Re: [EXT] ISC BIND 9 breakage?

2020-03-26 Thread Ray Bellis
isc.org zone. More detail to follow tomorrow once I've had some sleep... Ray Bellis Director of DNS Operations, ISC.

Re: ISC BIND 9 breakage?

2020-03-26 Thread Ray Bellis
On 26/03/2020 06:29, Mark Andrews wrote: > There should be a official report sometime tomorrow. Our report is at: <https://lists.isc.org/pipermail/bind-users/2020-March/102828.html> Ray Bellis Director of DNS Operations, ISC.

Re: Anyone else getting the 'spam' bomb threat?

2021-10-19 Thread Ray Bellis
On 19/10/2021 13:29, Travis Garrison wrote: > Yup, same here and here. For now we're just ignoring it, but if anyone wants to quote us (ISC, a DNS root server operator) in the event of law enforcement action please let me know. Ray

Re: [EXTERNAL] Re: Famous operational issues

2021-10-01 Thread Ray Bellis
On 16/02/2021 22:51, Compton, Rich A wrote: > There was the outage in 2014 when we got to 512K routes. > http://www.bgpmon.net/what-caused-todays-internet-hiccup/ There was a similar issue in 1998/9 or so when we got to 64K routes, which broke the routing table index (which defaulted to a

Re: more spaces in PTRs, this time totisp.net

2021-10-22 Thread Ray Bellis
On 22/10/2021 06:39, Owen DeLong via NANOG wrote: > \032 is not a space. > > Decimal 32 (0x20, \040) is a space. > \032 is a Ctrl-Z (26 decimal, 0x1a) In DNS zone files (and dig's presentation format) backslashed numbers are in decimal, not octal - RFC 1035, §5.1. Ray

Zayo contact help?

2022-03-18 Thread Ray Bellis
Hi all, I have transit donated from Zayo at Equinix SV8 (529 Bryant St, Palo Alto) but it's so old that no-one at Zayo appears to know it exists and they can't find records of it. It probably dates to the MFN / Above.net days. If you can assist with discussions about delivery of that

Re: Question re prevention of enumeration with DNSSEC (NSEC3, etc.)

2022-05-07 Thread Ray Bellis
On 07/05/2022 02:18, Mukund Sivaraman wrote: If zone enumeration was not a real concern, NSEC3 would not exist. However, public DNS is a public tree and so we should have limited expectations for hiding names in it. A significant motivation was to help defend database copyright in the

Re: Question re prevention of enumeration with DNSSEC (NSEC3, etc.)

2022-05-07 Thread Ray Bellis
> On 7 May 2022, at 17:37, Mel Beckman wrote: > >  I don’t think copyright can enter into it, by dint of the fact that > registry data, being purely factual and publicly available, cannot be > copyrighted. > > On March 27, 1991, in a case that transformed the nascent online database >

Re: Question re prevention of enumeration with DNSSEC (NSEC3, etc.)

2022-05-08 Thread Ray Bellis
> Is there any case law where someone has asserted a database right for a DNS > zone? > It seems like a rather stupid thing to do. If someone asserted such a > right, I would make sure not to infringe it by ensuring no entries > from that database entered my DNS caches or other software. It

Re: "Hypothetical" Datacenter Overheating

2024-01-16 Thread Ray Bellis
On 16/01/2024 01:32, Mike Hammett wrote: Someone I talked to while on scene today said their area got to 130 and cooked two core routers. We've lost one low-end switch. I'm very glad it wasn't two core routers! We're still looking into what recourse we have against the datacenter operator.

Re: What are these Google IPs hammering on my DNS server?

2023-12-05 Thread Ray Bellis
On 05/12/2023 20:08, Christopher Morrow wrote: is the test framework documented where others could setup/run the test(s)? :) (perhaps for mr hare I mean, or me! :) ) https://github.com/isc-projects/perflab https://www.isc.org/docs/bellis-oarc-perflab.pdf Are the tests for authoritative

Re: What are these Google IPs hammering on my DNS server?

2023-12-05 Thread Ray Bellis
On 05/12/2023 12:29, Michael Hare via NANOG wrote: At quick glance following the ISC link I didn’t see the compute infrastructure [core count] needed to get 1Mpps.  There is an obvious difference between 99% load of ~500rps and 1M, so we can maybe advise to not undersize ADNS if that's an

Re: TFTP over anycast

2024-04-06 Thread Ray Bellis
On 27/02/2024 18:47, William Herrin wrote: Then I'd write a script to monitor the local tftp server and stop frr if it detects any problems with the tftp server. There are other ways to achieve this without actually stopping the routing daemon. We have DNS servers where the anycast

Re: Cogent-TATA peering dispute?

2024-05-18 Thread Ray Bellis
On 18/05/2024 08:38, Bill Woodcock wrote: L-root, ICANN, selective: https://www.dns.icann.org/imrs/ ... So, of the thirteen root nameservers, ten are potentially available for interconnection, and of those, only two, Cogent and ICANN, don’t have open peering policies. IIUC, most of