Re: Request for review of performance advice

2020-07-29 Thread Niall O'Reilly
On 9 Jul 2020, at 21:25, Havard Eidnes via bind-users wrote: > 2e#1) Make sure your UDP socket *receive* buffers are big enough. > If on BSD, monitor for "dropped due to full socket buffers" > count in "netstat -s" output, and tune accordingly. Note that > this may be a symptom

Re: How to set up a dmarc record ?

2019-12-10 Thread Niall O'Reilly
of "_dmarc.pasteur-cayenne.fr", you should put "_dmarc", leaving out ".pasteur-cayenne.fr", just as you did for the DKIM record. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: What is wrong in the view matching below

2019-12-05 Thread Niall O'Reilly
h-clients` specification matches the requesting client; that view is then used. Since you have `match-clients { any; };` in the first view, scanning will stop there. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users t

Re: Regarding named related issue observed with bind 9.11.5-P4 version

2019-04-04 Thread Niall O'Reilly
On 3 Apr 2019, at 10:26, Chandra Rao wrote: > exec /usr/sbin/named -u named -c "/etc/ClusterDNS.conf" -f You may need to use sudo /usr/sbin/named -u named ... or, if you prefer exec sudo /usr/sbin/named -u named ... Best regards, N

Re: rndc and nsupdate failing to work for me

2019-03-14 Thread Niall O'Reilly
to the syntax of some of the configuration statements I needed to use in rndc.conf. I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-user

Re: Help: BIND _ Recursive query

2019-03-04 Thread Niall O'Reilly
On 4 Mar 2019, at 16:20, Paul Kosinski wrote: > provides our users with general caching DNS service for > all other domains. [...] > Its "named.conf" file doesn't list any "forwarders" any more, and > "forward-only" is gone, but it still has a leftover "recursion yes" > clause. Am I correct

Re: Server can not resolve Domain

2019-02-21 Thread Niall O'Reilly
On 21 Feb 2019, at 9:28, Wolfgang Pähler wrote: > The domain is: paehler.coud Zonemaster reports problems with the (currently) delegated name servers. I've put a little more detail in a private message. Best regards, Niall O'Reilly ___ Please vi

Re: How to create an SRV record for the CSTA service

2018-09-13 Thread Niall O'Reilly
On 13 Sep 2018, at 17:03, King, Harold Clyde (Hal) wrote: > _csta._tcp.csta.example.com. 3600 IN SRV 20 0 1040 > hostname.example.com Instead of "hostname.example.com", you need "hostname.example.com.", with a trailing dot. Niall O'Reilly signatur

Re: How to create an SRV record for the CSTA service

2018-09-13 Thread Niall O'Reilly
record For something more formal: https://tools.ietf.org/html/rfc2782 Good luck! Niall O'Reilly signature.asc Description: OpenPGP digital signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailin

Re: DNSSEC and secondary DNS servers

2018-09-08 Thread Niall O'Reilly
On 8 Sep 2018, at 14:58, @lbutlr wrote: > so I think there must be something else. You might need to so some other housekeeping: https://zonemaster.net/domain_check http://dnsviz.net/d/covisp.net/dnssec/ /Niall signature.asc Description: OpenPGP digital signature

Re: slave-not-updated

2018-08-01 Thread Niall O'Reilly
On 1 Aug 2018, at 10:01, Mohammed Ejaz wrote: Is there any way to troubleshoot from the master server why there is no synchnization to one more Slave. Only partly. You may need access to the slave at some stage. Master log should record NOTIFY messages sent to all slaves. If not all desired

Re: Handling expired domains

2018-06-29 Thread Niall O'Reilly
t involve a delay of some, or even many, hours. In any recovery situation, I would be minded to check slave status within a few minutes of restoration of reachability, and to force the master to send NOTIFY messages in case any slaves had not yet resumed service. Niall O'Reilly sign

Re: DNS not resolving on google, but is on other services

2018-02-17 Thread Niall O'Reilly
ervers; in such a case, it seems to give up early and report SERVFAIL. As it happens, there seem to be problems with the set of authority servers involved. You'll find more information at https://zonemaster.fr/test/932ded6946bfebb4 . Best regards, Niall O'Reilly signature.asc Description: O

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-23 Thread Niall O'Reilly
re. Best regards, Niall O'Reilly signature.asc Description: OpenPGP digital signature ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.or

Re: Subdomain DNSSEC

2017-08-28 Thread Niall O'Reilly
NS records as has always been the case. By simply not adding a DS record, you signal an insecure delegation. You may have problems if the two sets of name servers (for parent and child zones) overlap. Best regards, Niall O'Reilly ___ Pl

Re: delegation NS records

2017-07-14 Thread Niall O'Reilly
On 14 Jul 2017, at 14:07, b...@zq3q.org wrote: > only a single **delegation** NS record > needed Actually, there should be two or more, and their IP addresses should belong to different networks. RFC1034, section 4.1: A given zone will be available from several name servers to insure its

Re: "spare hosts" as personal DNS nameservers for 'mynew.org'

2017-07-11 Thread Niall O'Reilly
to fix, right? Short answer: just no. Long answer: not unless either of your servers is providing name service for the zone that the nameserver itself is in. As I understand from your original message, this is not the case, so just no. I hope this helps. With best regards, Niall O'Reilly

Re: "spare hosts" as personal DNS nameservers for 'mynew.org'

2017-07-11 Thread Niall O'Reilly
nameservers.** Any additional related tips appreciated. See above. With best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: DNS and cache-expiration modification

2016-11-18 Thread Niall O'Reilly
On 18 Nov 2016, at 9:24, Job wrote: Do you know if with Bind is possible? Perhaps the configuration option 'max-cache-ttl' is what you're looking for ? Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo

Re: BIND started replying to queries for .com with .COM

2016-04-01 Thread Niall O'Reilly
On 1 Apr 2016, at 11:08, Tony Finch wrote: > Robert Edmonds wrote: >> Tony Finch wrote: >>> Phil Mayers wrote: What is considered the source of the ownername for, say, "com."? >>> >>> It should be the root zone master file. >> >> Why not

Re: unalbe-to-query

2015-12-14 Thread Niall O'Reilly
run a comprehensive series of tests against the zone(s) which are giving you trouble. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Re: subdomain/zone with DHCPD

2015-10-15 Thread Niall O'Reilly
On 15 October 2015 15:56:42 BST, lejeczek wrote: >hi everybody > >I'm trying a bind setup which could be talked to by dhcpd. >I've bind setup with virtual zones and now trying to set up >dhcpd so it would be updating DNS, but... but. > >In dhcpd.conf I'm trying: and

Re: dname reverse delegation

2015-10-13 Thread Niall O'Reilly
RR it expects and > zone file for the 0/24. However I just want to forward this. I'm sorry. I don't understand what you think you're trying to achieve. I hope this helps. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org

Re: problem using setuid ("-u" option) with BIND 9.10.3 on RedHat when listening on tun/tap interface

2015-09-27 Thread Niall O'Reilly
use the "-u" option of > "named" to lower the privileges after launch (requiring native root > privileges to launch), but I can't use both at the same time. > > Can anyone shed any light on this scenario? I'm missing some information which

Re: problem using setuid ("-u" option) with BIND 9.10.3 on RedHat when listening on tun/tap interface

2015-09-27 Thread Niall O'Reilly
it listens on the configured ip's and it changes the > owner of the process to 'incadmin'. This is the "traditional" way to run a reduced-privilege instance of named. I've used it, and I believe it's widely used. Are you sure it's not adequately secure for your needs? B

Re: Multiple A and PTR and the "main" ones?

2015-09-13 Thread Niall O'Reilly
On Fri, 11 Sep 2015 15:54:52 +0100, David Ford wrote: > > [...] satisfy RFC requirements for DNS [...] Would you mind citing? Thanks Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: Issue in calling same zone in more than one VIEW

2015-05-29 Thread Niall O'Reilly
what I should do for getting rid of this issue. You need to use as many copies of each zone file as you have views needing to write to it. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: Issue in calling same zone in more than one VIEW

2015-05-29 Thread Niall O'Reilly
option referencing the first view. I hope this helps. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: Issue in calling same zone in more than one VIEW

2015-05-29 Thread Niall O'Reilly
On Fri, 29 May 2015 11:25:48 +0100, Cathy Almond wrote: From 9.10.0 there is a new zone type 'in-view'. From the release notes: Neat! Thanks and best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo

Re: lists subdomain not fully working [SOLVED]

2015-05-27 Thread Niall O'Reilly
On Wed, 27 May 2015 07:50:12 +0100, Lucio Crusca wrote: I've now fixed the MNAME and I have to wait propagation before testing again, but I'm really confident it will solve the problem, Fammi sapere, per piacere ... Niall ___ Please visit

Re: lists subdomain not fully working

2015-05-25 Thread Niall O'Reilly
need to look for help with analysing it to someone who has access to the name server(s) used by this SMTP server. Either of the users you mention may be able to help. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org

Re: BIND response time is relatively high

2015-01-26 Thread Niall O'Reilly
At Mon, 26 Jan 2015 21:50:37 +, Darcy Kevin (FCA) wrote: The parameter that is glaringly missing from your list is “recursive-clients”. Do you have that set at default value (1000) or have you bumped it up higher? Since you say that this happens at “peak hours”, recursive-clients is

Re: BIND9 Return different IP address based on subnet

2015-01-05 Thread Niall O'Reilly
At Sat, 3 Jan 2015 19:24:47 +0100, Christian Kette wrote: I have found a workaround. I defined a different zone for every network A simpler solution might be to use a sortlist. From the ARM: 6.2.16.13 The sortlist Statement The response to a DNS query may consist of multiple resource

Re: recursive-clients : recommended value for a high traffic recursive nameserver

2014-11-24 Thread Niall O'Reilly
, network problems, or some combination of these. Your logs will help identify which. I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing

Re: recursive-clients : recommended value for a high traffic recursive nameserver

2014-11-24 Thread Niall O'Reilly
, network problems, or some combination of these. Your logs will help identify which. I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing

Re: Digging to the final IP

2014-10-23 Thread Niall O'Reilly
At Thu, 23 Oct 2014 15:17:49 +0100, Sam Wilson wrote: In article mailman.1128.1414072988.26362.bind-us...@lists.isc.org, Bob Harold rharo...@umich.edu wrote: Anytime you see 'grep' and 'cut' used together, they can usually be shortened to just 'awk', which requires starting one less

Re: Digging to the final IP

2014-10-23 Thread Niall O'Reilly
At Thu, 23 Oct 2014 15:17:49 +0100, Sam Wilson wrote: In article mailman.1128.1414072988.26362.bind-us...@lists.isc.org, Bob Harold rharo...@umich.edu wrote: Anytime you see 'grep' and 'cut' used together, they can usually be shortened to just 'awk', which requires starting one less

Re: Digging to the final IP

2014-10-22 Thread Niall O'Reilly
At Tue, 21 Oct 2014 22:31:28 -0500, Frank Bulk wrote: Dave, Thanks for the input, but what I was looking for was a dig command that returns the IP(s) or a fail. It looks like the host command is the right solution in this case, not dig. Doesn't egrep fail on no match? Niall

Re: Does bind read /etc/hosts?

2014-07-15 Thread Niall O'Reilly
, please see http://serverfault.com/questions/498500/why-does-the-host-command-not-resolve-entries-in-etc-hosts Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: How to setup a backup NameServer?

2014-04-29 Thread Niall O'Reilly
At Tue, 29 Apr 2014 10:24:58 +, houguanghua wrote: Yes, I had asked the same question months ago. I'm designing how to protect DNS for an ISP. The zones are not owned by the ISP. The ISP wants to proect the DNS query during attacking. So it's not standard DNS solution. During the

Re: intermittent resolving problem for some domains

2014-02-19 Thread Niall O'Reilly
is giving these messages can reach any of the root servers or even any of the external Internet. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Re: bad owner name - Unable to add forward map from Nintendo Wii U ... REFUSED

2013-12-27 Thread Niall O'Reilly
the configuration of this server, I expect you're in a position to determine what owner name is passed to the DNS server, and that this approach might be what you need. This thread probably belongs better on the dhcp-users list ... Niall O'Reilly ___ Please

Re: missing ‘additional section’

2013-12-19 Thread Niall O'Reilly
On 18 Dec 2013, at 15:19, houguanghua houguang...@hotmail.com wrote: Is there any way to enable the Additional Section? Thanks. The server sends data in the additional section if either (a) these data are required, or (b) the server supports and is configured to send

Re: Recursive DNS server cannot resolve the reverse zone records from my IPv6 private network

2013-11-07 Thread Niall O'Reilly
) in the zone file you're using. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo

Re: use bind 9.8 as caching server and authoritative nameserver

2013-10-30 Thread Niall O'Reilly
-council-shares-its-report-on-dns-based-internet-filtering.html Best regards, Niall O'Reilly Member of AFNIC's Conseil Scientifique PS. I wan't a significant contributor to this report. Credit for that belongs to the colleagues who did the work. /Niall

Re: packet size

2013-09-11 Thread Niall O'Reilly
On 11 Sep 2013, at 17:24, Maria Iano wrote: What does it mean when the edns0 response to a dig says the overall packet size will be one value Not will be one value but can be no more than that value. but the message size reported is different. That's the actual size of the

Re: ISO or virtual appliance

2013-08-22 Thread Niall O'Reilly
www.example.com as a tiny dynamic zone and update it directly. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: BIND 9.8.1-P1: 'make test' fails

2013-08-20 Thread Niall O'Reilly
On 22 Nov 2011, at 11:24, Niall O'Reilly wrote: Since quite a few years, I habitually run 'make test' after building BIND from sources. I'me seiing a failure with 9.8.1-P1, and wonder whether anyone else is also. [By way of putting this to bed, at last ...] Updating

Re: BIND 9.8.1-P1: 'make test' fails

2013-08-20 Thread Niall O'Reilly
On 20 Aug 2013, at 15:08, Chris Buxton wrote: There is a mailing list for Net::DNS. List-Subscribe: https://www.nlnetlabs.nl/mailman/listinfo/net-dns-users, mailto:net-dns-users-requ...@nlnetlabs.nl?subject=subscribe That said, there was a discussion last December about what has changed

Re: Slave not creating/updating zones

2013-07-15 Thread Niall O'Reilly
On 15 Jul 2013, at 12:49, Grace Ingabire wrote: The issue is now resolved, my master was not configured properly! There's something else: LTD.RW seems not to be delegated. The problem seems to be masked from you because this zone and its parent are both hosted on

Re: Reverse address entries

2013-06-28 Thread Niall O'Reilly
On Fri, 28 Jun 2013 13:57:44 -0400 Novosielski, Ryan novos...@umdnj.edu wrote: The short answer is some software once cared. Does it still now, I'm not sure. But we do it. Some still does Niall O'Reilly ___ Please visit https

Re: Some Server not Resolving certain address

2013-04-08 Thread Niall O'Reilly
@127.0.0.1 ... you can be sure that the server on which your shell session is running is the one to which dig sends the query. If this is not what you need, use the address of the server's network interface. ATB Niall O'Reilly

Re: Suspecious DNS traffic

2013-03-25 Thread Niall O'Reilly
, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Blocking private addresses with a optionq

2013-03-14 Thread Niall O'Reilly
On 14 Mar 2013, at 15:57, Chris Buxton wrote: No, I'm pretty sure the OP wants to strip records from responses if the records are A records referring to private address space (RFC 1918). I've no idea how you would do this. Other than separate views, with a trimmed zone in the

Re: Blocking private addresses with a optionq

2013-03-14 Thread Niall O'Reilly
On 14 Mar 2013, at 16:22, Chris Buxton wrote: Well, yes, if the server in question is authoritative for all the data in question. But if it's just a resolver, that may be more difficult. Fair comment. I was (perhaps naïvely) being led by my aversion to open resolvers

Re: BIND9 statistics-server: JSON?

2013-02-15 Thread Niall O'Reilly
On 15 Feb 2013, at 05:57, Jan-Piet Mens wrote: would there be a chance of ISC adding this to stock BIND9? Even better: would ISC take on the work of doing it? ;-) FWIW: +1 /Niall ___ Please visit

Re: what do you use for logging?

2013-01-18 Thread Niall O'Reilly
On 17 Jan 2013, at 20:58, Mike Hoskins (michoski) wrote: Syslog as the default is perfectly fine with us. Please keep that as the default, following the principle of least astonishment. I do also use the rotated file method a few places, so hoping that doesn't disappear.

Re: what do you use for logging?

2013-01-18 Thread Niall O'Reilly
On 18 Jan 2013, at 06:27, Jan-Piet Mens wrote: Could CLI utility be man(1) and info(1)? :-) It could, yes, but `b10-msg NNN` isn't going to break BIND 10's development budget (I hope), +1 and I feel it to be more practical than scrolling through a man page with 900+

Re: what do you use for logging?

2013-01-18 Thread Niall O'Reilly
? Definitely. Do any packagers provide a configuration with different-than-default logging setup? (What and why?) I'm sorry; I don't know. Apart from one exceptional NetBSD box, I always build from source and avoid whatever the packager offers. Best regards Niall

Re: Update view without using 2 ip for each DNS Server

2012-12-04 Thread Niall O'Reilly
The example in the last one is extracted from a live configuration which I'm responsible for. Best regards, Niall O'Reilly University College Dublin IT Services ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: dhcpd

2012-10-19 Thread Niall O'Reilly
instead of BOOTP. Jim Glassford's suggestion seems good enough to me. On 18 Oct 2012, at 14:28, Jim Glassford wrote: We just continue to deny bootp for subnets that have no need for it and ignore them. Best regards, Niall O'Reilly University College Dublin

RH release selection (was: Moving from type forward to type static-stub)

2012-09-21 Thread Niall O'Reilly
On 21 Sep 2012, at 08:55, Adam Tkac wrote: Because rc2 was released too late to get it into RHEL 6.3... Btw which is the bug that bothers you? Why don't you report it to RH bugzilla? I don't understand why RH would choose to include a release candidate rather than a stable

Re: question about how a particular dig works ...

2012-09-18 Thread Niall O'Reilly
On 18 Sep 2012, at 14:45, M. Meadows wrote: dig www.careerone.com.au +short @8.8.8.8 www.careerone.com.au.edgesuite.net. a903.g.akamai.net. 208.44.23.99 208.44.23.121 Why does the above dig work when If you try dig +trace www.careerone.com.au you'll find that the

Re: ho to filter hundeds of domains ?

2012-08-30 Thread Niall O'Reilly
resources to chasing a moving target. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: SRV query with no domain?

2012-08-16 Thread Niall O'Reilly
On 16 Aug 2012, at 15:42, Christopher Cain wrote: Of course a dig query will fail without the domain appended. Dig takes you query at face value and will not append domains from your search suffix list like nslookup and ping will. You ALWAYS have to fully qualify your requests when using

Re: recursive-clients recommended values

2012-07-12 Thread Niall O'Reilly
. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Basic scope question

2012-07-10 Thread Niall O'Reilly
On 10/07/12 18:07, Bennett, Gary L. wrote: No, have that part. Was just wondering which domain-name-servers parm, global or in DHCP address pool, has precedence. Thanks. The more specific specific over-rides the global one. Niall O'Reilly

Re: Several (2) different views [SOLVED]

2012-07-09 Thread Niall O'Reilly
On 3 Jul 2012, at 21:21, Rodrigo Renie Braga wrote: Just giving a feedback, this method worked great, but in my case, didn't have no negate the keys in the ACL (like the example below), I created one key for each ACL in my configuration and used that ACL for the match-clients directive in

Several (2) different views

2012-06-15 Thread Niall O'Reilly
captive view internal { match-clients { internal-clients; }; // view details go here ... }; // standard view: 'general' view general { match-clients { any; }; // view details go here ... }; I hope this helps. Niall O'Reilly

Re: Transfer the same zone from a split-view master

2012-06-06 Thread Niall O'Reilly
expected to happen, and what actually happened. People won't help unless they believe you're making a serious effort; so far, you haven't sent anything which might convince them. Best regards, Niall O'Reilly University College Dublin

Re: erros in logs

2012-05-10 Thread Niall O'Reilly
expect to see these all the time when you run a resolver. There are broken and misconfigured servers out there! I hope this helps. Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users

Re: Restricting access keeping identical data across views

2012-03-28 Thread Niall O'Reilly
to contributing some effort to such a project. ATB Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman

Re: Restricting access keeping identical data across views

2012-03-28 Thread Niall O'Reilly
. The devil is in the details, which I'll spare you! 8-) Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org

Re: Master/slave configuration

2012-03-08 Thread Niall O'Reilly
On 8 Mar 2012, at 02:58, Lyle Giese wrote (on bind-users): On linux boxes, adding options rotate to the /etc/resolv.conf helps. [cross-posted, reply-to header set] Is there a DHCP option which expresses that, and which typical fielded DHCP clients will respect?

Re: State diagram for DNSsec key lifecycle

2012-02-10 Thread Niall O'Reilly
regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Permissions change after running dnssec-settime bind 9.9.0rc2

2012-02-01 Thread Niall O'Reilly
On 1 Feb 2012, at 09:52, Phil Mayers wrote: As is probably obvious, I consider it an irritating bug ;o) +1 Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: BIND 9.8.1-P1: 'make test' fails

2011-11-28 Thread Niall O'Reilly
On 22/11/11 18:10, /dev/rob0 wrote: Is this a manifestation of the same issue as brought up last week? https://lists.isc.org/pipermail/bind-users/2011-November/085593.html I don't think so. I can compile without problem. I see a failure during 'make test' processing, and

BIND 9.8.1-P1: 'make test' fails

2011-11-22 Thread Niall O'Reilly
Since quite a few years, I habitually run 'make test' after building BIND from sources. I'me seiing a failure with 9.8.1-P1, and wonder whether anyone else is also. Relevant log fragment is shown below. /Niall S:xfer:Tue Nov 22 11:12:07 GMT 2011

Re: I can dig a domain but named won't resolve it.

2011-09-22 Thread Niall O'Reilly
packet capture to find out what's not happening. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Re: I can dig a domain but named won't resolve it.

2011-09-22 Thread Niall O'Reilly
. You might find https://www.dns-oarc.net/oarc/services/porttest an interesting read. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: Delegation check failed

2011-09-21 Thread Niall O'Reilly
Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Delegation check failed

2011-09-21 Thread Niall O'Reilly
for clarifying, Kevin. I hadn't tried the Undelegated domain test until just now. I see. Best rregards Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users

Re: Problems with nic.it

2011-09-20 Thread Niall O'Reilly
this helps. Best regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: How to Setup a Name Servers visible on Internet?

2011-06-21 Thread Niall O'Reilly
name servers. If you think you've already done this, you should look for a spelling error or an omitted dot. Kind regards, Niall O'Reilly ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: AW: ipv6 PTR in zone file

2011-04-12 Thread Niall O'Reilly
pint $foo-reverse_ip() 2.4.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. pint ^D dhcp-c101a88b(niall)6: Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org

Re: About name servers registration

2011-03-10 Thread Niall O'Reilly
On 10 Mar 2011, at 08:44, Torinthiel wrote: Bujt the procedure still is same. A solution (not necessarilty better) involving less typing would be dig +trace dnsbed.com ns /Niall ___ bind-users mailing list

Re: failed multi-view zone transfer

2011-01-26 Thread Niall O'Reilly
On 22 Jan 2011, at 18:29, jeffreyp wrote: it's the transfers that are not happening. and, specifically, just the transfers of the internal view to the slave on the different subnet. You've mentioned that the slave receives and logs the NOTIFY. Do you see it (trying to) start

Re: check the master/slave status

2011-01-07 Thread Niall O'Reilly
are excellent. Either of these will give you some ideas about what to include in the script you want to write. Have fun! Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo

Re: nslookup Got recursion not available from... trying next server

2011-01-05 Thread Niall O'Reilly
. As it happens, 'dig' also makes a recursive query by default, although it's easy to tell it not to. Besides, 'dig' just shows the flags; it doesn't convert them into potentially disturbing messages. I hope this helps. Best regards, Niall O'Reilly

Re: bind slave not get DNS update

2011-01-05 Thread Niall O'Reilly
on the NOTIFY. That should make it clear what's not happening without manual intervention. Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Dynamic DNS with secondary nameserver?

2010-12-01 Thread Niall O'Reilly
Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: DNS Redundancy

2010-10-21 Thread Niall O'Reilly
when you take one of your authoritative servers down. Best regards, Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Multiple masters and multiple TSIG keys

2010-09-29 Thread Niall O'Reilly
On 29 Sep 2010, at 09:34, Anand Buddhdev wrote: Now, I have been given 2 keys, t1 and t2, to use for transferring z1 and z2 respectively. [Wandering off topic, perhaps] That seems to me a back-to-front way to do things. If the organization running the master is

Re: Multiple masters and multiple TSIG keys

2010-09-29 Thread Niall O'Reilly
On 29 Sep 2010, at 15:53, Anand Buddhdev wrote: Anyway, I discussed this with my colleague here, and we came up with a solution that works. We have created 2 views of the master name servers: Nice one, and useful to have in the mailing-list archive! /Niall

Re: recursing stop at about 1000 clients

2010-07-15 Thread Niall O'Reilly
, or other sources of information. I hope this helps. Niall O'Reilly ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: why dig +trace does not working?

2010-06-14 Thread Niall O'Reilly
, which isn't authoritative for the zone of interest, so dig follows the referral chain until it arrives at ns2.dns-diy.com, which is also authoritative, and so provides dig with the result you asked for. I hope this helps. Best regards Niall

Re: why dig +trace does not working?

2010-06-14 Thread Niall O'Reilly
; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 ;; WARNING: recursion requested but not available [SNIP] Se last line. Ehm, no. With +trace, dig doesn't request recursion, but takes control of following the referral chain itself. Best regards Niall

Re: Loopback alias

2010-03-04 Thread Niall O'Reilly
sudo bin/tests/system/ifconfig.sh down I hope this helps. Best regards, Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind

Re: AW: Disabling recursion causes browser hangs on clients with auto proxy config

2010-01-25 Thread Niall O'Reilly
names for which your name server is authoritative; likewise for more lines with subnets. Best regards, Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https

Re: Strange CNAME issue

2010-01-20 Thread Niall O'Reilly
, Niall O'Reilly University College Dublin IT Services ___ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

  1   2   >