND logs to write to the correct file.

2016-05-02 Thread Jeremy C. Reed
ding to a new version of Red Hat Linux > as well as a new version of BIND on a different server. > > Any help is greatly appreciated! What am I doing wrong here? Hi Sean, Also use a "category" configuration. For example: category defaul

Re: Bind 9.11.0a1

2016-04-21 Thread Jeremy C. Reed
On Thu, 21 Apr 2016, ap...@yandex.ru wrote: > Would be great to hear smth about question #2. I've tried to use rndc > trace with various levels of debugging and still edns subnet is not > shown anywhere. > > 2) I have looked through sources and bind 9.11 guide, but have not > > found the way

RE: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > Thanks Jeremy > > > Logging section from named.conf > > logging { > channel "named-log" { > file "/usr/local/named-jail9.10.3P4/var/adm/named.log" > versions 3 size 30m; ... > category "general" {

RE: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > I know it using rndc is a good practice but is there an option to > specify in named.conf to disable it? It is disabled by default because there is no complete command channel configuration in the first place, but this will make it so it

Re: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > '--enable-newstats' '--with-libxml2' '--enable-fullreport' 'CFLAGS=-O2 Unrelated to your problem, but the --enable-newstats configure switch is not used for BIND 9.10. > 1. Cannot seem to start named and it seems that it is looking for

Re: make test fails without Net::DNS::Nameserver

2015-07-14 Thread Jeremy C. Reed
On Tue, 14 Jul 2015, Maria Iano wrote: I don't see this mentioned anywhere else, although I'm suprised by that so maybe I'm missing something. When I build bind-9.10.2-P2 I find that make test fails for reclimit with Couldn't start server ans2 if I don't have Net::DNS::Nameserver installed.

Re: #service named restart fails with a weird message

2015-06-19 Thread Jeremy C. Reed
On Fri, 19 Jun 2015, Samad Agha wrote: Error in named configuration: /etc/named.conf:3: missing ';' before '}' Look on line 3 /etc/named.conf:11: missing ';' before '}' Look on line 11 options { directory /var/named;     allow-recursion {207.151.36.0/24; 206.117.117.0/24};

Re: Native pkcs#11 and auto-dnssec feature

2015-04-08 Thread Jeremy C. Reed
My question is about auto-dnssec feature that maintain zone by internally signing RRs. How this feature will work without a PIN since BIND needs access to private key when it needs to resign automatically and i did't find a way to provide the PIN throught configuration files ? Hi, Does

Re: compile and install from source

2015-03-30 Thread Jeremy C. Reed
On Sun, 29 Mar 2015, INVALID_ADDRESS wrote: named_conf=/etc/namedb/named.conf # Path to the configuration file ... So I changed the path (in /etc/rc.conf) to /usr/local/sbin/named But now I get: $ /etc/rc.d/named start Starting named. /etc/rc.d/named: WARNING: failed to start named

Re: Finding authoritative server and last update

2015-02-03 Thread Jeremy C. Reed
On Tue, 3 Feb 2015, Robert Moskowitz wrote: I am trying to find out which comcast server is authoritative for 4.254.253.50.in-addr.arpa and when the zone file for the ptr rr was last updated. I was told a week ago that the ptr would be updated, but I am still not seeing any change...

Re: Finding authoritative server and last update

2015-02-03 Thread Jeremy C. Reed
By the way, it looks like the SOA MNAME has a misspelling typo in it. I wonder if that is on purpose to foil automated/unintelligent spammers. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: DNSSEC

2015-01-17 Thread Jeremy C. Reed
On Sat, 17 Jan 2015, John wrote: is there a separate DNSSEC mailing list? You may use this bind-users list to discuss DNSSEC. There are other lists for DNSSEC managed outside of ISC and not specific to BIND, such as: Dnssec-deployment.org (but I cannot access their mailman webpage

BIND DNSSEC Guide draft

2014-12-31 Thread Jeremy C. Reed
://users.isc.org/~jreed/dnssec-guide/dnssec-guide.pdf The docbook source for the guide is at GitHub: https://github.com/isc-projects/isc-dnssec-guide/ Happy New Year! Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: BIND9 Return different IP address based on subnet

2014-12-27 Thread Jeremy C. Reed
On Sat, 27 Dec 2014, Christian Kette wrote: I have some questions. Q1: Why do I get the IP address 192.168.2.100 for DEV.home.lan from both the 192.168.2.0/24 and the 192.168.10.0/24 network? The view that matches first is used. #include /etc/bind/named.conf.default-zones; ... Q2: What

Re: Dumping the statistics channel

2014-11-03 Thread Jeremy C. Reed
On Mon, 3 Nov 2014, Thomas Schulz wrote: I have been asked to dump the statistics to help document a suspected memory leak in named. When I look at the statistics with Firefox, I see a nicely formatted set of statistics. If I then dump the statistics to a file with wget and then use Firefox

Re: bind-9.10.0-P2 memory leak?

2014-10-13 Thread Jeremy C. Reed
On Mon, 13 Oct 2014, Thomas Schulz wrote: I restarted bind 9.9.6 with a max-cache-size of 30M. We have 3 views. The inital process size was 36 MB. The process grew to 184 MB. It grew to 596 MB without the max-cache-size being set and was still growing when I restarted it. BUT when I now do

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
On Fri, 12 Sep 2014, Mathieu Arnold wrote: Yes, you can't use bmake if you try to build the python bits, I had to force gmake in the port: It looks to be a bug in the NetBSD bmake used by FreeBSD. I cannot find a bug report for it in FreeBSD. I opened one for NetBSD:

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
On Fri, 12 Sep 2014, Jeremy C. Reed wrote: It looks to be a bug in the NetBSD bmake used by FreeBSD. I cannot find a bug report for it in FreeBSD. I opened one for NetBSD: http://gnats.netbsd.org/49198x http://gnats.netbsd.org/49198 (My system types a random x on its own often. Imagine

Re: BIND 9.10.1rc2 won't build on FreeBSD 10-STABLE

2014-09-12 Thread Jeremy C. Reed
On Fri, 12 Sep 2014, Mark Andrews wrote: Try collapsing the multiple .SUFFIXES into a single entry. That doesn't work (for me). ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Re: bind-9.10.0-P2 memory leak?

2014-09-12 Thread Jeremy C. Reed
On Tue, 9 Sep 2014, Thomas Schulz wrote: What version did you upgrade from? I am seeing bind 9.9.5 and 9.9.6 grow without any evidence that it will ever stop. See my mail to this list with the subject Re: Process size versus cache size. Mine is growing slower than yours, but it is now up to

Re: bind-9.10.0-P2 memory leak?

2014-09-12 Thread Jeremy C. Reed
Can you copy and paste the out of memory error you are seeing? Is it still growing? Does it appear to work? I see your other thread answers some. https://lists.isc.org/pipermail/bind-users/2014-July/093618.html ___ Please visit

Re: no servers found

2014-08-21 Thread Jeremy C. Reed
In the virtual server, use dig @a.b.c.d with the IP address of the DNS servers you want to use to see if that works. If you are running named in that same virtual server, try dig @127.0.0.1. If that works, then just change your resolv.conf to point to only that nameserver 127.0.0.1

Re: no servers found

2014-08-21 Thread Jeremy C. Reed
On Thu, 21 Aug 2014, Adamiec, Lawrence wrote: Using dig @My-NAME-SERVER works.  I am not running named on the virtual server using dig @ 127.0.0.1 does not work. Okay. Then change your /etc/resolv.conf to contain just the nameserver and IP of that name server (and a couple others if you

Re: geoip asnum matching

2014-08-21 Thread Jeremy C. Reed
On Thu, 21 Aug 2014, Dietrich Oberhausen wrote: I've got an issue with bind 9.10 and GeoIP asnum based matching. As far as I can tell I need to match not only the AS number but also the org name? This works: match-clients { geoip asnum AS8767 M-net Telekommunikations GmbH, Germany; };

Re: Runtime disable RRL

2014-08-19 Thread Jeremy C. Reed
, but you can disable the rate limiting with: rate-limit { responses-per-second 0; }; If your tests involve builtin CHAOS, see https://lists.isc.org/pipermail/bind-users/2014-May/093107.html Jeremy C. Reed ISC ___ Please visit https

Re: both recursive-only BIND9 went deaf until rebooted

2014-08-13 Thread Jeremy C. Reed
On Wed, 13 Aug 2014, lcon...@go2france.com wrote: fbsd 8.2 VM with BIND 9.9.5 fbsd 10.0-RELEASE VM with BIND 9.10.0-P2 the older machine had uptime of 400+ days, the new machine only a couple weeks 24 hour query logging shows several million queries/day At about the same time last

Re: test bind before moving to production

2014-07-03 Thread Jeremy C. Reed
On Thu, 3 Jul 2014, brian wrote: I'm new to bind. I want to be able to test the dns server on my local machine before launching it by putting the domain names (ie example.com) in my browser and browsing the site. Both the dev and production machines are CentOS. I assume I'll need to edit

Re: Cannot get allow-query-on to work

2014-07-02 Thread Jeremy C. Reed
I am using Ubuntu 12.04.4, BIND 9.8.1-P1, and just added: allow-query-on { 127.0.0.1; }; Please upgrade your BIND. There was a bug in allow-query-on that was fixed since 9.8.6rc2. Please note that currently allow-query-on is only used for zone configurations. Use allow-cache-on if restricting

Re: Error when using GeoIP

2014-07-01 Thread Jeremy C. Reed
On Tue, 1 Jul 2014, Ali Jawad wrote: [root@uk etc]# ls -lart /usr/share/GeoIP/  -rw-r--r--   1 root root 1206078 Jul  1 10:08 GeoIP.dat The output from the logs is  Jul  1 14:38:56 uk named[1795]: using /usr/share/GeoIP as GeoIP directory Jul  1 14:38:56 uk named[1795]: GeoIP

Re: AIX and 9.9.5 compiling

2014-05-09 Thread Jeremy C. Reed
Currently, some of the systems that we automatically build and run various tests on include: FreeBSD 4.11 i386 FreeBSD 6.3 i386 FreeBSD 8.4 i386 FreeBSD 10.0-CURRENT i386 Fedora 18 Linux 3.8.1-201.fc18.x86_64 x86_64 Fedora 19 Linux 3.11.6-200.fc19.x86_64 x86_64 HPUX B11.11 HPPA2.0w (HP

Re: Issues in configuring Bind 9.10 in CentOS 6.3 with --open-ssl

2014-05-02 Thread Jeremy C. Reed
On Fri, 2 May 2014, Gaurav Kansal wrote: checking for OpenSSL library... using OpenSSL from /usr/lib and /usr/include checking whether linking with OpenSSL works... no configure: error: Could not run test program using OpenSSL from /usr/lib and /usr/include. Please check the argument

Re: RRL active by default?

2014-05-02 Thread Jeremy C. Reed
On Thu, 1 May 2014, Lawrence K. Chen, P.Eng. wrote: Does compiling in RRL mean its active, even without a rate-limit {} control block? Only for the built-in Chaos _bind view (for id.server, authors.bind, hostname.bind, and version.bind). ___ Please

RE: Issues in configuring Bind 9.10 in CentOS 6.3 with --open-ssl

2014-05-02 Thread Jeremy C. Reed
On Fri, 2 May 2014, Gaurav Kansal wrote: Config.log doesn't showing any useful data to troubleshoot this. configure:15338: checking for OpenSSL library configure:15436: error: /usr/include/openssl//include/openssl/opensslv.h not found You looked at config.log after you did a different

Re: RRL active by default?

2014-05-02 Thread Jeremy C. Reed
On 05/02/14 09:23, Jeremy C. Reed wrote: Only for the built-in Chaos _bind view (for id.server, authors.bind, hostname.bind, and version.bind). On Fri, 2 May 2014, Lawrence K. Chen, P.Eng. wrote: Awww...I found messages about version.bind. My workaround I use is like: # for builtin

Re: GeoIP in 9.10 RC2

2014-04-30 Thread Jeremy C. Reed
So the the IPv4 Country DB is recognized and loaded, but digs from US to that server still result in queries from the ALL view, which is the last view in the config file and the test View above is the first View in teh config file. You may want to try the geoiplookup (provided by GeoIP

Re: GeoIP in 9.10 RC2

2014-04-30 Thread Jeremy C. Reed
On Wed, 30 Apr 2014, Ali Jawad wrote: view US {        match-clients { US; }; For now please change to: match-clients { geoip country US; };___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: R: DNS with several ip adessess

2014-01-02 Thread Jeremy C. Reed
On Thu, 2 Jan 2014, wbr...@e1b.org wrote: When were views added to BIND? We started using using multiple servers in BIND 4, and I don't recall views being available back then, but I didn't configure the servers, just maintained the zones. Views were introduced in BIND 9.0.0 (September

Re: BIND10 : how do I import zone files stored in mysql to BIND10 ?

2013-12-16 Thread Jeremy C. Reed
data_sources/classes/IN[0]/params to see where you should put your database file. I will also try digging code meanwhile .. Have fun Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind

Re: caps compiling error

2013-11-26 Thread Jeremy C. Reed
Please see https://kb.isc.org/article/AA-01060/0/Building-BIND-9.9.4-9.8.6-and-9.6-ESV-R10-on-RHEL-and-CentOS-with-libcap-dev-installed.html ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: BIND9-ARM (HTML) feature request: better hyperlinking in/of chapter 6

2013-11-21 Thread Jeremy C. Reed
On Wed, 20 Nov 2013, /dev/rob0 wrote: Chapter 6 is the comprehensive configuration reference. What I'd like to see is more (and plain-language, consistent) hyperlinking. The basic idea is that any named.conf setting could be found at an anchor: Bv9ARM.ch06.html#that-setting Yes that

Re: Upgrade Bind documentation

2013-10-24 Thread Jeremy C. Reed
the major features introduces and any incompatible changes to be aware of for all of our releases. But it is not ready yet. Jeremy C. Reed ISC___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: the location of dig and named

2013-08-28 Thread Jeremy C. Reed
On Wed, 28 Aug 2013, Nidal Shater wrote: when I typed dig  or named ,,, what is the location of the executable program dig and named is ? Maybe one of these will help: command -v dig type dig which dig whereis dig command -v named type named which named whereis named There are many other

Re: auto-dnssec maintain and no key: no error message?

2013-07-30 Thread Jeremy C. Reed
On Tue, 30 Jul 2013, Stephane Bortzmeyer wrote: Of course, there is no signature: % dig +multi @localhost SOA auto.rd.nic.fr Add +dnssec ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: Notice: BIND Security Jul2013 CVE2013-4854

2013-07-27 Thread Jeremy C. Reed
) Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: make test fails on Fedora 10

2013-03-27 Thread Jeremy C. Reed
On Wed, 27 Mar 2013, Luther, Dan wrote: For the tests, BIND starts up with an empty group descriptor:   I:issuing command '/home/luther/bind-9.9.2-P2/bin/named/named -m record,size,mctx -T clienttest -c named.conf -d 99 -g named.run 21 echo $!' I guess you are talking about -g. It is

Re: make test fails on Fedora 10

2013-03-27 Thread Jeremy C. Reed
On Wed, 27 Mar 2013, Luther, Dan wrote: Working with the BIND 9.9.2-P2 compile, I just spent several minutes tracking the source of this down with some judicious use of ?print? in the ?bin/tests/system/start.pl? script and viewing the ?*.run? output. It really comes down to file permissions

BIND 10 - 1.0.0 Release Candidate

2013-02-14 Thread Jeremy C. Reed
://lists.isc.org/mailman/listinfo/bind10-users https://lists.isc.org/mailman/listinfo/bind10-dev Jeremy C. Reed ISC Release Engineering -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (NetBSD) iEYEARECAAYFAlEdqlYACgkQs9Bv5D4YwC3t9QCdFmHE9bVZq0WRa4E1pq5t1JtK

Re: Performance impact of a large ACL list.

2013-02-04 Thread Jeremy C. Reed
On Mon, 4 Feb 2013, Augie Schwer wrote: Does anyone have any experience using a large ( 1k ) entry ACL list? Was there any performance degradation? I haven't implemented my ACL yet, but it has quickly ballooned up, and I am hoping to get some advice from others in a similar situation. It

what do you use for logging?

2013-01-17 Thread Jeremy C. Reed
documentation for each of its 933 possible log identifiers!) Thanks! Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

BIND 10 - 1.0.0 Beta Release

2012-12-20 Thread Jeremy C. Reed
in the same directory. (Trac #2475, git 834fa9e8f5097c6fd06845620f68547a97da8ff8) Thanks again to those who contributed bug reports, code, and reviews. Jeremy C. Reed ISC Release Engineer -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.9 (NetBSD

Re: Strange Issue

2012-12-12 Thread Jeremy C. Reed
.  There are also no errors in the logs. Any ideas? You may want to verify you are querying the correct name server? (and enable extra logging for that) Also it may be easier for others to point out problems if you show the actual configurations, data, reproducable steps, etc. Jeremy C. Reed

Re: another performance tuning question

2012-11-30 Thread Jeremy C. Reed
On Fri, 30 Nov 2012, Adamiec, Lawrence wrote: I got similar results when running against the master server. Then why so many lost?   Queries sent:         11000 queries   Queries completed:    8968 queries   Queries lost:         2032 queries ...   Percentage completed:  81.53%  

Re: Need to improve named performance

2012-11-12 Thread Jeremy C. Reed
On Mon, 12 Nov 2012, Ed LaFrance wrote: Currently I'm not using query logging, it's not in my options at all. I think rndc querylog was used to enable it (even if no corresponding logging configuration). You can use it again to toggle it off. rndc status will show if query logging is on or

Re: BIND 9.9.1-P4 is now available

2012-10-25 Thread Jeremy C. Reed
correctly but it is slow.) Jeremy C. Reed ISC___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Disable log message

2012-10-18 Thread Jeremy C. Reed
On Thu, 18 Oct 2012, Jack Tavares wrote: I am running bind9.8.x built from source and I see this message in the logs built with '--prefix=/blah' '--sbindir=/blah' '--sysconfdir=/blah' '--localstatedir=/var' '--exec-prefix=/usr' '--libdir=/usr/lib' '--mandir=/usr/share/man'

Re: squash 'client query (cache) denied' syslog entries

2012-10-18 Thread Jeremy C. Reed
On Thu, 18 Oct 2012, David Dowdle wrote: Some of my external facing nameservers are under attack, and the biggiest fallout, is the machines goign into iowait from logging all the client query denied syslog messages. note: yes, recursion is turned off on these machines. The current

Re: How to prevent BIND from resolving addresses in logs

2012-09-27 Thread Jeremy C. Reed
On Thu, 27 Sep 2012, Spumonti Spumonti wrote: I just installed BIND 9.9.1-P3 from source and while looking through the query log files I noticed that IP addresses were being resolved: 27-Sep-2012 12:01:56.512 client 192.168.5.10#44863 (host.foo.com): query: www.ibm.com ... That is:

Re: Issue with Minumum Value for named9

2012-09-21 Thread Jeremy C. Reed
On Fri, 21 Sep 2012, Robert JR wrote: i have the minimum value in my dns server as 60 mins, and my TTL is 60 Seconds , but still when users hit a non exist record , the other dns hold the negative cache for 60 secs instead of 60 mins .. ? why ?  $TTL 60 @ IN SOA NS1.TEST.BIZ.

Re: Problem with ACL in named.conf

2012-08-29 Thread Jeremy C. Reed
On Thu, 30 Aug 2012, GS Bryan wrote: also-notify { alladdr; }; This uses an ip_addr instead of an address_match_list. Some versions of named-checkconf will tell you expected IP address. /etc/named.conf:111: masters alladdr not found I can't reproduce your problem. What version of

Re: Zone Transfer issue on BIND9

2012-08-24 Thread Jeremy C. Reed
On Fri, 24 Aug 2012, sn...@email.it wrote: ***MASTER server (FreeBSD 9.0-RELEASE-p3 (i386)|| BIND 9.8.3-P2)*** view internal { match-clients { !key TSIG-KEY; internal; datacentre; }; ... view dmz { match-clients { !key TSIG-KEY; internal; datacentre; }; A client request

Re: Zone Transfer issue on BIND9

2012-08-24 Thread Jeremy C. Reed
On Fri, 24 Aug 2012, sn...@email.it wrote: view internal { ... zone 1.16.172.in-addr.arpa IN { type master; file /etc/namedb/master/1.16.172.in-addr.arpa.ext.zone; Previous zone file names in this same view were called int. Why the filename change?

Re: Version statement...

2012-08-18 Thread Jeremy C. Reed
How are you testing it? Where do you see the wrong version? ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org

Re: Dig 9.9.1 AD-bit

2012-08-02 Thread Jeremy C. Reed
On Thu, 2 Aug 2012, Marco Davids (SIDN) wrote: Dig 9.9.1 is setting the AD-bit in queries by default. Does anyone know why? 3205. [func] Upgrade dig's defaults to better reflect modern nameserver behaviour. Enable dig +adflag and

Re: Operation cancelled Error

2012-05-24 Thread Jeremy C. Reed
.) Jeremy C. Reed ISC ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Host command timing out sporadically

2012-05-02 Thread Jeremy C. Reed
On Wed, 2 May 2012, Paul Marais wrote: I'm having an issue where my postfix server is having trouble with some lookups. When I type 'host hostname', 80% of the time I get decent reply speed, but for 20% I get a 5 second delay, or even a timeout. My nameserver is configured to only allow

Re: Convice Bind to listen on IP alias with a range of IPs.

2012-04-30 Thread Jeremy C. Reed
On Mon, 30 Apr 2012, Augie Schwer wrote: I must be doing something wrong, because what I want to do doesn't seem that difficult. I have a range of IPs bound to a local interface: lo:1 Link encap:Local Loopback inet addr:10.0.0.1 Mask:255.255.255.224 And I want to

Re: Logging issue with bind

2012-02-17 Thread Jeremy C. Reed
On Fri, 17 Feb 2012, Andrea Gozzi wrote: All further tests haven't produced any results. Any related log messages in your other named logging about it. (Maybe some isc_stdio_open error for example?) Why were the permissions of your log file rwxrwxrwx? (Why executable? Why writable by other?)

Re: Logging issue with bind

2012-02-16 Thread Jeremy C. Reed
On Fri, 17 Feb 2012, Mark Andrews wrote: Do: rndc querylog or querylog yes; But the previous email showed rndc status had: query logging is ON ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

Re: make bind-9.7.4-P1 fails when --prefix and --exec-prefix switches are used

2011-11-30 Thread Jeremy C. Reed
On Wed, 30 Nov 2011, jagan padhi wrote: checking build system type... sparc-sun-solaris2.10 checking for a sed that does not truncate output... ./configure: line 4579: /usr/bin/cmp: cannot execute binary file What does this tell you? file /usr/bin/cmp (Maybe you have /usr/bin/cmp for

Re: make bind-9.7.4-P1 fails when --prefix and --exec-prefix switches are used

2011-11-17 Thread Jeremy C. Reed
I am unable to reproduce this (on a CentOS Linux system). Please tell us about your platform, what shell, what make, and provide a copy of your full configure output, and config.log and generated bin/named/Makefile. You may send these to me off-list if you'd like. Thanks, Jeremy C. Reed

nanny (was Re: bind-9.8.1: INSIST(! dns_rdataset _isassociated(sigrdataset)) failed)

2011-11-17 Thread Jeremy C. Reed
On Wed, 16 Nov 2011, Phil Mayers wrote: It might be good if bind were able to re-start itself, rather than dying outright (e.g. re-exec the process) but that is dangerous too; it's better done by an unrelated supervising process. In the bind9 tarball's contrib directory there is a simply

Re: named web statistics

2011-07-06 Thread Jeremy C. Reed
On Wed, 6 Jul 2011, King, Harold Clyde (Hal) wrote: I know there is a web front end to DNS stats, but I can not remember the option in the named.conf that defines the port. I'm running 9.8.0-P4 (just now being able to upgrade to a version that supports the statistics) statistics-channels

Re: Description of log file contents

2011-04-14 Thread Jeremy C. Reed
It is in the ARM. http://ftp.isc.org/isc/bind9/cur/9.8/doc/arm/Bv9ARM.ch06.html#id2575842 (search for queries or querylog) ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: bind8 and bind9 installed on the same server: possible?

2011-02-01 Thread Jeremy C. Reed
--prefix=/usr/local/bind9 (change path has you like to not overwrite existing). Jeremy C. Reed ISC___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: rcode 5, refused since upgrade

2011-01-06 Thread Jeremy C. Reed
On Thu, 6 Jan 2011, jim wrote: Upgraded today from BIND 9.2.4 to BIND 9.7.0-P2-RedHat-9.7.0-5.P2.el6_0.1. Pretty much copied the named.conf file from one to the other. We are a slave for a three other sites, two I download the zones OK, one I get REFUSED since the upgrade. Check your BIND

Re: error (broken trust chain) resolving

2010-11-23 Thread Jeremy C. Reed
On Wed, 24 Nov 2010, Brian J. Murrell wrote: Yeah, I was hoping to have caught the attention of a BIND developer here with all of this by now. Perhaps they just don't hang out here. Maybe I will try to find out where to ask questions that they might see. I was reading it all along, but

Re: clarification

2010-10-22 Thread Jeremy C. Reed
On Fri, 22 Oct 2010, rams wrote: I have a record in BIND as follows:   mxdomain.com. 86400 IN MX 65536 gmail.com. How did you get named to load this? If your named does load it, what version of BIND are you using? You should get out of range. (See named-checkzone too.) When I query

Re: rndc.key vs. rndc.conf

2010-10-02 Thread Jeremy C. Reed
On Sat, 2 Oct 2010, online-reg wrote: Hi All: One more conf issue on bind 9.7.1-P2   After running rndc-confgen and reloading BIND I?m getting this error:   WARNING: key file (/etc/namedb/rndc.key) exists, but using default configuration file (/etc/namedb/rndc.conf) rndc: connection to

Re: PKCS#11 engine implementation

2010-03-03 Thread Jeremy C. Reed
On Wed, 3 Mar 2010, Nikolay Elenkov wrote: I've a few question about the PKCS#11 support in BIND 9.7, specifically the OpenSSL engine implementation. Is this the right place to ask? There appears to be no bind-dev mailing list. I see you already asked your question. This list is okay.

Re: no hostname become unresolvable.

2010-02-23 Thread Jeremy C. Reed
@   IN  MX 10   mail.man169.com. Try adding here: @ IN A 202.68.195.36 www IN  A   202.68.195.36___ bind-users mailing list bind-users@lists.isc.org

Re: ISC BIND 9.7.0 syslog recorded notices

2010-02-19 Thread Jeremy C. Reed
On Fri, 19 Feb 2010, ic.nssip wrote: I just installed ISC 9.7.0 on one of our x86 SUN Solaris 10 machines. I did a fresh local compiled install with all default settings. It looks that DNS is working fine for customers (anyway the time is too short to conclude that), but my syslog suddenly

Re: ISC BIND 9.7.0 syslog recorded notices

2010-02-19 Thread Jeremy C. Reed
On Fri, 19 Feb 2010, Jeremy C. Reed wrote: Some loggings maybe could be made more clear, for example: stats.surfaid.ihost.com/ no SOA returned Not sure why I saw that. Looking again I see com. But I have other problems there too. ___ bind

Re: strange problem

2010-02-08 Thread Jeremy C. Reed
Please provide real names. ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Fatal Error in resolver.c

2010-01-21 Thread Jeremy C. Reed
Thank you very much for your bug report. For your information, you can also submit bugs to our bind9-bugs AT isc.org email address. Your issue is now being tracked as ticket # 20923. ___ bind-users mailing list bind-users@lists.isc.org

Re: Poblem with ZONE (subdomain)

2010-01-19 Thread Jeremy C. Reed
On Tue, 19 Jan 2010, Michelle Konzack wrote: Jan 19 18:56:42 samba3 named[18333]: 19-Jan-2010 18:56:42.920 general: error: dns_master_load: /etc/bind/net.tamay-dogan.debian:18: lists.debian.tamay-dogan.net: CNAME and other data See line 18 and then look for lists.

Re: dig query

2010-01-06 Thread Jeremy C. Reed
On Wed, 6 Jan 2010, Michael Sinatra wrote: I tried this out and I noticed that both BIND and unbound appear to behave the same way when using dig in this manner. So both of the major validating implementations support it. I don't see specific reference to using the AD flag in queries in

Re: blockhole'd IP receiving referral?

2009-12-18 Thread Jeremy C. Reed
On Fri, 18 Dec 2009, Len Conrad wrote: dig'ging from a !mynets IP receives a referral to rather than time-out/silence. Please show us. Does dig and tcpdump (or other packet trace) show where the response actually comes from? ___ bind-users mailing

Re: Insecure response BIND 9.7.0b2

2009-11-19 Thread Jeremy C. Reed
On Thu, 19 Nov 2009, David Forrest wrote: Logged: Nov 19 12:13:45 maplepark named[23329]: validating @0x17b7980: dlv.isc.org SOA: got insecure response; parent indicates it should be secure What does this mean? This is documented in the ARM. The parent zone says (published DS) that it

Re: System Resolver Test App?

2009-11-11 Thread Jeremy C. Reed
http://www.reedmedia.net/software/gethost/ ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: multiple internal views not working (requested conf files and logs)

2009-11-02 Thread Jeremy C. Reed
On Mon, 2 Nov 2009, Paul Krash wrote: view internal { zone eng.exegy.net { Do you have anything to match here? By default, match-clients and match-destinations default to matching all addresses (even not internal). So when you reversed, the other view (dot5) would never match

Re: call for testers (Re: ISC BIND 9.7.0b1 is now available)

2009-10-22 Thread Jeremy C. Reed
Possibly also useful to report success here so that many people aren't needlessly repeating the same test. - NetBSD 4.99.62 amd64, gcc 4.1.3 20080202 prerelease (NetBSD nb1 20080202) - NetBSD 5.0.0_PATCH i386, pcc 0.9.9 (HEAD) for i386-unknown-netbsdelf5.0.0.

Re: Problem on CNAME configuration.

2009-10-05 Thread Jeremy C. Reed
On Mon, 5 Oct 2009, Cyril Gaudin - Rodacom wrote: But in my browser, if I write http://myapplication/, the dns request failed. Here is the bind log (192.168.6.28 is my computer): queries: client 192.168.6.28#36728: query: myapplication.home.fr IN A + queries: client 127.0.0.1#56888:

Re: Dig ANY gives SERVFAIL / FORMERR

2009-09-23 Thread Jeremy C. Reed
It looks like that the authoritative name server for youbei.cc actually did return some answers, but somehow bind gave a FORMERR for some unknown reasons, which I think it caused a SERVFAIL to be reported in turn. Interestingly, dig any youbei.cc +trace ran successfully and did not report any

Re: 9.7.0a2 - deny-answer-addresses

2009-08-21 Thread Jeremy C. Reed
On Fri, 21 Aug 2009, clemens fischer wrote: BIND 9.7.0a2 built with '--prefix=/opt/bind/9.7.0a2' '--with-openssl=yes' '--disable-linux-caps' '--sysconfdir=/usr/local/etc' '--localstatedir=/var' 'CFLAGS=-O' Thank you very much for testing the alpha release. deny-answer-addresses {

Re: 9.5.1-P1 to 9.6.1-P1

2009-07-29 Thread Jeremy C. Reed
On Wed, 29 Jul 2009, Sandy Mackenzie wrote: Any known gotcha's for this upgrade? The significant 9.6.0 changes are listed at https://www.isc.org/software/bind/new-features/9.6 The BIND 9.6.1 minor release has numerous improvements especially in portability, documentation, and DNSSEC. The

Re: querylog entries

2009-06-12 Thread Jeremy C. Reed
was in use (E), if DO (DNSSEC Ok) was set (D), or if CD (Checking Disabled) was set (C). Jeremy C. Reed ISC echo ... naq ninvynoyr va cevagrq obbx sbezng. | \ tr noqrsvxyzabcegi abdefiklmnoprtv ___ bind-users mailing list bind-users@lists.isc.org

  1   2   >