Re: [Pdns-users] Unable to resolve domain when using DO and not AD

2018-12-13 Thread Frank Louwers via Pdns-users
Dear Luca, > On 12 Dec 2018, at 19:53, Luca Lesinigo > wrote: > > Il giorno 12 dic 2018, alle ore 18:45, bert hubert > ha scritto: >>> Right now I am refraining to disclose the domain because I don’t know if >>> this behavior could

Re: [Pdns-users] Unable to resolve domain when using DO and not AD

2018-12-12 Thread Brian Candler
On 12/12/2018 18:53, Luca Lesinigo wrote: - or can I configure pdns-recursor to selectively turn off DNSSEC for a single domain / regex? Negative Trust Anchor. https://doc.powerdns.com/recursor/dnssec.html#negative-trust-anchors (Yes, it's one line of LUA to configure - or you can just use

Re: [Pdns-users] Unable to resolve domain when using DO and not AD

2018-12-12 Thread Luca Lesinigo
Il giorno 12 dic 2018, alle ore 18:45, bert hubert ha scritto: >> Right now I am refraining to disclose the domain because I don’t know if >> this behavior could disclose a software/version/configuration with some >> kind of known vulnerability. > Sadly, that is where we stop reading about your

Re: [Pdns-users] Unable to resolve domain when using DO and not AD

2018-12-12 Thread bert hubert
On Wed, Dec 12, 2018 at 05:59:20PM +0100, Luca Lesinigo wrote: > Right now I am refraining to disclose the domain because I don’t know if > this behavior could disclose a software/version/configuration with some > kind of known vulnerability. Sadly, that is where we stop reading about your

[Pdns-users] Unable to resolve domain when using DO and not AD

2018-12-12 Thread Luca Lesinigo
Hello list! We recently had reports from our users about difficulties receiving mails from a specific external domain, caused by our systems unability to resolve the sender domain through our pdns recursors. Right now I am refraining to disclose the domain because I don’t know if this behavior