[Pdns-users] PowerDNS Authoritative Server 4.9.1

2024-05-28 Thread Peter van Dijk via Pdns-users
Hello! This is release 4.9.1 of the Authoritative Server. It contains a collection of small fixes.  A detailed list of changes can be found in the [1]changelog. Please make sure to read the [2]Upgrade Notes before upgrading. If you install (not upgrade to) this version on Debian or Ubuntu,

[Pdns-users] PowerDNS Recursor Security Advisory 2024-02: if recursive forwarding is configured, crafted responses can lead to a denial of service in Recursor

2024-04-24 Thread Peter van Dijk via Pdns-users
Dear user, Please find below a security advisory, relating to PowerDNS Recursor 4.8.7, 4.9.4 and 5.0.3 only. When using recursive forwarding, a crafted response from an upstream server can cause a Denial of Service in the Recursor.

[Pdns-users] PowerDNS Authoritative Server 4.9.0

2024-03-15 Thread Peter van Dijk via Pdns-users
Hello! This is release 4.9.0 of the Authoritative Server. It brings a few new features, and a collection of small improvements and fixes. Some internals have been reworked to support the new features. A detailed list of changes can be found in the [1]changelog. Please make sure to read the

[Pdns-users] PowerDNS Authoritative Server 4.9.0-beta2

2024-02-16 Thread Peter van Dijk via Pdns-users
Hello! This is release 4.9.0-beta2 (beta1 was not released, due to a tagging mistake) of the Authoritative Server. It brings a few new features, and a collection of small improvements and fixes. Some internals have been reworked to support the new features. A detailed list of changes can be found

Re: [Pdns-users] PowerDNS Authoritative Server 4.9.0-alpha1

2024-01-12 Thread Peter van Dijk via Pdns-users
On Fri, 2024-01-12 at 14:13 +0100, Peter van Dijk via Pdns-announce wrote: > https://doc.powerdns.com/authoritative/changelog/4.8.html#change-4.9.0-alpha1 This, of course, should be https://doc.powerdns.com/authoritative/changelog/4.9.html#change-4.9.0-alpha1 Thanks to Frank Louwers for

[Pdns-users] PowerDNS Authoritative Server 4.9.0-alpha1

2024-01-12 Thread Peter van Dijk via Pdns-users
Hello! This is release 4.9.0-alpha1 of the Authoritative Server. It brings a few new features, and a collection of small improvements and fixes. Some internals have been reworked to support the new features. A detailed list of changes can be found in the [4]changelog. If you install (not

Re: [Pdns-users] URL redirect with PDNS Authoritative

2024-01-12 Thread Peter van Dijk via Pdns-users
On Fri, 2024-01-12 at 10:25 +0100, Peter van Dijk via Pdns-users wrote: > If you want to build this feature, and keep all data in one place (the > PowerDNS database), you could use disabled=1 records with some convenient > type (TXT, URI, etc.) that your webservice can look up. You could

Re: [Pdns-users] URL redirect with PDNS Authoritative

2024-01-12 Thread Peter van Dijk via Pdns-users
On Fri, 2024-01-12 at 09:42 +0100, Andrea Biancalani via Pdns-users wrote: >  is there any way to set a record in PDNS authoritative server that > allow web URL redirect? Not really. >  Example: example.com IN WR https://example.net/subpage/... > >  Reading official documentation, WR record

[Pdns-users] PowerDNS Authoritative Server 4.8.4

2023-12-21 Thread Peter van Dijk via Pdns-users
Hello! This is the release of Authoritative Server 4.8.4. In Authoritative Server 4.8, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay extra

[Pdns-users] package build instructions (was: Re: PDNS repos request)

2023-10-09 Thread Peter van Dijk via Pdns-users
On Thu, 2023-10-05 at 17:45 +0200, Peter van Dijk via Pdns-users wrote: > On Tue, 2023-10-03 at 20:38 +0300, Alex Pavlov via Pdns-users wrote: > > Hello To all PDNS admins, > >   > > Recently the  older PDNS repos were deleted from official PDNS Repo > > website. >

Re: [Pdns-users] PDNS repos request

2023-10-05 Thread Peter van Dijk via Pdns-users
On Tue, 2023-10-03 at 20:38 +0300, Alex Pavlov via Pdns-users wrote: > Hello To all PDNS admins, >   > Recently the  older PDNS repos were deleted from official PDNS Repo > website. > The distros for Ubuntu 16.x (Xenial) and 18.x (Bionic) were wiped out > without any link to “archives” or “old

[Pdns-users] PowerDNS Authoritative Server 4.8.3

2023-10-05 Thread Peter van Dijk via Pdns-users
Hello! This is the release of Authoritative Server 4.8.3. In Authoritative Server 4.8, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay extra

[Pdns-users] delivery problems for mailman.powerdns.com

2023-09-07 Thread Peter van Dijk via Pdns-users
Hello dear readers, recently, mailman.powerdns.com ended up listed on a few RBLs. This caused a lot of email to bounce, and eventually Mailman unsubscribed many people from pdns-users. We have requested delisting where we could find URLs to do so, and hope that the situation will improve. If you

[Pdns-users] PowerDNS Authoritative Server 4.8.2

2023-09-07 Thread Peter van Dijk via Pdns-users
Hello! This is the release of Authoritative Server 4.8.2. In Authoritative Server 4.8, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay extra

[Pdns-users] PowerDNS Authoritative Server 4.8.1

2023-07-07 Thread Peter van Dijk via Pdns-users
Hello! This is the release of Authoritative Server 4.8.1. In Authoritative Server 4.8, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay extra

Re: [Pdns-users] Unable to edit domainmetadata with API

2023-07-03 Thread Peter van Dijk via Pdns-users
On Fri, 2023-06-30 at 17:25 +0530, Shailendra Gautam via Pdns-users wrote: > Hi,  > > I'd like to edit the domain metadata SOA-EDIT-API to EPOCH but the API > doesn't allow it, however I can edit SOA-EDIT kind. Is that a bug? Both items are available on the Zone object -

[Pdns-users] First Release Candidate of PowerDNS Recursor 4.9.0

2023-06-15 Thread Peter van Dijk via Pdns-users
We are proud to announce the first release candidate of PowerDNS Recursor 4.9.0. Compared to the previous major (4.8) release of PowerDNS Recursor, this release contains the following major changes: * The performance impact of metrics collection has been reduced by using lock-free non-atomic

[Pdns-users] NOTE! debian/ubuntu package signing keys need to be refreshed

2023-06-08 Thread Peter van Dijk via Pdns-users
As several people noted on this list and on https://github.com/PowerDNS/pdns/issues/12894, we let our release signing keys expire. I have now extended the expiry by 3 years and we will deploy a more robust solution before -that- time passes. You can either redownload the keys from the same

[Pdns-users] PowerDNS Authoritative Server 4.8.0, with Lightning Stream support

2023-06-01 Thread Peter van Dijk via Pdns-users
Hello! This is the release of Authoritative Server 4.8.0. In Authoritative Server 4.8, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay extra

[Pdns-users] Authoritative Server 4.8.0-beta1, with Lightning Stream support

2023-05-04 Thread Peter van Dijk via Pdns-users
Hello! This is the first Beta release for Authoritative Server 4.8.0. In Authoritative Server 4.8, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay

Re: [Pdns-users] order of Comments in the MySQL-Backend

2023-04-26 Thread Peter van Dijk via Pdns-users
Hello Markus, On Thu, 2023-04-20 at 12:48 +, Markus Ehrlicher via Pdns-users wrote: > Hello together, > > I’m not sure, if this is a real problem or my thinking is wrong in this > case, so I will try to describe as best as possible ;) > > We’re currently using PDNS Auth-Servers in version

[Pdns-users] PowerDNS Authoritative Server 4.7.4

2023-04-17 Thread Peter van Dijk via Pdns-users
Hello, This is the release of version 4.7.4 of the Authoritative Server. It contains various bug fixes, some performance improvements, and one new feature (pdnsutil list-member-zones). A full list of changes can be found in the [1]changelog. Please make sure to read the [2]Upgrade Notes

Re: [Pdns-users] Rcode 3 NXDOMAIN for existing CNAME

2023-03-22 Thread Peter van Dijk via Pdns-users
On Tue, 2023-03-21 at 16:57 +0100, Peter Thomassen via Pdns-users wrote: > Well, if you ask for the xNAME (e.g. CNAME) record, then you'll get that > (with a NOERROR code). So by issuing an xNAME query in addition to the record > type you're interested in, you can learn whether the NXDOMAIN is

[Pdns-users] Authoritative Server 4.8.0-alpha1, with Lightning Stream support

2023-03-21 Thread Peter van Dijk via Pdns-users
Hello! This is the first Alpha release for Authoritative Server 4.8.0. In this release, the LMDB backend gains a new Lightning Stream-compatible schema, which requires a data migration (this is automatic, and there is no migration back to the old schema). LMDB backend users should pay extra

Re: [Pdns-users] pdns_recursor issue

2023-01-26 Thread Peter van Dijk via Pdns-users
Hi Arien, On Thu, 2023-01-26 at 13:30 +0100, Arien Vijn via Pdns-users wrote: > Greetings, > > We recently upgraded pdns_recursor from version 4.4.5 to 4.8.0. It seems that > we run in into the following issue ever since. > > 1/ Client queries for an A-record for xdsl-serviceweb.kpn.com. > 2/

Re: [Pdns-users] Reloading metadata with bind-backend & sqlite

2023-01-12 Thread Peter van Dijk via Pdns-users
On Mon, 2022-12-19 at 14:29 +0100, Thib D via Pdns-users wrote: > Hi, > > Apologies for the misunderstanding, > > I was mentioning this warning from the pdns docs, but I'm not sure this > also applies to bind-backend + sqlite setups:  > > It is not possible to replace the sqlite3 database file

[Pdns-users] PowerDNS Authoritative Server 4.5.5, 4.6.4 and 4.7.3 Released

2022-12-09 Thread Peter van Dijk via Pdns-users
Hello, Today we have released maintenance updates of PowerDNS Authoritative Server 4.5.5, 4.6.4 and 4.7.3, containing fixes for a few minor issues. For more details on the other fixes, consult the changelogs available at [1]4.5.5, [2]4.6.4, [3]4.7.3. The source tarballs ([4]4.5.5, [5]4.6.4,

[Pdns-users] FOSDEM 2023 DNS Devroom Call for Presentations

2022-11-16 Thread Peter van Dijk via Pdns-users
Hello DNS enthusiasts and other developers, After three earlier successful and packed DNS devrooms at FOSDEM 2018, 2019, and 2020, we are happy to announce a half-day DNS devroom at FOSDEM 2023. As with the previous events, we hope to host talks anywhere from hardcore protocol stuff, to

[Pdns-users] dnsdist 1.7.3 released

2022-11-02 Thread Peter van Dijk via Pdns-users
Hello! We are very happy to release dnsdist 1.7.3 today, a maintenance release with no functional changes. This release strictly serves to bring dnsdist packages to our EL9 and Ubuntu Jammy repositories, and upgrades the dnsdist Docker image from Debian buster to Debian bullseye, as buster is

[Pdns-users] PowerDNS Authoritative Server 4.7.2

2022-11-01 Thread Peter van Dijk via Pdns-users
Hello, This is the release of version 4.7.2 of the Authoritative Server. Just one day after releasing version 4.7.1, we realised an important fix was missing from it. Specifically, AXFR clients (secondaries) can get very busy checking for updates on primaries, or could miss updates entirely.

[Pdns-users] [Pdns-announce] PowerDNS Authoritative Server 4.7.1

2022-10-31 Thread Peter van Dijk via Pdns-users
Hello, This is the release of version 4.7.0 of the Authoritative Server. After 4.7.0 (quite recently) was released, we realised the SQL schema update files were missing. 4.7.1 corrects this. It also contains a few small fixes in the catalog zones implementation. A full list of changes can be

Re: [Pdns-users] NXDOMAIN for noon authoritative zone

2022-10-28 Thread Peter van Dijk via Pdns-users
Hello Riccardo, On Fri, 2022-10-28 at 14:37 +, Riccardo Brunetti via Pdns-users wrote: > Thanks for your answer. > Maybe I found the issue: > > mysql> select * from records where domain_id=13203; > +--+---+--+--+- >

Re: [Pdns-users] NXDOMAIN for noon authoritative zone

2022-10-28 Thread Peter van Dijk via Pdns-users
Hi Riccardo, On Fri, 2022-10-28 at 09:11 +, Riccardo Brunetti via Pdns-users wrote: > Hello. > We have a powerdns server which is authoritative for some zones, let's > say zoneA and zoneB > If we send a dns query for a zoneC we get NXDOMAIN answer instead of > REFUSED. > > Is this the

[Pdns-users] PowerDNS Authoritative Server 4.7.0

2022-10-20 Thread Peter van Dijk via Pdns-users
Hello, This is the release of version 4.7.0 of the Authoritative Server. 4.7.0 brings support for [1]Catalog Zones, developed by Kees Monshouwer. As part of that development, the freshness checks in the Primary code were reworked, reducing them from doing potentially thousands of SQL queries (if

Re: [Pdns-users] pdns-recursor (4.6) empty response after expiration of the TTL of the cached record

2022-10-07 Thread Peter van Dijk via Pdns-users
On Thu, 2022-09-22 at 09:27 +0200, Leeflangetje via Pdns-users wrote: > dig @ns1 riecis.nl A If you happen to have a contact at RIEC/riecis, please point them to https://www.sidn.nl/nieuws-en-blogs/agressief-cache-gebruik-levert-snelheidswinst-en-efficientie-op-voor-validerende-resolvers The

[Pdns-users] First release candidate for PowerDNS Authoritative Server 4.7.0

2022-10-03 Thread Peter van Dijk via Pdns-users
Hello, This is the first release candidate for Authoritative Server 4.7.0. We hope it will also be the last :-) 4.7.0 brings support for [1]Catalog Zones, developed by Kees Monshouwer. As part of that development, the freshness checks in the Primary code were reworked, reducing them from doing

[Pdns-users] PowerDNS Authoritative Server 4.7.0-beta2

2022-09-13 Thread Peter van Dijk via Pdns-users
Hello, today we released the first Beta release for Authoritative Server 4.7.0, even though it is called beta2. (beta1 was never released because of bugs found during the release process). 4.7.0 brings support for [1]Catalog Zones, developed by Kees Monshouwer. As part of that development, the

[Pdns-users] PowerDNS Authoritative Server 4.6.3

2022-07-13 Thread Peter van Dijk via Pdns-users
Hello! Today we published release 4.6.3 of the Authoritative Server.It contains a few bug fixes, and marks the appearance of Ubuntu Jammy packages for the 4.6 branch. Please find a full list in the [1]changelog. Please make sure to read the [2]Upgrade Notes before upgrading. The

Re: [Pdns-users] Powerdns Alpine authoritative server 4.5.4 series missing zone2sql , zone2json binary

2022-05-06 Thread Peter van Dijk via Pdns-users
Hello Varsha, On Thu, 2022-04-28 at 16:32 +0530, Rain Musings via Pdns-users wrote: > Background: > We are using the powerdns alpine distribution in docker images .  > We were previously using 4.0.8 powerdns  which came with the zone2sql > , zone2json utility.  > These utilities are used by our

[Pdns-users] [Pdns-announce] PowerDNS Authoritative Server 4.6.2

2022-04-12 Thread Peter van Dijk via Pdns-users
Hello! Today we published release 4.6.2 of the Authoritative Server. It contains a carefully selected set of new features, plus a few bug fixes. Please find a full list in the [1]changelog. Please make sure to read the [2]Upgrade Notes before upgrading. The [3]tarball ([4]signature) is

Re: [Pdns-users] ixfrdist and AA flag when querying for SOA record

2022-02-28 Thread Peter van Dijk via Pdns-users
Hello David, On Wed, 2022-02-23 at 13:56 +, GAVARRET, David via Pdns-users wrote: > Is it normal for ixfrdist, considering its main usage of zone > transfer, that it does not handle the ‘AA’ flag the same way the > backend pdns server acts ? Or am I not using ixfrdist like it > should ? That

Re: [Pdns-users] PowerDNS Slave with DNSSEC and subdomain

2022-02-22 Thread Peter van Dijk via Pdns-users
Hello Benjamin, On Wed, 2022-02-16 at 17:48 +0100, Benjamin Rechsteiner via Pdns-users wrote: > However, we get the following error message on the slave server (4.5.3) > during check-all-zones: > > [Warning] 'dev.foobar.ch|RRSIG' in zone 'foobar.ch' is occluded by a > delegation at

[Pdns-users] Authoritative Server 4.7.0-alpha1

2022-02-17 Thread Peter van Dijk via Pdns-users
Hello! this is the first Alpha release for Authoritative Server 4.7.0. It brings a couple of new features into the hands of our users early. New features: * lmdbbackend databases now get a UUID assigned, making it easy for external software to spot if a database was completely replaced *

Re: [Pdns-users] Does PowerDNS ignore SOA expiry time

2022-02-04 Thread Peter van Dijk via Pdns-users
Hello Stefan, On Fri, 2022-02-04 at 10:44 +, Stefan Becker via Pdns-users wrote: > I wonder if zones can expire when using PowerDNS as secondary nameserver. So, > when a zone cannot be updated from its primary due to any communication error > will the zone then expire or will it still work?

[Pdns-users] Moving CentOS 8 builds to Oracle Linux 8

2022-02-01 Thread Peter van Dijk via Pdns-users
As you might be aware, CentOS 8 has reached End of Life on December 31st 2021 [1]. Furthermore, yesterday, CentOS 8 actually disappeared from the distribution mirrors. While we had made plans for this [2], we failed to execute those plans until now. This means we will need to switch build

Re: [Pdns-users] [LdapBackend] avoid writing PdnsDomainNotifiedSerial

2022-01-25 Thread Peter van Dijk via Pdns-users
Hello Michael, On Fri, 2022-01-21 at 17:10 +0100, Michael Ströder via Pdns-users wrote: > I have a very tiny and simple setup of PowerDNS Authorative server(s) > 4.5.3 with LDAP backend using native OpenLDAP replication. Each pdns > instance asks a single local LDAP server (via ldapi://). No

Re: [Pdns-users] Is the update protocol between supermaster and superslave pdnsversion agnostic?

2022-01-25 Thread Peter van Dijk via Pdns-users
On Mon, 2022-01-17 at 15:59 +0100, Leeflangetje via Pdns-users wrote: > I have a setup with pretty old pdns servers (4.2). > > One hidden master that serves a number of internet-facing authorative > servers which act as superslaves. > > I want to upgrade the lot to the latest version, but

[Pdns-users] Authoritative Server 4.6.0

2022-01-25 Thread Peter van Dijk via Pdns-users
Hello! after a very useful beta/RC period in which we received some excellent bug reports, we released Authoritative Server version 4.6.0 today. Version 4.6.0 mostly brings small improvements and fixes, but there are three notable new features: * support for incoming PROXY headers * support for

[Pdns-users] PowerDNS Authoritative Server 4.5.3

2022-01-21 Thread Peter van Dijk via Pdns-users
Hello! Today we published release 4.5.3 of the Authoritative Server. It contains several robustness fixes for the LMDB backend, and for the zone cache. Please find a full list in the [1]changelog. Please make sure to read the [2]Upgrade Notes before upgrading. The [3]tarball ([4]signature) is

[Pdns-users] First Release Candidate for Authoritative Server 4.6.0

2022-01-14 Thread Peter van Dijk via Pdns-users
Hello! Today we released the first Release Candidate for Authoritative Server version 4.6.0. Version 4.6.0 mostly brings small improvements and fixes, but there are three notable new features: * support for incoming PROXY headers * support for EDNS cookies * autoprimary management via pdnsutil

[Pdns-users] First Beta Release for Authoritative Server 4.6.0

2021-12-09 Thread Peter van Dijk via Pdns-users
Hello! Today we released the first Beta version for Authoritative Server version 4.6.0. Version 4.6.0 mostly brings small improvements and fixes, but there are two notable new features: * support for incoming PROXY headers * support for EDNS cookies A note to downstream packagers: we removed

[Pdns-users] PowerDNS Authoritative Server 4.4.2

2021-11-25 Thread Peter van Dijk via Pdns-users
Hello! We are proud to announce version 4.4.2 of the Authoritative Server. This releases fixes one issue: * RFC2136/nsupdate: apply new TTL to whole RRset, not only to the added record Please find a full list in the [1]changelog. Please make sure to read the [2]Upgrade Notes before upgrading.

Re: [Pdns-users] Disable DNSSEC Digest Type

2021-11-19 Thread Peter van Dijk via Pdns-users
Hello Dave, On Fri, 2021-11-19 at 12:24 +0200, Dave Strydom via Pdns-users wrote: > Is there a way to prevent or disable 'pdnsutil secure-zone' generating the DS > record with the SHA-1 digest type and only generate the SHA-256 and SHA-384? secure-zone does not generate DSes, it only generates

[Pdns-users] PowerDNS Authoritative Server 4.5.2

2021-11-10 Thread Peter van Dijk via Pdns-users
Hello! Today we published release 4.5.2 of the Authoritative Server. It contains several robustness fixes for the bindbackend, and for SOA handling. These fixes are especially important for zone cache users. Please find a full list in the [1]changelog. Please make sure to read the [2]Upgrade

Re: [Pdns-users] SERVFAIL responses on malformed subdomain query

2021-10-14 Thread Peter van Dijk via Pdns-users
On Thu, 2021-10-14 at 16:01 +0200, Remi Gacogne via Pdns-users wrote: > On 10/14/21 15:52, Thib D via Pdns-users wrote: > > It seems like pdns auth servers are answering SERVFAIL queries when the > > subdomain is malformed in the query. It is testable on powerdns.com > >

[Pdns-users] First Alpha Release for Authoritative Server 4.6.0

2021-10-07 Thread Peter van Dijk via Pdns-users
Hello! Today we released the first Alpha version for Authoritative Server version 4.6.0. Version 4.6.0 mostly brings small improvements and fixes, but there are two notable new features: * support for incoming PROXY headers * support for EDNS cookies A note to downstream packagers: we removed

Re: [Pdns-users] pdns-recursor suddenly started to answer with content from . zone instead of what is configured in forward.zones.

2021-09-21 Thread Peter van Dijk via Pdns-users
Hello Thomas, On Tue, 2021-09-21 at 13:53 +0200, Thomas Mieslinger via Pdns-users wrote: > dog.80 IN NSEC domains. NS DS RRSIG NSEC This looks like aggressive NSEC reuse ( https://datatracker.ietf.org/doc/html/rfc8198) and/or NXDOMAIN: There Really Is Nothing Underneath (

Re: [Pdns-users] bind backend zones not registered with zone cache

2021-08-18 Thread Peter van Dijk via Pdns-users
Hello Christof, On Sun, 2021-08-01 at 22:03 +0200, Christof Meerwald via Pdns-users wrote: > So the problem only seems to occur when also launching the gsqlite3 > backend in addition to the bind backend. I am mainly using the bind > backend for the zone data and gsqlite3 for DNSSEC. > > >

Re: [Pdns-users] returning a TXT record consisting only of digits from lua backend

2021-08-18 Thread Peter van Dijk via Pdns-users
Hi Christof, On Sun, 2021-08-01 at 21:49 +0200, Christof Meerwald via Pdns-users wrote: > Sorry, when saying lua backend I actually mean lua2backend: > > pdns-backend-lua2 4.5.1-1pdns.focal > > > > Better yet, can you show some config and code? > > I was basically just testing my Let's

Re: [Pdns-users] bind backend zones not registered with zone cache

2021-07-30 Thread Peter van Dijk via Pdns-users
Hello Christof, On Tue, 2021-07-27 at 19:21 +0200, Christof Meerwald via Pdns-users wrote: > After adding a zone with > > pdns bind-add-zone example.com /etc/dns/example.com.dns > > I could query that zone. > > To me it seems there really is a call to "g_zoneCache.add" missing for > those

Re: [Pdns-users] returning a TXT record consisting only of digits from lua backend

2021-07-30 Thread Peter van Dijk via Pdns-users
Hello Christof, On Wed, 2021-07-28 at 22:49 +0200, Christof Meerwald via Pdns-users wrote: > it seems to be impossible to return a "TXT" record that only contains > digits from the lua backend (something like "1234"). > > Any attempt results in "boost::bad_get: failed value get using >

[Pdns-users] security advisory 2021-01 for PowerDNS Authoritative Server 4.5.0

2021-07-26 Thread Peter van Dijk via Pdns-users
Hello, today we have released PowerDNS Authoritative Server 4.5.1, fixing a remotely triggered crash present in version 4.5.0. No other versions are affected. Tarballs and signatures are available at https://downloads.powerdns.com/releases/, and a single patch is available at

Re: [Pdns-users] DDoS attack with random A requests causes SQL backend overload

2021-07-16 Thread Peter van Dijk via Pdns-users
On Fri, 2021-07-16 at 12:08 +0200, Thomas Mieslinger via Pdns-users wrote: > Suggestions from older threads (Klaus Darrilon): > - Put that zone in a more efficent Backend (he suggested lmdb) Good idea. > - Put that zone in a more efficent Software (he suggested nsd) and use > dnsdist to route

[Pdns-users] PowerDNS Authoritative Server 4.5.0

2021-07-13 Thread Peter van Dijk via Pdns-users
Hello! PowerDNS Authoritative Server 4.5.0 was released today. Version 4.5.0 mostly brings small improvements and fixes, but there are two notable new features: * The ‘zone cache’, which allows PowerDNS to keep a list of zones in memory, updated periodically. With this cache, PowerDNS can avoid

[Pdns-users] Second Release Candidate for PowerDNS AUthoritative Server 4.5.0

2021-07-06 Thread Peter van Dijk via Pdns-users
Hello! Today we released the second, and hopefully last, Release Candidate for Authoritative Server version 4.5.0. Please try it! Version 4.5.0 mostly brings small improvements and fixes, but there are two notable new features: * The ‘zone cache’, which allows PowerDNS to keep a list of zones

[Pdns-users] First Release Candidate for PowerDNS Authoritative Server 4.5.0

2021-06-25 Thread Peter van Dijk via Pdns-users
Hello! Today we released the first Release Candidate for Authoritative Server version 4.5.0. Version 4.5.0 mostly brings small improvements and fixes, but there is one notable new feature: the zone cache. The zone cache allows PowerDNS to keep a list of zones in memory, updated periodically.

Re: [Pdns-users] Timeout error: Error from remote in receive(): Resource temporarily unavailable

2021-06-14 Thread Peter van Dijk via Pdns-users
On Mon, 2021-06-14 at 13:32 +0800, Jackson Yap via Pdns-users wrote: > We found the cause. > > The issue for the timeout is due to some domains’ nameservers in the record > cannot be resolved. > How can we disable the resolving of NS records in the DNS zones to avoid such > resolving stucking

Re: [Pdns-users] Master Support with LDAP Backend

2021-06-07 Thread Peter van Dijk via Pdns-users
On Wed, 2021-06-02 at 14:44 +0300, Nikolaos Milas via Pdns-users wrote: > On 19/5/2021 9:40 μ.μ., Nikolaos Milas via Pdns-users wrote: > > > By the way, the LDAP backend documentation states "Master (support): > > No", yet there is a section (Master Mode) with configuration for > > Master

[Pdns-users] PowerDNS Authoritative Server 4.5.0-alpha1

2021-05-27 Thread Peter van Dijk via Pdns-users
Hello! Today we released the first Alpha version for Authoritative Server version 4.5.0. Version 4.5.0 mostly brings small improvements and fixes, but there is one notable new feature: the zone cache. The zone cache allows PowerDNS to keep a list of zones in memory, updated periodically. With

Re: [Pdns-users] Dig @127.0.0.1 gives status servfail

2021-05-24 Thread Peter van Dijk via Pdns-users
On Sat, 2021-05-22 at 16:16 -0500, von lon via Pdns-users wrote: > When i do the command "Dig @127.0.0.1" i get a response called servfail when > i do the command "sudo systemctl status pdns" i get "Backend reported > permanent error which prevented lookup (GSQLBackend lookup query:Could not >

Re: [Pdns-users] Upgrading Auth Server directly from 4.1.14 to 4.4.1

2021-05-24 Thread Peter van Dijk via Pdns-users
On Wed, 2021-05-19 at 21:40 +0300, Nikolaos Milas via Pdns-users wrote: > By the way, the LDAP backend documentation states "Master (support): > No", yet there is a section (Master Mode) with configuration for Master > operation.These changes will allow master operation in the future, or >

Re: [Pdns-users] another rrset question

2021-04-25 Thread Peter van Dijk via Pdns-users
On Sun, 2021-04-25 at 07:17 -0700, Larry Wapnitsky via Pdns-users wrote: > example error: > > RRset pod.wapnitsky.com. IN TXT: Conflicts with pre-existing RRset What RRsets already exist at 'pod'? Kind regards, -- Peter van Dijk PowerDNS.COM BV - https://www.powerdns.com/

Re: [Pdns-users] Upgrade path

2021-04-15 Thread Peter van Dijk via Pdns-users
Hello Larry, On Wed, 2021-04-14 at 21:13 +0200, Larry Wapnitsky via Pdns-users wrote: > I'm currently on 4.2 from the Ubuntu repos, and am looking to upgrade to > 4.5 so I can get the Prometheus metrics. I've run the upgrade in my lab > today and, after some db troubles, got pdns up and running.

Re: [Pdns-users] Error using pdnsutil with MySQL backend

2021-04-12 Thread Peter van Dijk via Pdns-users
On Mon, 2021-04-12 at 12:38 +, tach yon via Pdns-users wrote: > # change zone check to have conditional on status > gmysql-info-zone-query=select id,name,master,last_check,notified_serial,type > from domains where name='%s' and status='A' The original query in 4.1 is select

Re: [Pdns-users] How to list zones by account?

2021-04-05 Thread Peter van Dijk via Pdns-users
Hello, On Sat, 2021-04-03 at 21:32 -0600, Team 1035 via Pdns-users wrote: > Hi team -- I'm trying to list zones by account. Is there any way to do this > other than loading every zone and then filtering? The search endpoint doesn't > seem to consider account. > > Even if I maintain my own

Re: [Pdns-users] Could not update pdns authoritive server

2021-04-01 Thread Peter van Dijk via Pdns-users
Hello Pierrick, On Thu, 2021-04-01 at 15:44 +0200, Pierrick CHOVELON via Pdns-users wrote: > Hi there, > > I'm struggling for updating one authoritive server from 4.1.6 version to 4.4. > I'm following this link as I always do, https://repo.powerdns.com/ I'm on a > Debian 10 server. Debian 10

[Pdns-users] Recursor 4.3.7 released

2021-03-22 Thread Peter van Dijk via Pdns-users
Hello! Today we are releasing PowerDNS Recursor 4.3.7. This release fixes a bug where the wrong TTL could be used when inserting records into the packet cache. Additionally, the recursor no longer resolves unneeded names when chasing CNAME records if QName Minimization is enabled. Please refer

Re: [Pdns-users] Recursor address in Dnstap messages

2021-03-19 Thread Peter van Dijk via Pdns-users
Hello Hans, On Fri, 2021-03-19 at 10:08 +0100, Hans Seidel via Pdns-users wrote: > Hello, > > we are using the message logging via Dnstap of the PowerDNS Recursor > (version 4.4.2). Since we have several instances that send us log > messages, we want to distinguish the different instances via

Re: [Pdns-users] API Bug(?) with Postgres backend when inserting rr containg dots

2021-03-17 Thread Peter van Dijk via Pdns-users
Hello Ferdinand, On Tue, 2021-03-16 at 16:40 +0100, Ferdinand Goldmann via Pdns-users wrote: > Mar 16 15:48:10 pdns[67880]: [webserver] > 759b42ae-4c22-42be-a961-6b27805d9171 HTTP ISE for > "/api/v1/servers/localhost/zones/ferdl.test.": Exception: GSQLBackend unable > to insert empty

[Pdns-users] PowerDNS Authoritative Server 4.3.2

2021-03-11 Thread Peter van Dijk via Pdns-users
Hello, We are happy to announce version 4.3.2 of the Authoritative Server. This release fixes latency calculations to match the approach used in 4.4.0, to make comparisons between 4.3 and 4.4 more useful. It also contains a few build-related improvements. Please find a full list in the

Re: [Pdns-users] [EXT] Re: Buiding powerdns container images with podman

2021-03-04 Thread Peter van Dijk via Pdns-users
On Thu, 2021-03-04 at 12:50 +0100, Cheikh Dieng wrote: > > g++: fatal error: Killed signal terminated program cc1plus > > compilation terminated. This usually means you ran out of memory. Can you check dmesg? Kind regards, -- Peter van Dijk PowerDNS.COM BV - https://www.powerdns.com/

Re: [Pdns-users] Buiding powerdns container images with podman

2021-03-04 Thread Peter van Dijk via Pdns-users
Hello, On Wed, 2021-03-03 at 19:21 +0100, Cheikh Dieng via Pdns-users wrote: > Hello Peter, > Thanks for you response. > For the 1rs Question: I split it in many step. > I have to install to powerdns with ldap backend (plugin). What are the > options during the images podman built processus to

Re: [Pdns-users] Buiding powerdns container images with podman

2021-03-03 Thread Peter van Dijk via Pdns-users
Hello, On Fri, 2021-02-26 at 11:48 +0100, Cheikh Dieng via Pdns-users wrote: > 1st question: > How can i add new dns entry (ie new Server) for building new docker > images. What's the file I should use? for new entries before the buid > process ? I'm sorry, I don't understand this question. What

Re: [Pdns-users] [EXT] Re: PowerDNS Authoritative Server 4.4.1

2021-02-19 Thread Peter van Dijk via Pdns-users
On Fri, 2021-02-19 at 09:11 +, Brian Candler wrote: > On 19/02/2021 09:01, Peter van Dijk via Pdns-users wrote: > > > Our plan: > > * reinstate 4.4 (and older, I think) for Stretch soon > > * communicate clearly > > * most likely not release 4.5 for Stre

Re: [Pdns-users] PowerDNS Authoritative Server 4.4.1

2021-02-19 Thread Peter van Dijk via Pdns-users
Hello Brian, On Mon, 2021-02-08 at 13:41 +, Brian Candler via Pdns-users wrote: > On 08/02/2021 11:23, Peter van Dijk via Pdns-users wrote: > > On Mon, 2021-02-08 at 12:07 +0100, Peter van Dijk wrote: > > > is available at downloads.powerdns.com and packages for CentOS 7 a

Re: [Pdns-users] PowerDNS Authoritative Server 4.4.1

2021-02-08 Thread Peter van Dijk via Pdns-users
On Mon, 2021-02-08 at 12:07 +0100, Peter van Dijk wrote: > is available at downloads.powerdns.com and packages for CentOS 7 and 8, > Debian Buster, Ubuntu Xenial, Bionic and Focal are available from > repo.powerdns.com. Correction: because Xenial is almost End-of-Life, the last supported PowerDNS

[Pdns-users] PowerDNS Authoritative Server 4.4.1

2021-02-08 Thread Peter van Dijk via Pdns-users
Hello! We are proud to announce version 4.4.1 of the Authoritative Server. This releases fixes several small issues discovered since the release of 4.4.0. Please find a full list in the changelog. < https://doc.powerdns.com/authoritative/changelog/4.4.html#change-4.4.1 > Please make sure to

Re: [Pdns-users] Question about upgrade notes 4.3.x to 4.4.0

2021-01-29 Thread Peter van Dijk via Pdns-users
Hello Steinar, On Fri, 2021-01-22 at 17:15 +0100, Steinar Haug via Pdns-users wrote: > Quick question about PowerDNS 4.4.0 and the 4.3.x to 4.4.0 upgrade > notes at > > https://doc.powerdns.com/authoritative/upgrading.html > > I'm running 4.3.0 with the BIND backend, and planning to

Re: [Pdns-users] TCP nameserver had error, cycling backend: innodb-read-committed=no

2021-01-12 Thread Peter van Dijk via Pdns-users
Hello, On Sat, 2021-01-09 at 18:26 +0100, Gert van Dijk via Pdns-users wrote: > It seems that this error message is triggered whenever PowerDNS cannot > connect to the database at the first attempt, but it succeeds a second > time. [1] The second time it tries to connect without transaction >

[Pdns-users] PowerDNS Authoritative 4.1.x End Of Life

2020-12-18 Thread Peter van Dijk via Pdns-users
On Fri, 2020-12-18 at 11:53 +0100, Peter van Dijk wrote: > We are proud to announce version 4.4.0 of the Authoritative Server. This means that versions 4.1.x and older are now End Of Life. Please see our EOL page for more information: https://doc.powerdns.com/authoritative/appendices/EOL.html

[Pdns-users] PowerDNS Authoritative Server 4.4.0

2020-12-18 Thread Peter van Dijk via Pdns-users
Hello! We are proud to announce version 4.4.0 of the Authoritative Server. This release drops GSS/TSIG support, please see PowerDNS Security Advisory 2020-06 < https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-06.html >. Version 4.4.0 brings a bunch of exciting

[Pdns-users] First Release Candidate for Authoritative Server 4.4.0

2020-12-07 Thread Peter van Dijk via Pdns-users
Hello! This is the first Release Candidate for version 4.4.0 of the Authoritative Server. If no trouble surfaces, we will release the actual 4.4.0 within a few weeks. This release drops GSS/TSIG support, please see PowerDNS Security Advisory 2020-06 <

Re: [Pdns-users] API issue

2020-11-24 Thread Peter van Dijk via Pdns-users
(resent from correct account - apologies if my previous email also appears eventually) On Sun, 2020-11-22 at 12:24 +0100, Stef Coene via Pdns-users wrote: > Hi, > > I noticed that you can add a record with no content if you specify a > comment. Not exactly - because there is no 'records' array

Re: [Pdns-users] IXFR request refused response

2020-11-24 Thread Peter van Dijk via Pdns-users
On Tue, 2020-11-24 at 08:26 +, Brian Candler via Pdns-users wrote: > You could also tell them that https://wiki.opendnssec.org/ is down. They are aware, should come back later today with some luck. Kind regards, -- Peter van Dijk PowerDNS.COM BV - https://www.powerdns.com/

Re: [Pdns-users] IXFR request refused response

2020-11-24 Thread Peter van Dijk via Pdns-users
On Mon, 2020-11-23 at 14:54 +, Brian Candler via Pdns-users wrote: > On 23/11/2020 13:33, Sebastian Sandberg via Pdns-users wrote: > > I have questions regarding IXFR. I have a problem in my lab where pdns is > > refusing IXFR requests to check current serial of a master zone in pdns. > >

[Pdns-users] Authoritative Server 4.4.0-beta1

2020-11-23 Thread Peter van Dijk via Pdns-users
Hello! we are very happy to announce version 4.4.0-beta1 of the Authoritative Server. This release drops GSS/TSIG support, please see PowerDNS Security Advisory 2020-06 < https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2020-06.html >. Version 4.4.0 brings a bunch

Re: [Pdns-users] recursor failing to pick up change in master .ca zone file

2020-11-17 Thread Peter van Dijk via Pdns-users
On Mon, 2020-11-16 at 16:17 +, Brian Candler via Pdns-users wrote: > Or were you getting NXDOMAIN for the query (for a newly-created domain?) > Negative answers are also cached. The .ca SOA record says they can be cached > for one hour: > ;; ANSWER SECTION: > ca.3585IN

Re: [Pdns-users] Servfail spikes on PowerDNS authoritive

2020-11-05 Thread Peter van Dijk via Pdns-users
Hi Roman, On Mon, 2020-11-02 at 14:41 +0100, Roman Steinhart via Pdns-users wrote: > Luckily PowerDNS is logging why these servfails occur: > > Exception building answer packet for britishgerbil.aternos.me/DS (Attempt > > to print an unset dnsname) sending out servfail > > But unfortunately, I

[Pdns-users] Authoritative 4.4.0-alpha3

2020-11-05 Thread Peter van Dijk via Pdns-users
Hello! we are very happy to announce version 4.4.0-alpha3 of the Authoritative Server. (A painful bug in the LMDB backend was found just as we started the Alpha 2 release process, so we decided to skip right on to Alpha 3, with that bug fixed). This release drops GSS/TSIG support, please see

Re: [Pdns-users] Implementing virtual domains

2020-10-05 Thread Peter van Dijk via Pdns-users
On Tue, 2020-09-29 at 12:12 +0100, Robert Mortimer via Pdns-users wrote: > In theory apex DNAME records should work - I've not had that much luck in > getting them to do so. No, DNAME records generate CNAMEs for every name -under- them. They never do anything for their own name. Kind regards,

  1   2   >