Re: New warning message...

2013-07-22 Thread Noel Butler
On Mon, 2013-07-22 at 02:51 -0400, Jason Hellenthal wrote: It's exactly as it says... Instead of ... TXT SPF ... You now do ... SPF SPF ... Mark Andrews wrote: No. It has a legacy SPF TXT record. It SHOULD have record of type SPF as per RFC 4408. Named will complain if

Re: New warning message...

2013-07-22 Thread Jason Hellenthal
Basically a SPF record type in place that's new but you could carry both for new and older clients. -- Jason Hellenthal Inbox: jhellent...@dataix.net Voice: +1 (616) 953-0176 JJH48-ARIN On Jul 22, 2013, at 0:48, SH Development listacco...@starionline.com wrote: I just started noticing

Re: New warning message...

2013-07-22 Thread G.W. Haywood
Hi there, On Mon, 22 Jul 2013, Jason Hellenthal wrote: It's exactly as it says... Instead of ... TXT SPF ... You now do ... SPF SPF ... Caution! The SPF record type is near enough dead. See in particular RFC6686 paragraph 5.6; paragraph 6.2; and Appendix A point 4. -- 73, Ged.

Re: resolving-problem

2013-07-22 Thread LiuGN
On 07/21/13 17:55, Ejaz wrote: I have similar problem recently. Ejaz, I think your server can resolve the domain name correctly because it's resolv.conf set to a public dns server, try to resolve by itself and see what happen. About two month ago, my dns server have the similar problem on

Re: New warning message...

2013-07-22 Thread Matus UHLAR - fantomas
On Mon, 22 Jul 2013, Jason Hellenthal wrote: It's exactly as it says... Instead of ... TXT SPF ... You now do ... SPF SPF ... On 22.07.13 11:26, G.W. Haywood wrote: Caution! The SPF record type is near enough dead. See in particular RFC6686 paragraph 5.6; paragraph 6.2; and Appendix A

NAMED LOGS

2013-07-22 Thread Grace Ingabire
Dear Team, Does anyone know what is going on here? As I can't understand why we do receive a lot of these messages in our logs. Jul 22 14:18:21 ns1 named[13045]: client 200.222.123.108#43576: query (cache) 'www.minghui.org.s210.ip4.verteiltesysteme.net/A/IN' denied Jul 22 14:18:21 ns1

Re: NAMED LOGS

2013-07-22 Thread Steven Carr
It looks like those clients are trying to query your DNS server for www.minghui.org.s210.ip4.verteiltesysteme.net and are being denied. Steve On 22 July 2013 13:21, Grace Ingabire grac...@ricta.org.rw wrote: Dear Team, ** ** Does anyone know what is going on here? As I can’t

Re: New warning message...

2013-07-22 Thread Barry S. Finkel
This was discussed here already, and imho this is anti-spf bullshit like all those spf breaks forwarding FUD. The SPF RR is already here and is preferred over TXT that is generik RR type, unlike SPF. It is not Fear, Uncertainty, and Doubt that SPF breaks forwarding. SPF *DOES* break

Re: NAMED LOGS

2013-07-22 Thread LiuGN
On 07/22/13 20:21, Grace Ingabire wrote: Dear Team, Does anyone know what is going on here? As I cant understand why we do receive a lot of these messages in our logs. Jul 22

Re: NAMED LOGS

2013-07-22 Thread Barry S. Finkel
Date: Mon, 22 Jul 2013 14:21:51 +0200 From: Grace Ingabiregrac...@ricta.org.rw Dear Team, Does anyone know what is going on here? As I can't understand why we do receive a lot of these messages in our logs. Jul 22 14:18:21 ns1 named[13045]: client 200.222.123.108#43576: query (cache)

IPv4 not working reverse on /24 cidr

2013-07-22 Thread Ryan Pavely
Ok. What am I doing wrong? As far as I know this has worked for years and sometime, weeks, months, years, ago it stopped. This is for doing /24 (greater in cidr smaller in size) Example: we have a /25 that we host... and another /25 we host.. so we split it up into smaller files unless we

Re: IPv4 not working reverse on /24 cidr

2013-07-22 Thread Barry Margolin
In article mailman.877.1374504592.20661.bind-us...@lists.isc.org, Ryan Pavely para...@nac.net wrote: Ok. What am I doing wrong? As far as I know this has worked for years and sometime, weeks, months, years, ago it stopped. This is for doing /24 (greater in cidr smaller in size)

Re: IPv4 not working reverse on /24 cidr

2013-07-22 Thread David Forrest
On Mon, 22 Jul 2013, Ryan Pavely wrote: Ryan Pavely Net Access Corporation http://www.nac.net/ So that would suggest any time any block a /24 is hosted you must actually host the parent zone, pointing to the larger cidr, and then have your normal files for each cider in that block.

Re: IPv4 not working reverse on /24 cidr

2013-07-22 Thread Ryan Pavely
Ryan Pavely Net Access Corporation http://www.nac.net/ On 7/22/2013 11:00 AM, Barry Margolin wrote: In article mailman.877.1374504592.20661.bind-us...@lists.isc.org, Ryan Pavely para...@nac.net wrote: Ok. What am I doing wrong? As far as I know this has worked for years and

Re: New warning message...

2013-07-22 Thread Barry Margolin
In article mailman.881.1374508134.20661.bind-us...@lists.isc.org, Matus UHLAR - fantomas uh...@fantomas.sk wrote: This was discussed here already, and imho this is anti-spf bullshit like all those spf breaks forwarding FUD. The SPF RR is already here and is preferred over TXT that is generik

Re: IPv4 not working reverse on /24 cidr

2013-07-22 Thread Barry Margolin
In article mailman.879.1374506938.20661.bind-us...@lists.isc.org, Ryan Pavely para...@nac.net wrote: So that would suggest any time any block a /24 is hosted you must actually host the parent zone, pointing to the larger cidr, and then have your normal files for each cider in that block.

Re: IPv4 not working reverse on /24 cidr

2013-07-22 Thread Matus UHLAR - fantomas
On 22.07.13 12:29, Ryan Pavely wrote: I always thought I had to break up the CIDR's into the proper blocks so then my downstream customer can slave that partial zone. I don't want them slaving 10.10.1/24... etc.. So to do that you break up the block into all its parts, each with an origin,

Re: IPv4 not working reverse on /24 cidr

2013-07-22 Thread Ryan Pavely
I only mentioned rfc1918 as I am directly hosting them, versus my upstream pointing cnames at me for other blocks. I didn't expect anything different about them. I thought, and it worked in the past (2008/2009 perhaps), that having the full cidr notation and such in the named.conf files you

Re: New warning message...

2013-07-22 Thread Barry S. Finkel
On 7/22/2013 11:17 AM, bind-users-requ...@lists.isc.org wrote: This was discussed here already, and imho this is anti-spf bullshit like all those spf breaks forwarding FUD. The SPF RR is already here and is preferred over TXT that is generik RR type, unlike SPF. On 22.07.13 08:50, Barry S.

Question about cache reload

2013-07-22 Thread Stanley Weilnau
I have just set up DNSSEC on bind 9.9.3. I had set up the zone and put a DS record out at the registrar. Several days later I found that I had set up the keys incorrectly using only NSEC verses NSEC3 so i changed the keys. I deleted the old keys and DS record, and had bind resign everything

Re: New warning message...

2013-07-22 Thread Chris Buxton
On Jul 22, 2013, at 1:24 PM, Barry S. Finkel bsfin...@att.net wrote: On 7/22/2013 11:17 AM, bind-users-requ...@lists.isc.org wrote: This was discussed here already, and imho this is anti-spf bullshit like all those spf breaks forwarding FUD. The SPF RR is already here and is preferred over

Re: NAMED LOGS

2013-07-22 Thread Mark Andrews
s210.ip4.verteiltesysteme.net has been delegated to you. See the address records in the referral. Complain to the parent zone administrators if this is in error otherwise configure your system to serve s210.ip4.verteiltesysteme.net. P.S. It would

Re: New warning message...

2013-07-22 Thread Noel Butler
On Mon, 2013-07-22 at 08:50 -0500, Barry S. Finkel wrote: This was discussed here already, and imho this is anti-spf bullshit like all those spf breaks forwarding FUD. The SPF RR is already here and is preferred over TXT that is generik RR type, unlike SPF. It is not Fear, Uncertainty,

Re: NAMED LOGS

2013-07-22 Thread Matthäus Wander
Hi, Grace Ingabire writes: Does anyone know what is going on here? As I can't understand why we do receive a lot of these messages in our logs. Jul 22 14:18:21 ns1 named[13045]: client 200.222.123.108#43576: query (cache) 'www.minghui.org.s210.ip4.verteiltesysteme.net/A/IN' denied [...]

Re: Question about cache reload

2013-07-22 Thread Mark Andrews
In message c27f9adb-21a3-445d-87bc-a97374e62...@cnri.reston.va.us, Stanley We ilnau writes: I have just set up DNSSEC on bind 9.9.3. I had set up the zone and put a DS record out at the registrar. Several days later I found that I had set up th e keys incorrectly using only NSEC verses

Re: NAMED LOGS

2013-07-22 Thread Mark Andrews
In message 51edcfad.5030...@uni-due.de, =?ISO-8859-15?Q?Matth=E4us_Wander?= w rites: Hi, Grace Ingabire writes: Does anyone know what is going on here? As I can't understand why we do receive a lot of these messages in our logs. Jul 22 14:18:21 ns1 named[13045]: client

Re: NAMED LOGS

2013-07-22 Thread Matthäus Wander
* Mark Andrews [2013-07-23 03:36]: How do you do that with a broken delegation? Did you think to ask before delegating a zone to a zone not configured for it? What does your Chancellor think about using uninformed third parties for experiments like this? The method is described here

Re: NAMED LOGS

2013-07-22 Thread Mark Andrews
In message 51ede640.8040...@uni-due.de, =?ISO-8859-15?Q?Matth=E4us_Wander?= w rites: * Mark Andrews [2013-07-23 03:36]: How do you do that with a broken delegation? Did you think to ask before delegating a zone to a zone not configured for it? What does your Chancellor think about using

Can I change the zone file from command line?

2013-07-22 Thread Manish Rane
Hi Folks, Wondering if I can edit/change the static zone file as a result of certain bash script. Well, I am trying to write a script which will monitor the server on certain ports and it if fails to connect to the server it will delete or add the entry from zone file so that traffic will be

Re: Can I change the zone file from command line?

2013-07-22 Thread Mihamina Rakotomandimby
Hello, I did not catch what you're trying to achieve. Please give more details. On 2013-07-23 08:25, Manish Rane wrote: Hi Folks, Wondering if I can edit/change the static zone file as a result of certain bash script. Well, I am trying to write a script which will monitor the server on

Re: Can I change the zone file from command line?

2013-07-22 Thread Mike Hale
This seems pretty straight forward. Use your standard bash tools to modify the file when necessary, then you should simply be able to call rndc reload ZONENAME in the script. On Mon, Jul 22, 2013 at 10:28 PM, Mihamina Rakotomandimby miham...@rktmb.org wrote: Hello, I did not catch what you're