Re: DNS format error

2015-07-29 Thread Mukund Sivaraman
On Wed, Jul 29, 2015 at 08:13:38AM +0200, Matus UHLAR - fantomas wrote: On 29.07.15 03:06, Yang Yu wrote: I configured bind to forward queries to 8.8.8.8 do you have any reason to do this? BIND can resolve properly itself, it does not need to forward queries to anyone unless you are

Re: DNS format error

2015-07-29 Thread Mukund Sivaraman
Hi Tony, Yang On Tue, Jul 28, 2015 at 10:41:49PM +0100, Tony Finch wrote: However the weirdness in the NSEC3 record is not what is upsetting BIND, and it might be a bug. A noerror response with just NSEC3 and RRSIG(NSEC3) in the authority section should (I think) be treated as a type 3 nodata

Re: DNS format error

2015-07-29 Thread Tony Finch
Mukund Sivaraman m...@isc.org wrote: Mark pointed out on our internal bug ticket that RFC 2308 section 3 requires no data replies from signed zones to have an SOA RR in the authority section. Aha! Thanks for pointing that out :-) Tony. -- f.anthony.n.finch d...@dotat.at http://dotat.at/

Re: DNS format error

2015-07-28 Thread Tony Finch
Yang Yu yang.yu.l...@gmail.com wrote: the query error log can be replicated with dig www.vip.icann.org ds This sounds like a DNSSEC validation issue, but why would I get DNS format error in the log This is weird and interesting. The name servers for vip.icann.org are doing some kind of

Re: DNS format error

2013-11-11 Thread Tony Finch
Jim Pazarena b...@paz.bz wrote: I see in my logs DNS format error from 205.178.190.53#53 resolving excelwetsuits.com/MX for client 207.34.147.83#54521: invalid response The client is *my* mail server IP. I am wondering is this error on MY side or their's ? Theirs. ; DiG 9.9.4rc1 ns

Re: DNS Format error ...

2012-03-28 Thread Mark Andrews
The problem is that their servers are returning non-authoritative answers from the cache without also adding the NS records for the child zone to allow the interative resolver to find a authoritative answer. The parent server is configured as a recursive server not a authoritative server. On

Re: DNS format error

2010-04-27 Thread Chuck Anderson
On Tue, Apr 27, 2010 at 07:40:20PM -0600, ic.nssip wrote: I hope somebody can tell me why I'm getting so many DNS format error on a DNS Server running BIND 9.7.0 on a Solaris 10 machine. The server is resolving fine queries for normal traffic. Is just syslog that gets tones of messages like

Re: DNS format error

2010-04-27 Thread Mark Andrews
In message 50f2fa04b0ce44d496491214ac8eb...@internal.corp.ds, ic.nssip writ es: Hello everyone, I hope somebody can tell me why I'm getting so many DNS format error = on a DNS Server running BIND 9.7.0 on a Solaris 10 machine. The server is resolving fine queries for normal traffic. Is just