[Pdns-users] PowerDNS Recursor 3.2 Release Candidate 2 available

2010-02-28 Thread bert hubert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi everybody, Please find below the release notes of the PowerDNS Recursor version 3.2, Release Candidate 2. Compared to RC1, this version mostly contains compilation and platform fixes (for Solaris and CentOS4/RHEL4), as well as improved statistics

Re: [Pdns-users] PowerDNS Recursor 3.2 Release Candidate 1 available

2010-02-19 Thread bert hubert
Peter, Thanks for your report! On Fri, Feb 19, 2010 at 11:22:31AM +0100, Peter Gervai wrote: > But here's what made me write: cache efficiency. Old version forks ran > at average 70% (both). New version right now runs at 25%. Since > nothing was really changed (userbase same, config same, cach

Re: [Pdns-users] nslookup weirdness

2010-02-17 Thread bert hubert
On Wed, Feb 17, 2010 at 11:51:45PM +0100, Udo Rader wrote: > > 2.1.13.172.in-addr.arpa name = weird.example.com. > >> exit > > hmm, I just tried something else from a remote server that has the > troublesome pdns server as its primary nameserver: > > $ cat /etc/resolv.conf > nameserver 172.13

Re: [Pdns-users] PowerDNS Recursor 3.2 Release Candidate 1 available

2010-02-15 Thread bert hubert
On Mon, Feb 15, 2010 at 08:54:23PM +0100, Marcel Pennewiß wrote: > > * Domains can now be forwarded with the 'recursion-desired' > >bit on or off. Feature suggested by Darren Gamble, > >implemented in commit 1451. DOCUMENTATION FORTHCOMING! > > Maybe Bert will write a few lines about this

Re: [Pdns-users] PDNS doesn't feel authoritative?

2010-02-10 Thread bert hubert
On Thu, Feb 11, 2010 at 02:28:53AM +0100, Chris wrote: > Earlier I set this the recursor to some random dns server on the > internet. But there's the problem that pdns should serve some > private zone that's not resolvable through the root servers. That works pretty well, as long as you don't use

[Pdns-users] PowerDNS Community IRC Channel moving to OFTC

2010-02-10 Thread bert hubert
Community to interact, than for there to be two (which do not mutually communicate). Kind regards, Bert Hubert ('ahu' on #powerdns) ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] PowerDNS Recursor 3.2 Release Candidate 1 available

2010-02-10 Thread bert hubert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi everybody, Please find below the release notes of the PowerDNS Recursor version 3.2, release candidate 1. RC1 is already deployed in a number of large places, and it appears to be holding up well. In addition, a number of future users have perform

[Pdns-users] Heads up for Lua users within PowerDNS: check your code before upgrading

2010-02-06 Thread bert hubert
script, *after upgrading* you will no * longer have a working Lua script! So before doing any upgrading from -testing or self-compiled versions from Subversion, please check the manual linked above, especially the getlocaladdress() function. Kind regards, Bert Hubert

Re: [Pdns-users] pdns-recursor returning bad data intermittently

2010-02-04 Thread bert hubert
On Fri, Feb 05, 2010 at 08:07:23AM +0100, ab...@t-ipnet.net wrote: > > mydomain.net=172.17.18.241;172.17.18.242 > > maybe you have different zone data on your auth servers. What is the > result of > > # dig @172.17.18.241 smtp.mydomain.net. > > and > > # dig @172.17.18.242 smtp.mydomain.net.

[Pdns-users] [bert.hub...@netherlabs.nl: Re: qtype argument to pipe backend is always set to 'ANY' (continued)]

2010-02-04 Thread bert hubert
- Forwarded message from bert hubert - Date: Thu, 4 Feb 2010 10:12:48 +0100 From: bert hubert To: Sudarshan Raghavan Subject: Re: [Pdns-users] qtype argument to pipe backend is always set to 'ANY' (continued) On Thu, Feb 04, 2010 at 02:41:08PM +0530, Sudarshan Ragh

Re: [Pdns-users] qtype argument to pipe backend is always set to 'ANY' (continued)

2010-02-04 Thread bert hubert
This question keeps getting asked, I've put a note about this in the documentation, http://doc.powerdns.com/backends-detail.html#AEN5622 For completeness: Besides regular query types, the DNS also knows the 'ANY' query type. When a server receives a question for this ANY type, it should reply wit

Re: [Pdns-users] New PowerDNS GUI

2010-02-03 Thread bert hubert
On Wed, Feb 03, 2010 at 10:20:44AM +, Chris Maciejewski wrote: > Hi, > > Just wanted to let you know I recently released a new PowerDNS GUI. > > It is a GPL v2. licensed and hosted at http://code.google.com/p/pdns-gui/ What can I say except: LOOKING GOOD! I see there is a demo on http://ww

[Pdns-users] update on Exactly simultaneous PowerDNS Recursor Crashes in a number of places

2010-02-01 Thread bert hubert
Hi everybody, I promised several people to summarise what we discovered about the spike of packets. It is not quite conclusive, but enough that we know what to do. The short summary is that the upcoming 3.2 release will contain some slight tweaks to improve stability, but that there is no reason

Re: [Pdns-users] PowerDNS Recursor instability

2010-01-28 Thread bert hubert
preferably be run inside 'screen', or something else > that preserves the console connection (nohup, for example). > > Further things you can do > - > If you observe stability issues, please email me privately. > > We

[Pdns-users] PowerDNS Recursor instability

2010-01-28 Thread bert hubert
sole connection (nohup, for example). Further things you can do - If you observe stability issues, please email me privately. We will keep you updated as the situation develops. Kind regards, Bert Hubert ___ Pdns-users mailing

Re: [Pdns-users] PowerDNS & DNSSEC: your support is needed

2010-01-25 Thread bert hubert
On Mon, Jan 25, 2010 at 10:59:56PM +0100, Marten Lehmann wrote: > Unfortunately I neither received an answer regarding this to a private > email to Bert Hubert nor through a message I left on the contact form of > the powerdns website. I hope that this way someone involved in t

Re: [Pdns-users] PowerDNS and DNSSEC

2010-01-25 Thread bert hubert
On Mon, Jan 25, 2010 at 03:35:59PM +0100, Michael FROMENT wrote: > I've test DNS packet size with my pdns-resursor and it seems that I cannot > get packet size over 512bytes. (...) The PowerDNS Recursor can do >512 packets over TCP/IP fine. Outside of DNSSEC, >512 byte packets are exceedingly rar

Re: [Pdns-users] [Pdns-announce] Attack scope clarification, Ubuntu PowerDNS Recursor Updates + need to restart

2010-01-21 Thread bert hubert
On Thu, Jan 21, 2010 at 01:15:04PM +0100, Sean Boran wrote: > The PDNS tarball on : > http://www.powerdns.com/en/downloads.aspx > is still the same version, 2.9.22, which is the version that was around a > year ago. Sean, That is the version number for the Authoritative Server - for the Recursor

Re: [Pdns-users] Delegation of subdomain when allow-recursion-override=on

2010-01-19 Thread bert hubert
Hi Pizza, I briefly thought you were Anthony Mangieri ;-) But he has better things to do than manage DNS. Can you show an AXFR of your foobar.com domain? I'm not too aware of the exact workings of the LDAP backend, so I need to see if your problem is simply DNS related. Thanks. Bert O

[Pdns-users] Attack scope clarification, Ubuntu PowerDNS Recursor Updates + need to restart

2010-01-09 Thread bert hubert
their older versions too once we get round to shipping the patch to 3.1.4. Many thanks to Imre Gergely, who mangled the patches for Ubuntu. Bert On Wed, Jan 06, 2010 at 04:19:56PM +0100, bert hubert wrote: > The correct links to the .deb packages are: > http://downloads.powerdns.com/r

Re: [Pdns-users] Critical PowerDNS Recursor Security Vulnerabilities: please upgrade ASAP to 3.1.7.2

2010-01-06 Thread bert hubert
the executable over /usr/sbin/pdns_recursor. Bert On Wed, Jan 06, 2010 at 04:11:09PM +0100, bert hubert wrote: > Dear PowerDNS Users, > > Two major vulnerabilities have recently been discovered in the PowerDNS > Recursor (all versions up to and including 3.1.7.1). Over the pa

[Pdns-users] Critical PowerDNS Recursor Security Vulnerabilities: please upgrade ASAP to 3.1.7.2

2010-01-06 Thread bert hubert
us. Kind regards, Bert Hubert ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] PDNS + MySQL results not un-escaped?

2010-01-05 Thread bert hubert
On Wed, Jan 06, 2010 at 03:28:32PM +1300, Michael wrote: > First time poster, long time SysAdmin :-) intending to convert from Bind. Nice ;-) > I have just noticed that PDNS with GMySQL back end does not seem to un-escape > result records. Can you elaborate a bit what you mean by this? For exam

[Pdns-users] lots of bugs fixed, but also tickets closed: please check

2009-12-22 Thread bert hubert
' ;;' 207|worksforme|fancyrecords a partly broken in pdns-2.9.22-rc1.20081118.1295 161|wontfix|Enhancement to log DNS queries and Src IP Kind regards, Bert Hubert ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] TCP listener hangs with fd error on recursor

2009-12-21 Thread bert hubert
On Mon, Dec 21, 2009 at 11:30:25AM +, Josh Berry wrote: > On Mon, Dec 21, 2009 at 10:07:18AM +, Josh Berry wrote: > > > Can you tell us if you are behind a firewall? Perhaps iptables on the host > > itself? > > The server is not behind a firewall, it is behind a load balancer (Nortel > Ap

Re: [Pdns-users] TCP listener hangs with fd error on recursor

2009-12-21 Thread bert hubert
On Mon, Dec 21, 2009 at 10:07:18AM +, Josh Berry wrote: > I am having a problem with the powerdns recursor where the TCP listener > dies every now and then unless the daemon is restarted periodically. Josh, Can you tell us if you are behind a firewall? Perhaps iptables on the host itself? Ar

Re: [Pdns-users] How to avoid to be redirected to ad by my ISP if NXDOMAIN?

2009-11-12 Thread bert hubert
On Thu, Nov 12, 2009 at 09:14:28PM +0100, Gerhard Gaußling wrote: > I'm using powerdns since a long time on ubuntu/hardy amd64. > My ISP changed his behaviour and now I get on NXDOMAIN an ad site with a > search form. But I prefer to get the firefox error page. I can understand. > How do I conf

Re: [Pdns-users] MySQL libraries required?

2009-11-08 Thread bert hubert
On Sat, Nov 07, 2009 at 06:54:55PM -0800, Ask Bjørn Hansen wrote: > After resetting my working copy and running bootstrap and > CXXFLAGS=-I/opt/local/include/ ./configure --with-modules="pipe" The current subversion trunk may indeed have problems compiling the Authoritative Server. > "_g_singl

[Pdns-users] PowerDNS Development & Community Server hosted at XS4ALL

2009-11-08 Thread bert hubert
Hi everybody, Over the past few months, the PowerDNS Wiki and Subversion servers had a hard time and were no longer able to keep up with the growing amounts of traffic. Since these servers also routed my personal email, I had little choice but move the flood of spam to gmail. But no more! We ac

Re: [Pdns-users] MySQL libraries required?

2009-11-07 Thread bert hubert
h bootstrap; CXXFLAGS=-I/opt/local/include/ ./ > configure --with-modules="pdns pipe geo" Which is why. Good luck! Kind regards, Bert Hubert ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Install latest PDNS and PDNS-Recursor on Solaris 10 Sparc

2009-10-29 Thread bert hubert
On Thu, Oct 29, 2009 at 1:35 AM, Barron, Josh wrote: > Ok looks like PDNS-Recursor compiled. > > I've attached the errors I received during the compilation.  FYI I'm using > the following platform: > SunOS ns1 5.10 Generic_141444-09 sun4v sparc SUNW,Sun-Fire-T1000 > > Now on to the authoritative

Re: [Pdns-users] Install latest PDNS and PDNS-Recursor on Solaris 10 Sparc

2009-10-28 Thread bert hubert
On Wed, Oct 28, 2009 at 12:38 AM, Barron, Josh wrote: > Has anyone gotten the latest version of PDNS to install on Solaris 10 > Sparc?? > Lots of random posts out there but nothing much definitive… Josh, Can you try http://svn.powerdns.com/snapshots/pdns-recursor-3.1.8-testing.tar.bz2 and see i

Re: [Pdns-users] FW: Trying to compile with OpenDBX support - LUA issues?!?

2009-10-26 Thread bert hubert
Robert, The suggestion is to not compile the recursor from the authoritative tarball - this is not supported! So remove --enable-recursor, and things should be fine. Good luck! On Mon, Oct 26, 2009 at 5:07 PM, Robert Dunkley wrote: > Can anyone offer any advice on this? Have been staring at th

Re: [Pdns-users] wildcards and pipe backend

2009-09-23 Thread bert hubert
On Wed, Sep 23, 2009 at 10:17 PM, Fagyal Csongor wrote: > The question is: if I know I have wildcard records, then I have to do a > wildcard query? Currently what I do is to first query non-wildcard records, > and if none is found, then I do a wildcard match. Is that correct? Do the > backend have

[Pdns-users] Some comic relief - freeware is not malware, but it is close according to Nominum

2009-09-23 Thread bert hubert
Hi everybody! Sorry for being a bit silent over the past two weeks, have been very busy with our newly born son Guus! Mother and son are doing really well. In the meantime, you may enjoy the propaganda below from DNS vendor Nominum, who I know are stalking many subscribers of this list to migrate

Re: [Pdns-users] Using pdns-recursor on a network with high latency.

2009-09-22 Thread bert hubert
On Fri, Sep 18, 2009 at 10:40 AM, bert hubert wrote: > I'm currently looking in to this and I see why this has not been fixed > - the timeout mechanism is rather crude, and may in fact not even be > doing exactly what it is supposed to be doing. It is supposed to > deliver a

Re: [Pdns-users] Using pdns-recursor on a network with high latency.

2009-09-18 Thread bert hubert
On Fri, Sep 18, 2009 at 9:16 AM, Sten Spans wrote: > As far as I know there currently is no way to improve powerdns-recursor's > behaviour, short of modifying the source. I think Bert would appreciate a > well tested patch which improves the behaviour, although only if it doesn't > hurt lookup per

Re: [Pdns-users] Odd master/slave behavior for large domains

2009-09-11 Thread bert hubert
On Fri, Sep 11, 2009 at 7:14 AM, thomas morgan wrote: > I created a single zone on the server and added 2 million host records. I > know that's a bunch, but it is a specific use case, not just an attempt to > break things. Thomas, Many thanks for your interesting and detailed bug report! I've do

[Pdns-users] PowerDNS & PowerAdmin contributor Jorn Ekkelenkamp has passed away

2009-09-07 Thread bert hubert
relay the details if you want to attend. I wish his family and everyone who knew Jorn lots of strength in dealing with this tremendous loss. Bert Hubert PowerDNS.COM ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/m

Re: [Pdns-users] Presentation 'DNS Security in the Broadest Sense' online

2009-08-17 Thread bert hubert
This should of course read: http://tinyurl.com/powerdns Apologies for the confusion! On Mon, Aug 17, 2009 at 03:55:56PM +0200, bert hubert wrote: > The presentation from last Friday can be found on > http://tinydns.com/powerdns "DNS Security in the Broadest Sense". -- http://

[Pdns-users] Presentation 'DNS Security in the Broadest Sense' online

2009-08-17 Thread bert hubert
Hi everybody, The presentation from last Friday can be found on http://tinydns.com/powerdns "DNS Security in the Broadest Sense". In addition, a movie of the presentation, two interviews (radio & video) and some nice photos can be found on: http://bert-hubert.blogspot.com/2009/08/har2009-thoughts

[Pdns-users] Reminder for visitors of HAR2009.ORG: presentation tomorrow!

2009-08-13 Thread bert hubert
Dear PowerDNS Users currently at HAR2009, Besides benefiting from PowerDNS serving the DNS at HAR2009, if you are interested in PowerDNS, you could consider attending my presentation about "DNS Security in the Broadest Sense" tomorrow (Friday) at 14:00 CET. Also, let me know if you want to meet u

[Pdns-users] PowerDNS & DNSSEC: your support is needed

2009-08-11 Thread bert hubert
t me privately if they are in a position to either acquire a support contract with us, or to fund DNSSEC development directly. If you are interested, or know someone who might be, please let us know and we can send you the 'PowerDNS DNSSEC Enhancement Project Proposal', which includes th

[Pdns-users] PowerDNS Recursor 3.1.7.1 released!

2009-08-02 Thread bert hubert
Release notes with clickable links available on: http://doc.powerdns.com/changelog.html#CHANGELOG-RECURSOR-3-1-7-1 Download from: http://downloads.powerdns.com/releases/pdns-recursor-3.1.7.1.tar.bz2 http://downloads.powerdns.com/releases/rpm/pdns-recursor-3.1.7.1-1.x86_64.rpm http://downloads

Re: [Pdns-users] Logging All DNS Queries

2009-07-22 Thread bert hubert
On Wed, Jul 22, 2009 at 9:36 PM, Brendan Oakley wrote: > On Wed, Jul 22, 2009 at 10:49 AM, Bryan Brannigan wrote: >> I would like to configure PowerDNS to log all DNS queries to a text >> file or to a MySQL table.  Does anyone know if this is possible? > > There is the query-logging setting, but gi

Re: [Pdns-users] Logging All DNS Queries

2009-07-22 Thread bert hubert
On Wed, Jul 22, 2009 at 7:49 PM, Bryan Brannigan wrote: > I would like to configure PowerDNS to log all DNS queries to a text > file or to a MySQL table.  Does anyone know if this is possible? Bryan, The PowerDNS Authoritative Server does not have this ability, the PowerDSN Recursor does ('quiet=

Re: [Pdns-users] SQLite3 problem during stress

2009-07-20 Thread bert hubert
On Mon, Jul 20, 2009 at 11:01 AM, Christian Svensson wrote: > Yes, updating only one zone at the time is very much acceptable - that the > initial transfer takes quite long time does not matter. > > We do not want to use an "active" database due to memory / CPU footprint. If > PowerDNS locks the ta

Re: [Pdns-users] SQLite3 problem during stress

2009-07-19 Thread bert hubert
On Sun, Jul 19, 2009 at 2:15 PM, Norbert Sendetzky wrote: > Hi Christian > >> After combating some weird incompatibility with Debian Lenny 5.0 where >> PDNSs gsqlite3 refused to write anything to the database it begun to crash >> when we did the initial transfer (notify of several hundred domains).

Re: [Pdns-users] SQLite3 problem during stress

2009-07-18 Thread bert hubert
Very quick reply without thinking, make sure PowerDNS has write permissions on the *directory* containing the sqlite3 database - this tends to trip people up 'it can write to the file' is not enough. I'll read your message more carefully to see what else might be happening. Bert On Sat, Jul

Re: [Pdns-users] problems resolving CNAME's with pdns_recursor 3.1.7

2009-07-16 Thread bert hubert
On Thu, Jul 16, 2009 at 2:13 PM, Tom Mueller wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Hi, > > sometimes the pdns_recursor doesn't send all A or records where > the requested CNAME points to. Tom, Do you run with an IPv6 local query address enabled? Can you, privately, sen

Re: [Pdns-users] TCP Query Problem

2009-07-16 Thread bert hubert
On Thu, Jul 16, 2009 at 10:48 AM, InterNetworX|Hostmaster wrote: > Hello, > > we're running PowerDNS since a long time. Usaly TCP queries are working, > only from time to time we need to restart PowerDNS if it stops. Hello "InterNetwoX|Hostmaster", Thank you for your report. Can you run PowerDNS

Re: [Pdns-users] PowerDNS & DNSSEC!

2009-07-15 Thread bert hubert
Hi everybody, I've seen the discussion on the list, and I've had more questions off-list about DNSSEC, DNSCurve and the quality and desirability of these protocols. In the message below, I want to share some of my thoughts on this, and then I kindly request everyone to have this discussion elsewhe

[Pdns-users] PowerDNS & DNSSEC!

2009-07-14 Thread bert hubert
.. http://www.powerdnssec.org .. Is signed by PowerDNS, and the delegation from .ORG is also signed. And of course this domain is powered by PowerDNS! (Re)Signing & re-keying is automatic, and configuration consists of a two step plan: 1) configure a key-repository directory in the pdns.conf. 2)

Re: [Pdns-users] backend ldap

2009-07-12 Thread bert hubert
Vladimir, PowerDNS LDAP backend is used by lots of people, so feel free to use it! Bert On Fri, Jul 10, 2009 at 10:27 PM, Vladimir Elizarov wrote: > Hello! > > I am interested in backend ldap. But it seems to have not used anyone > and their development is not. Is that so? > > Thanks. > > > _

Re: [Pdns-users] DHCP and powerdns backend ldap

2009-07-12 Thread bert hubert
On Fri, Jul 10, 2009 at 10:29 PM, Vladimir Elizarov wrote: > There are some replication between powerdns and dhcp? Sadly, not yet. It turns out this is not easy to do. People sometimes ask if we are pondering 'PowerDHCP' for this reason. Bert ___ Pdn

Re: [Pdns-users] PDNS Recursor compile errors on g++ 4.4.0

2009-07-05 Thread bert hubert
Hi everybody, On Sun, Jul 5, 2009 at 11:44 AM, Roger Libiez wrote: > PDNS-Recursor version 3.1.7 from the download page. I'm unaware of there > being anything newer. > > If the RPM package is any indication, it's Boost 1.37. 3.1.7 indeed does not compile with Boost 1.37 or higher, since they star

Re: [Pdns-users] UDP Connection Table Exhaustion?

2009-07-03 Thread bert hubert
To nuance this a bit - on Linux, you can have great benefit from the iptables 'NOTRACK' target, which can help you do firewalling that will not run into problems from busy DNS traffic. Bert On Fri, Jul 3, 2009 at 9:58 AM, Matthew Walster - Gyron wrote: > > >> -Original Message- >> From

[Pdns-users] PowerDNS at HAR 2009 conference!

2009-07-01 Thread bert hubert
Hi everybody, I thought I'd let you know I'll be presenting on DNS at the famous HAR 2009 conference: "International technology & security conference. Four days of technology, ideological debates and hands-on tinkering. On August 13-16, 2009 the 20th anniversary edition of the four-yearly Dutch o

Re: [Pdns-users] Return Authority section

2009-06-29 Thread bert hubert
On Mon, Jun 29, 2009 at 8:35 PM, Jesse Angell wrote: > I’m migrating from bind and one thing that I noticed is that bind returns > the NS records and the A records for those NS records with every query.  I > noticed that PowerDNS does not do this and I’m trying to figure out if this > will be a pro

Re: [Pdns-users] SIGSEGV after some AXFR queries

2009-06-29 Thread bert hubert
On Mon, Jun 29, 2009 at 3:36 PM, Marek Kroemeke wrote: > Hi there, > > Thanks for suggestions. I was trying to find the particular domain that > could have some odd data in MySQL - but the problem is that this DNS > server seems to send around ~40 AXFR requests in a row - I was not able > to find o

Re: [Pdns-users] SIGSEGV after some AXFR queries

2009-06-29 Thread bert hubert
Marek, Indeed - both 2.9.21 and 2.9.22 contain important updates to the TCP component of PowerDNS. So please consider upgrading, or follow Kenneth's excellent suggestion. Kind regards, Bert Hubert On Mon, Jun 29, 2009 at 3:17 PM, Kenneth Marshall wrote: > Marek, > > Version 2.

Re: [Pdns-users] Recursor fails to build on CentOS

2009-06-28 Thread bert hubert
Boost 1.39 is too new for the Recursor 3.1.7. Either use an older Boost, or use a snapshot of the recursor, which has this problem fixed. Bert On Mon, Jun 29, 2009 at 6:08 AM, Jesse Angell wrote: > Any idea why this is happening? > > Fails with:  lwres.cc:184: error: reference to ‘exceptionâ

Re: [Pdns-users] Possible DNS DOS?

2009-06-22 Thread bert hubert
On Tue, Jun 23, 2009 at 12:27 AM, Chris Modesitt wrote: > I have an interesting problem that has been happening for about 2 weeks. > First a little about my setup, currently I am running the following: Ok - this issue has probably been fixed in commits 1364 and 1365. What happened was that during

Re: [Pdns-users] Possible DNS DOS?

2009-06-22 Thread bert hubert
On Tue, Jun 23, 2009 at 12:27 AM, Chris Modesitt wrote: > What I have been seeing recently show up in the logs is: > Jun 22 09:09:38 dns1 pdns[10948]: 5003 questions waiting for database > attention. Limit is 5000, respawning This is very consistent with a (brief) spike in queries. > Jun 22 09:0

Re: [Pdns-users] PDNS performance comparison to BIND

2009-06-22 Thread bert hubert
On Tue, Jun 23, 2009 at 2:05 AM, Jan Rudinsky wrote: > > Hello, > I have tested PDNS performance (configuration below). A zone transfer of 100 > 000 records takes ~ 10 s using either MySQL or file backends. > However Bind can make it in ~ 1 s (file-stored records). Hi Jan, We've never really opti

Re: [Pdns-users] 2.9.22 compile problem with ldap

2009-06-22 Thread bert hubert
On Mon, Jun 22, 2009 at 7:41 PM, Gary Smith wrote: > Hello, > > We have an SRPM for 2.9.21.2 that compiles fine.  We are trying to update the > package to 2.9.22.  In doing so we ran into an issue with configure not being > able to find ldap.  So, trying it straight (without rpmbuild) and manuall

[Pdns-users] copy of SIDN presentation yesterday

2009-06-19 Thread bert hubert
, Bert Hubert -- http://www.PowerDNS.com Open source, database driven DNS Software http://netherlabs.nl Open and Closed source services ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman

[Pdns-users] third test

2009-06-17 Thread bert hubert
third test to get things working again.. -- http://www.PowerDNS.com Open source, database driven DNS Software http://netherlabs.nl Open and Closed source services ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mail

[Pdns-users] test 3

2009-06-17 Thread bert hubert
another test to get mailman working again.. -- http://www.PowerDNS.com Open source, database driven DNS Software http://netherlabs.nl Open and Closed source services ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://m

[Pdns-users] test post

2009-06-17 Thread bert hubert
test post, please ignore. -- http://www.PowerDNS.com Open source, database driven DNS Software http://netherlabs.nl Open and Closed source services ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.c

[Pdns-users] PowerDNS Presentation over at 'SIDN Relatiedag'

2009-05-16 Thread bert hubert
ma en de aanmeldprocedure op http://www.relatiedagsidn.nl of op de deelnemerssite van SIDN. Ik zie jullie graag op 18 juni. Groeten, Bert Hubert -- http://www.PowerDNS.com Open source, database driven DNS Software http://netherlabs.nl Open and Closed source

[Pdns-users] Mailing list downtime

2009-05-09 Thread bert hubert
Hi PowerDNS list readers, Due to massive amounts of spam, the PowerDNS Mailman / Postfix installation is having problems. I think I have things working again, but some messages from the past week may be lost. So if your post did not make it, now might be a good time to re-send it. Apologies for

Re: Fwd: [Pdns-users] pdns-recursor forwarder setting

2009-04-07 Thread bert hubert
> From: Darren Gamble > > It doesn't, sorry. > > I've previously opened up ticket #199 to request this functionality on a > per-zone basis. ?This is blocking replacing some of our DNS servers with > PowerDNS. Half of the required functionality was added yesterday. What is left to do is hook thi

[Pdns-users] Re: AXFR error

2009-03-08 Thread bert hubert
1 10 271 > Fax : +31 (0)76 - 20 11 179 > Mob: +31 (0)6 - 43 44 45 27 > > > > On Sun, Mar 8, 2009 at 2:37 PM, bert hubert wrote: > > Johan, > > > > Check if your domain_id field is filled out correctly for all records in > > your zone. > > >

[Pdns-users] AXFR error

2009-03-08 Thread bert hubert
Johan, Check if your domain_id field is filled out correctly for all records in your zone. It looks like they aren't. To check manually, try: select id from domains where name='example.com'; select * from records wher domain_id=123; where 123 is the domain id. Then check to see if you see all

Re: [Pdns-users] bind backend behavior

2009-03-03 Thread bert hubert
On Tue, Mar 03, 2009 at 01:01:03PM +0100, Marco Chiavacci wrote: > - with bind we can change in named.conf for a domain the zone file (another > zone file) and during a reconfig this zone was reloaded properly > - with pdns we change in named.conf in same way zone file but during > rediscover domai

Re: [Pdns-users] Weird CNAME root-referral problem

2009-02-10 Thread bert hubert
On Tue, Feb 10, 2009 at 03:38:11AM -0500, Ask Bj?rn Hansen wrote: > At least you came up with a patch about as fast as I found the > bug! :-) (We only started testing powerdns a few days ago; it's > already one of the nameservers for apache.org and perl.org actually). Cool! I read in your o

Re: [Pdns-users] Weird CNAME root-referral problem

2009-02-10 Thread bert hubert
On Tue, Feb 10, 2009 at 02:45:03AM -0500, Ask Bj?rn Hansen wrote: > I can't get powerdns (2.9.22) to not send root(!) referrals with CNAME > replies. Any ideas? Could you try the attached patch? It appears that you have found a bug! Thanks. -- http://www.PowerDNS.com Open source, datab

Re: [Pdns-users] PowerDNS Recursor 3.1.8-prerelease with EDNS-PING

2009-02-07 Thread bert hubert
One small note - EDNS-PING is *not* yet an official standard. It is like buying a '802.11N DRAFT' router! But it is unlikely the technical details (wire format) of EDNS-PING will change, since the specification is so simple. Bert On Sun, Feb 08, 2009 at 01:22:29AM +0100, b

[Pdns-users] PowerDNS Recursor 3.1.8-prerelease with EDNS-PING

2009-02-07 Thread bert hubert
Hi everybody, Quoting from http://edns-ping.org : EDNS-PING is an option within the EDNS DNS framework which allows nameservers to protect themselves from certain "spoofing" attacks. By default, responses to DNS questions are matched to their questions by making sure they share the s

Re: [Pdns-users] Does PowerDNS need the '.' domain?

2009-01-28 Thread bert hubert
On Wed, Jan 28, 2009 at 07:21:38PM +0100, Arjan Schrijver wrote: > Hi list, > > After some complaints that our DNS server was not answering all > questions correctly, we found out that our PowerDNS installation thinks > it's authoritative for the root '.' domain. The domain has domain_id 1, > s

Re: [Pdns-users] "redirect" queries

2009-01-28 Thread bert hubert
On Wed, Jan 28, 2009 at 10:38:53AM -0200, sysadmin wrote: > Hi, > > It's possible setup recursor to point to a specific A record instead return > a error, if a domain do not exist ? Please look into the 'lua' scripts, they make this possible. Search for 'Lua' in the manual to see how this works

[Pdns-users] Book covering PowerDNS Available + RFC

2009-01-27 Thread bert hubert
Hi everybody, There is even more important news than the 2.9.22 release! First a book, second an RFC. Book Jan-Piet Mens has written a book called 'Alternative DNS Servers: Choice and Deployment, and Optional SQL/LDAP Back Ends'. Jan-Piet asked Norbert Sendetzky and me to proofread the Power

[Pdns-users] PowerDNS Authoritative Server version 2.9.22 released!

2009-01-27 Thread bert hubert
PowerDNS Authoritative Server version 2.9.22 released! Download from: http://downloads.powerdns.com/releases/pdns-2.9.22.tar.gz http://downloads.powerdns.com/releases/deb/stable/pdns-static_2.9.22-1_i386.deb http://downloads.powerdns.com/releases/rpm/pdns-static-2.9.22-1.i386.rpm http://down

Re: [Pdns-users] ignore +norecurse ?

2008-12-22 Thread bert hubert
On Mon, Dec 22, 2008 at 03:45:58PM +0100, Jeroen Wunnink wrote: > Is there a way to force a recurse even if a norecurse is set on the > requesting end (i.e. ignore the norecurse flag) ? No. > I'm trying to forward non existing zones to a recursing backend which > will always reply with correct

Re: R: [Pdns-users] intel compiler

2008-12-16 Thread bert hubert
On Tue, Dec 16, 2008 at 03:30:12PM +0100, Marco Chiavacci wrote: > >This is very weird. Can you try searching and replacing 'runtime_error' by > >'std::exception' in zoneparser-tng.cc to see if the problem goes away? > > Sorry but it doesn't work (compile) replacing the string in this file... > li

Re: [Pdns-users] intel compiler

2008-12-16 Thread bert hubert
On Tue, Dec 16, 2008 at 12:03:07PM +0100, Marco Chiavacci wrote: > because " nameserver.cc(117): error: destructible entities are not allowed > inside of a statement expression" htons is sometimes a very weird macro, so I can understand this error. > - the second problem is a strange thing becaus

[Pdns-users] Re: [Pdns-announce] Release Candidate: PowerDNS Authoritative Server 2.9.22-rc2 released!

2008-11-29 Thread bert hubert
This should of course be: http://downloads.powerdns.com/releases/pdns-2.9.22-rc2.tar.gz http://downloads.powerdns.com/releases/deb/stable/pdns-static_2.9.22-rc2-1_i386.deb http://downloads.powerdns.com/releases/rpm/pdns-static-2.9.22rc2-1.i386.rpm Thanks to Ton van Rosma

[Pdns-users] Release Candidate: PowerDNS Authoritative Server 2.9.22-rc2 released!

2008-11-29 Thread bert hubert
Download from: http://downloads.powerdns.com/releases/pdns-2.9.22-rc1.tar.gz http://downloads.powerdns.com/releases/deb/stable/pdns-static_2.9.22-rc1-1_i386.deb http://downloads.powerdns.com/releases/rpm/pdns-static-2.9.22rc1-1.i386.rpm 2.9.22 will be a very important Po

Re: [Pdns-users] building 2.9.21.2 and 2.9.22-rc1

2008-11-29 Thread bert hubert
On Wed, Nov 19, 2008 at 07:50:55PM +0100, Bas wrote: > Hi Bert, > > I did some build tests on both versions : > > CXXFLAGS=-I/temp/boost_1_35_0 ./configure --with-modules=gmysql Bas, The output below implies that your autoconf tries to rebuild the Makefiles. Did you touch Makefile.am?

Re: [Pdns-users] PDNS & pdns-recursor on same machine problems

2008-11-24 Thread bert hubert
On Mon, Nov 24, 2008 at 03:36:07PM -0600, Baird, Josh wrote: > I have a set of authoritative servers running PDNS. One of these servers is > also running pdns-recursor which is bound to a separate IP address. The > recursor is having problems resolving domains that the authoritative > instance i

Re: [Pdns-users] Re: Release Candidate: PowerDNS Authoritative Server 2.9.22-rc1 released!

2008-11-20 Thread bert hubert
On Thu, Nov 20, 2008 at 06:23:51PM +0100, Christof Meerwald wrote: > I built it from source on Ubuntu 8.04 (i386) this morning and so far it > appears to work fine. Good to hear! > One note though, would you expect "pdns_control ccounts" to return some data > - I only get an empty line (btw, I am

[Pdns-users] Release Candidate: PowerDNS Authoritative Server 2.9.22-rc1 released!

2008-11-18 Thread bert hubert
Download from: http://downloads.powerdns.com/releases/pdns-2.9.22-rc1.tar.gz http://downloads.powerdns.com/releases/deb/stable/pdns-static_2.9.22-rc1-1_i386.deb http://downloads.powerdns.com/releases/rpm/pdns-static-2.9.22rc1-1.i386.rpm Hi Everybody, 2.9.22 will be a ver

Re: [Pdns-users] PowerDNS Authoritative Server 2.9.21.2 Security Upgrade

2008-11-18 Thread bert hubert
On Tue, Nov 18, 2008 at 03:10:27PM +0100, Ton van Rosmalen wrote: > Hi Bert, > > Is the patch also integrated in the snapshot 1293 (or up)? It is! I recommend running: http://svn.powerdns.com/snapshots/1299/ or higher Bert -- http://www.PowerDNS.com Open source, database driven DN

[Pdns-users] PowerDNS Authoritative Server 2.9.21.2 Security Upgrade

2008-11-18 Thread bert hubert
Authoritative Server version 2.9.21.2 Released on the 18th of November 2008. Downloadable from: http://downloads.powerdns.com/releases/pdns-2.9.21.2.tar.gz http://downloads.powerdns.com/releases/deb/stable/pdns-static_2.9.21.2-1_i386.deb http://downloads.powerdns.com/rel

Re: [Pdns-users] 2.9.22-rc1 coming up!

2008-11-18 Thread bert hubert
On Tue, Nov 18, 2008 at 10:45:43AM +0100, Ton van Rosmalen wrote: >I probably should have said that I'm using the following options in m >config-file >- setuid >- setgid > >Which might explain the problem I saw before my hack. No problems have >been seen after my modificati

Re: [Pdns-users] 2.9.22-rc1 coming up!

2008-11-17 Thread bert hubert
On Mon, Nov 17, 2008 at 05:54:46PM +0100, Ton van Rosmalen wrote: > Hi all, > > I decided to be adventurous and go ahead and install the snapshot. Thanks Ton! > The auth server runs ok, so no problems there. The only problem I see > has to do with pdns_control. Hmm, this smells like a bug that

Re: [Pdns-users] Error While loading shared libraries: libpq.so.5:Cannot open shared object ---> libssl could not be found

2008-11-16 Thread bert hubert
Borin, Which RPM are you trying exactly? They are supposed to be static! Also FC9 comes with PowerDNS, so no need to use our RPM! Bert On Mon, Nov 17, 2008 at 07:35:16AM +0700, BORIN HY/WiCAM wrote: > Hi, > > Thanks for your response. I got the missing package install as per your > ad

[Pdns-users] 2.9.22-rc1 coming up!

2008-11-16 Thread bert hubert
Hi everybody, On http://svn.powerdns.com/snapshots/1293/ you can find snapshots of what wil become 2.9.22-rc1 later this week, and probably 2.9.22 real soon after that. This is one of the biggest and imho most exciting Authoritative Server releases in many years. Thanks are due to UPC Broadband

Re: [Pdns-users] Slaves aren't fetching zones fast enough.

2008-11-15 Thread bert hubert
On Tue, Nov 04, 2008 at 10:04:12AM -0700, Tyler Hall wrote: > Wanted to update everyone on this. I've been working with ahu who has been > extremely helpful. > > He added some code into my release to fix the problem I was having. Thanks. This code is now part of the subversion version of PowerDN

<    3   4   5   6   7   8   9   10   11   12   >