[Pdns-users] PowerDNS Recursor 4.2.0 Released

2019-07-15 Thread Otto Moerbeek via Pdns-users
(via: https://blog.powerdns.com/2019/07/15/powerdns-recursor-4-2-0-released/) July 15, 2019 PowerDNS Recursor 4.2.0 Released We’re proud to announce version 4.2.0 for the PowerDNS Recursor 4.2 release train. The 4.2.0 release of the PowerDNS Recursor brings a lot of small, incremental

[Pdns-users] First alpha release of PowerDNS Recursor 4.3.0

2019-09-05 Thread Otto Moerbeek via Pdns-users
First alpha release of PowerDNS Recursor 4.3.0 We are proud to announce the first alpha release for the PowerDNS Recursor 4.3 release train. Two major features are introduced: o A relaxed form of QName Minimization as described in rfc7816bis-01 [1] has been implemented. To test this

[Pdns-users] PowerDNS Recursor 4.2.1 Released

2019-12-09 Thread Otto Moerbeek via Pdns-users
Hello, Today we released PowerDNS Recursor 4.2.1. This is a maintenance release that fixes a few issues. In particular, a very slow creeping memory leak is plugged and an rare failure to resolve specific names when the "dnssec" configuration is set to "validate" has been fixed. Please refer to

[Pdns-users] PowerDNS Recursor 4.1.15 Released

2019-12-06 Thread Otto Moerbeek via Pdns-users
Hello, Today we released PowerDNS Recursor 4.1.15. This is a maintenance release that fixes a few issues. In particular, a very slow creeping memory leak is plugged and an rare failure to resolve specific names when the "dnssec" configuration is set to "validate" has been fixed. Please refer to

[Pdns-users] Third alpha release of PowerDNS Recursor 4.3.0

2019-10-29 Thread Otto Moerbeek via Pdns-users
Third alpha release of PowerDNS Recursor 4.3.0 == We’re proud to announce the third alpha release for the PowerDNS Recursor 4.3 release train. Note that a second alpha was tagged, but never released due to an issue found. A few major features are

Re: [Pdns-users] Weird wildcard behavior

2020-02-09 Thread Otto Moerbeek via Pdns-users
On Sun, Feb 09, 2020 at 01:29:25AM +0300, Gencer W. Genç via Pdns-users wrote: > Update: I have redefined all records i think i made a mistake on some > records. However, I still get infinite wildcard issues. That's the way DNS wildcards work. Non-intuitive and full of surprises. See e.g.

Re: [Pdns-users] PowerDNS Recursor 4.3.0 released

2020-03-03 Thread Otto Moerbeek via Pdns-users
On Tue, Mar 03, 2020 at 12:38:24PM +0100, Winfried Angele via Pdns-users wrote: > > > Hello Otto, > > Am 3. März 2020 10:33:11 MEZ schrieb Otto Moerbeek via Pdns-users > >... > >* When the recursor is started by systemd, the recursor will no longer >

Re: [Pdns-users] Are queries towards RPZ domains supposed to use the packet cache?

2020-02-24 Thread Otto Moerbeek via Pdns-users
On Mon, Feb 24, 2020 at 08:41:15AM +0100, Steinar Haug via Pdns-users wrote: > >> > Thank you, that got me a bit further. But I'm not where I want to be > >> > yet. DNSQuestion.variable will let me decide whether an answer should > >> > be inserted into the packet cache or not. But using this in

[Pdns-users] PowerDNS Recursor 4.3.0 released

2020-03-03 Thread Otto Moerbeek via Pdns-users
(via https://blog.powerdns.com/2020/03/03/powerdns-recursor-4-3-0-released/) Hello!, We are proud to announce the release of PowerDNS Recursor 4.3.0. Compared to the last release candidate, only two very minor issues were fixed. Compared to the 4.2 release of PowerDNS Recursor, the most

Re: [Pdns-users] Are queries towards RPZ domains supposed to use the packet cache?

2020-02-14 Thread Otto Moerbeek via Pdns-users
On Fri, Feb 14, 2020 at 03:06:10PM +0100, Steinar Haug via Pdns-users wrote: > >> I have previously used PowerDNS recursor and RPZ while treating all > >> query sources equally. This works fine. > >> > >> I'm now trying to use RPZ to block copyright type domains selectively > >> based on source

Re: [Pdns-users] Are queries towards RPZ domains supposed to use the packet cache?

2020-02-14 Thread Otto Moerbeek via Pdns-users
On Fri, Feb 14, 2020 at 03:34:37PM +0100, Otto Moerbeek via Pdns-users wrote: > On Fri, Feb 14, 2020 at 03:06:10PM +0100, Steinar Haug via Pdns-users wrote: > > > >> I have previously used PowerDNS recursor and RPZ while treating all > > >> query so

[Pdns-users] Second Release Candidate of PowerDNS Recursor 4.3.0

2020-02-18 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the second and hopefully last release candidate of what should become PowerDNS Recursor 4.3.0. Compared to the first release candidate, this release candidate changes the way RPZ policies are processed: if the matched policy is passthru, policies with a higher

Re: [Pdns-users] Are queries towards RPZ domains supposed to use the packet cache?

2020-02-10 Thread Otto Moerbeek via Pdns-users
On Mon, Feb 10, 2020 at 03:15:02PM +0100, Steinar Haug via Pdns-users wrote: > I have previously used PowerDNS recursor and RPZ while treating all > query sources equally. This works fine. > > I'm now trying to use RPZ to block copyright type domains selectively > based on source IP from the

[Pdns-users] PowerDNS Recursor 4.3.0 Beta 2

2020-01-16 Thread Otto Moerbeek via Pdns-users
Hello, (via: https://blog.powerdns.com/2020/01/16/second-beta-release-of-powerdns-recursor-4-3-0/ ) We are proud to announce the second beta release of what should become PowerDNS Recursor 4.3.0. Compared to the first beta release, this release fixes a two bugs related to DNSSEC validation.

Re: [Pdns-users] pdns-recursor Permissions Error

2020-01-10 Thread Otto Moerbeek via Pdns-users
It looks like the rec_control line your snmpd.conf is triggering the problem. Likely the snmd subsystem starts rec_control as a user that does not have permission to write into /var/run/pdns-recursor. You can try disabling (by commenting it out) the extend pdns-rec /usr/local/bin/pdns_stats

Re: [Pdns-users] disable-any-meta-query-type

2020-03-12 Thread Otto Moerbeek via Pdns-users
On Thu, Mar 12, 2020 at 10:30:39AM +, Rahal Sami via Pdns-users wrote: > Hi > > I would like to have a setting disable-any-meta-query-type=yes in pdns.conf > like this : > dig +nodnssec +short @ns5.cloudflare.com. ANY cloudflare.com > "RFC8482" "" > > > I use pdns version 3 . Short

Re: [Pdns-users] Auth and Recursor dedicated logging only

2020-04-09 Thread Otto Moerbeek via Pdns-users
On Thu, Apr 09, 2020 at 06:52:23PM +0200, Giovanni Vecchi via Pdns-users wrote: > Hi guys, > > how to configure both auth and recursor to log only on syslog facility (and > not on stdout)? > From docu it seems that syslog logging is an addition only. daemon=yes stops the logging to stdout.

Re: [Pdns-users] [Pdns-dev] First Alpha Release of PowerDNS Recursor 4.4.0

2020-04-24 Thread Otto Moerbeek via Pdns-users
On Wed, Apr 22, 2020 at 03:36:39PM +, Francis Turner via Pdns-users wrote: > In re > "* The ability to add custom tags[2] to RPZ hits." > > What is the best way to give some specific feedback / feature improvement > requests? A github issue would be appropriate, please include specifics

[Pdns-users] First Alpha Release of PowerDNS Recursor 4.4.0

2020-04-22 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first alpha release of what should become PowerDNS Recursor 4.4.0. This release contains various bug fixes, improvements and new features. The most important new features are * Native DNS64[1] support, without the need to use Lua. * The ability to add custom

Re: [Pdns-users] recursor fail to resolve

2020-05-04 Thread Otto Moerbeek via Pdns-users
On Fri, May 01, 2020 at 11:31:21AM -0500, Sergio P Cesar via Pdns-users wrote: > I am new with pdns, just installed a resolver 4.3.0-rc2 to learn and all > seems to work but stumbled into an issue I cant resolve. > > My mailserver failed to deliver email to a few domains, in tracking it I >

Re: [Pdns-users] recursor fail to resolve

2020-05-04 Thread Otto Moerbeek via Pdns-users
On Mon, May 04, 2020 at 07:05:48AM -0500, Sergio P Cesar wrote: > It is not a guessing game, the recursor fail to resolve. You initial email did not specify which name(s) were queried. Only later in the thread you list an example. Only with yor latest reply you tell something about your config.

[Pdns-users] PowerDNS Recursor 4.3.1, 4.2.2. and 4.1.16 released fixing multiple vulnerabilities

2020-05-19 Thread Otto Moerbeek via Pdns-users
Hello!, Today we are releasing PowerDNS Recursor 4.3.1, 4.2.2. and 4.1.16, containing security fixes for three CVEs: - CVE-2020-10995[1] - CVE-2020-12244[2] - CVE-2020-10030[3] The issues are: CVE-2020-10995: An issue in the DNS protocol has been found that allows malicious parties to use

Re: [Pdns-users] Serial lagging in authoritative 4.2.2 using native MySQL sync from 4.1.13

2020-05-15 Thread Otto Moerbeek via Pdns-users
On Thu, May 14, 2020 at 04:20:46PM +0300, Cristian Seres via Pdns-users wrote: > Hi, > > one of three authoritative name servers (ns3) which uses authoritative > version 4.2.2 gives older serial number than the other two which use version > 4.1.13. > > MySQL sync is working properly and as far

Re: [Pdns-users] Pdns RPZ logging

2020-03-20 Thread Otto Moerbeek via Pdns-users
On Thu, Mar 19, 2020 at 09:18:18AM +, Francis Turner via Pdns-users wrote: > All, > > > As you may know ThreatSTOP provides an RPZ service and it works on power DNS. > What doesn't quite work is logging and I'm trying to fix that. > > > My problem is that the documentation for what is

[Pdns-users] First Beta Release of PowerDNS Recursor 4.4.0

2020-08-31 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first beta release of what should become PowerDNS Recursor 4.4.0. Compared to the last alpha release, this release contains new features with respect to RPZ processing (in particular chasing of CNAMES from an RPZ and better logging of RPZ hit information in

Re: [Pdns-users] questions of understanding pdns-recursor with hosts-file

2020-09-09 Thread Otto Moerbeek via Pdns-users
On Tue, Sep 08, 2020 at 08:23:27AM +0200, Otto Moerbeek via Pdns-users wrote: > On Tue, Sep 08, 2020 at 06:05:40AM +, Markus Ehrlicher via Pdns-users > wrote: > > > Hello together, > > > > can anyone reproduce this problem or should I open a ticket on gi

Re: [Pdns-users] PowerDNS Recursor build fails on openSUSE Tumbleweed/Factory (gcc 10)

2020-09-09 Thread Otto Moerbeek via Pdns-users
On 2020-09-09 10:55, Michael Ströder via Pdns-users wrote: > On 9/8/20 11:49 AM, Remi Gacogne via Pdns-users wrote: >> On 9/8/20 11:39 AM, Michael Ströder via Pdns-users wrote: >> >>> Currently building PowerDNS Recursor fails building on openSUSE >>> Tumbleweed/Factory: >> >> It's an issue

Re: [Pdns-users] PowerDNS Recursor build fails on openSUSE Tumbleweed/Factory (gcc 10)

2020-09-09 Thread Otto Moerbeek via Pdns-users
On 2020-09-09 11:14, Otto Moerbeek via Pdns-users wrote: > > > On 2020-09-09 10:55, Michael Ströder via Pdns-users wrote: >> On 9/8/20 11:49 AM, Remi Gacogne via Pdns-users wrote: >>> On 9/8/20 11:39 AM, Michael Ströder via Pdns-users wrote: >>> >>>&g

Re: [Pdns-users] PowerDNS Recursor build fails on openSUSE Tumbleweed/Factory (gcc 10)

2020-09-09 Thread Otto Moerbeek via Pdns-users
On 2020-09-09 11:39, Otto Moerbeek via Pdns-users wrote: > > > On 2020-09-09 11:14, Otto Moerbeek via Pdns-users wrote: >> >> >> On 2020-09-09 10:55, Michael Ströder via Pdns-users wrote: >>> On 9/8/20 11:49 AM, Remi Gacogne via Pdns-users wrote: >>

Re: [Pdns-users] Slow query and SERVERFAIL from local pdns_recursor

2020-09-11 Thread Otto Moerbeek via Pdns-users
On Thu, Sep 10, 2020 at 03:40:54PM +0200, Christian Degenkolb via Pdns-users wrote: > Hi Thomas, > > what is a reasonable low value for udp-truncation-threshold? I tried with > 900 and 600 (as low as half the default value) but found no improvements. Try edns-outgoing-bufsize, that is the one

Re: [Pdns-users] Slow query and SERVERFAIL from local pdns_recursor

2020-09-08 Thread Otto Moerbeek via Pdns-users
On Tue, Sep 08, 2020 at 09:22:31AM +0200, Christian Degenkolb wrote: > (send again, first answer was not send cc to the ML) > > Hi, > > sorry for not sending any configs. pdns_recursor runs more or less with the > vanilla config with the following changes: > >

Re: [Pdns-users] questions of understanding pdns-recursor with hosts-file

2020-09-08 Thread Otto Moerbeek via Pdns-users
On Tue, Sep 08, 2020 at 06:05:40AM +, Markus Ehrlicher via Pdns-users wrote: > Hello together, > > can anyone reproduce this problem or should I open a ticket on github? I wanted to look into this, but I did not have time yet. Without looking at the code but knowing some details of the auth

[Pdns-users] PowerDNS Recursor 4.3.4 Released

2020-09-08 Thread Otto Moerbeek via Pdns-users
Hello!, Today we are releasing PowerDNS Recursor 4.3.4. This release: - fixes an issue where certain CNAMEs could lead to resolver failure, - fixes an issue with the hostname reported in Carbon messages, - allows for multiple recursor services to run under systemd. Please refer to the

Re: [Pdns-users] Slow query and SERVERFAIL from local pdns_recursor

2020-09-04 Thread Otto Moerbeek via Pdns-users
On Wed, Sep 02, 2020 at 09:44:37AM +0200, Christian Degenkolb via Pdns-users wrote: > Hi, > > I hope somebody on the ML can help me figure out what I'm doing wrong. > I have a local pdns_recursor (version 4.1.11-1+deb10u1 from debian 10) > runing and added it at the top of my /etc/resolve.conf

[Pdns-users] Second Release Candidate of PowerDNS Recursor 4.4.0

2020-10-06 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the second release candidate of what should become PowerDNS Recursor 4.4.0. Compared to the first release candidate, this release contains a few enhancements and fixes a few bugs. In particular, DS records of forwarded zones are handles properly and the parsing of

[Pdns-users] PowerDNS Recursor 4.3.5, 4.2.5. and 4.1.18 released fixing a cache pollution issue (CVE-2020-25829)

2020-10-13 Thread Otto Moerbeek via Pdns-users
Hello!, Today we are releasing PowerDNS Recursor 4.3.5, 4.2.5. and 4.1.18, containing a security fix for CVE-2020-25829[1]: An issue has been found in PowerDNS Recursor where a remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state,

[Pdns-users] PowerDNS Recursor 4.4.0 Released

2020-10-19 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the release of PowerDNS Recursor 4.4.0. Compared to the last release candidate, this release contains a fix for the cache pollution issue described in security advisory 2020-07[1]. Please refer to the changelog[2] for details. Compared to the 4.3 release of

Re: [Pdns-users] [EXT] Re: [Pdns-announce] PowerDNS Recursor 4.3.1, 4.2.2. and 4.1.16 released fixing multiple vulnerabilities

2020-05-20 Thread Otto Moerbeek via Pdns-users
On 2020-05-20 12:35, Kevin P. Fleming wrote: > The new packages aren't available for Raspbian yet; would someone > check the build systems for Raspbian? Thanks. The builds are slow, the packages should become available soon. -Otto > > On Tue, May 19, 2020 at 4:58 AM Otto Moerbeek via

Re: [Pdns-users] pdns recursor: forward-zones: load balancing and failover

2020-10-27 Thread Otto Moerbeek via Pdns-users
On Tue, Oct 27, 2020 at 08:32:29PM +0300, Egor Fatyushin via Pdns-users wrote: > Hello, > I have two authoritative DNS servers and I'd like to use them as two > replicas with the same set of records. Can I use 'forward-zones' for both > failover and load balancing features. > > I mean, if I have

[Pdns-users] PowerDNS Recursor 4.3.3 and 4.2.4 released

2020-07-17 Thread Otto Moerbeek via Pdns-users
Hello!, Today we are releasing PowerDNS Recursor 4.3.3 and 4.2.4. These releases fix an issue where the refresh time of a loaded RPZ zone was ignored. A DNSSEC issue that could lead to zones being marked Bogus wrongly and a few other DNSSEC related issues were also fixed. Please refer to the

[Pdns-users] PowerDNS Recursor 4.3.2, 4.2.3. and 4.1.17 released fixing CVE-2020-14196: Access restriction, bypass

2020-07-01 Thread Otto Moerbeek via Pdns-users
Hello!, Today we are releasing PowerDNS Recursor 4.3.2, 4.2.3. and 4.1.17, containing a security fix for CVE-2020-14196: Access restriction bypass[0]. An issue has been found in PowerDNS Recursor where the ACL applied to the internal web server via `webserver-allow-from` is not properly

Re: [Pdns-users] LUA createForward() records and improvement suggestions

2020-06-22 Thread Otto Moerbeek via Pdns-users
On Mon, Jun 22, 2020 at 10:11:30PM +0200, Michael Rommel via Pdns-users wrote: > > Dear all, > > a while ago (2020-03-01) I asked about setting up domains with LUA > createForward() > records. > > I suceeded in setting it up and found some peculiarities, which I would like > to > discuss

Re: [Pdns-users] LUA createForward() records and improvement suggestions

2020-06-23 Thread Otto Moerbeek via Pdns-users
On Tue, Jun 23, 2020 at 08:28:38AM +0200, Michael Rommel wrote: > Hi Otto, > > thanks for the pointer! AFAICT it covers my patches as well, looks a lot more > complicated, though. I'll take a closer look at it. > > Is there any reason, why it hasn't been merged yet? Any cases that would >

Re: [Pdns-users] Mysql cluster backend & rpz

2020-06-22 Thread Otto Moerbeek via Pdns-users
On Mon, Jun 22, 2020 at 10:07:07AM +, Bill Pye via Pdns-users wrote: > As a follow-up to my last post I have a question (or two) about using a mysql > cluster as the backend and using rpz. > > First, where does PDNS-recursor store the download zone for an rpz, is it in > the mysql db or

Re: [Pdns-users] Problem configuring rpz

2020-06-22 Thread Otto Moerbeek via Pdns-users
On Mon, Jun 22, 2020 at 09:57:13AM +, Bill Pye via Pdns-users wrote: > Hi all > > I'm a home user of your excellent software and by no means an expert in DNS. > A while ago I was experimenting with setting-up rpz files on my DNS servers, > that all worked OK. Recently I've been trying to

Re: [Pdns-users] dnstap problem

2020-06-22 Thread Otto Moerbeek via Pdns-users
On Sun, Jun 21, 2020 at 08:29:39PM +0100, Brian Candler via Pdns-users wrote: > I am trying to get dnstap to work with pdns-recursor 4.3.1-1pdns.bionic from > the powerdns repo, under Ubuntu 18.04, but failing. > > I want to send to a remote network destination.  I've added one line to >

Re: [Pdns-users] iprange is hitting my dns servers

2020-06-10 Thread Otto Moerbeek via Pdns-users
On Wed, Jun 10, 2020 at 09:53:43AM +0200, Steffan via Pdns-users wrote: > No there not its a ip[range here in the country > Ans looks like it is connected to ADSL lines > > But is it harmless? Yes. The message is a bit cryptic but it means the auth server supplied an answer containing trailing

Re: [Pdns-users] Recursor 4.3.1 problems with long CNAME chains

2020-06-05 Thread Otto Moerbeek via Pdns-users
On Fri, Jun 05, 2020 at 12:44:03PM +0200, Steinar Haug via Pdns-users wrote: > We recently upgraded from Recursor 4.2.1 to 4.3.1, due to the recent > security alert. Unfortunately, after this upgrade some queries have > stopped working. > > The examples below are from a test installation where

Re: [Pdns-users] [dnsdist] Fourth release candidate for dnsdist 1.5.0

2020-07-20 Thread Otto Moerbeek via Pdns-users
On Sun, Jul 19, 2020 at 12:29:05PM +0200, Stephane Bortzmeyer via Pdns-users wrote: > On Tue, Jul 07, 2020 at 04:41:00PM +0200, > Remi Gacogne via dnsdist wrote > a message of 84 lines which said: > > > While we expected the third release candidate for dnsdist 1.5.0 to be > > the last one,

[Pdns-users] Second Alpha Release of PowerDNS Recursor 4.4.0

2020-07-20 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the second alpha release of what should become PowerDNS Recursor 4.4.0. Compared to the first alpha release, this release mostly contains bug fixes and code cleanup. In particular, fixes already backported to the 4.3 release branch are included and a bug in the

[Pdns-users] PowerDNS Recursor 4.4.1 and 4.3.6 released

2020-11-25 Thread Otto Moerbeek via Pdns-users
Hello!, Today we are releasing PowerDNS Recursor 4.4.1 and 4.3.6. These releases fix a bug where a reply from an authoritative server could get lost, causing timeouts or ServFail answers to clients. Additionally, an issue resolving CNAMEs of the form a.b.c CNAME x.a.b.c when QName Minimization

[Pdns-users] PowerDNS Recursor 4.4.2 released

2020-12-14 Thread Otto Moerbeek via Pdns-users
Hello! Today we are releasing PowerDNS Recursor 4.4.2. This release fixes a bug where the wrong type could be used while verifying DNSSEC signatures, causing domains to be incorrectly marked as Bogus. Additionally, the recursor no longer resolves unneeded names when chasing CNAME records if

Re: [Pdns-users] Servfail spikes on PowerDNS authoritive

2020-11-02 Thread Otto Moerbeek via Pdns-users
On Mon, Nov 02, 2020 at 02:41:18PM +0100, Roman Steinhart via Pdns-users wrote: > Hi guys, > > We're running two PowerDNS authoritative instances v4.3.0/4.3.1 (upgraded > today) with a self-written remote backend. > > From time to time we see small, 1-2 minute long spikes of servfail >

[Pdns-users] PowerDNS Recursor 4.5.0 Alpa1 Released

2021-01-15 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first alpha release of what should become PowerDNS Recursor 4.5.0. This release contains various bug fixes, improvements and new features. The upcoming 4.5.0 release features a re-worked negative cache that is shared between threads, allowing

[Pdns-users] PowerDNS Recursor 4.4.4 and 4.5.2 Released

2021-06-09 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the release of PowerDNS Recursor 4.4.4. and 4.5.2. Both releases contain mostly smaller bug fixes. For the 4.5.2 release the default value of nsec3-max-iterations[1] has been lowered to 150, in accordance with new guidelines[2] and in coordination with

Re: [Pdns-users] ARM 64 bit OS support for pdns recursor

2021-05-11 Thread Otto Moerbeek via Pdns-users
On Tue, May 11, 2021 at 11:59:08PM +, Francis Turner via Pdns-users wrote: > I see the email about the dropping of support for 32 bit environments, which > includes Raspbian. Are you planning on making arm64 builds available? > > > Either the (beta not entirely released, but works) 64 bit

[Pdns-users] PowerDNS Recursor 4.5.1 Released

2021-05-11 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the release of PowerDNS Recursor 4.5.1. Compared to the release candidate, this release contains two bug fixes. Note that 4.5.0 was never released publicly, since an issue was found during QA. Compared to the previous major (4.4) release of

Re: [Pdns-users] Building for 32-bit platforms (was: PowerDNS Recursor 4.5.1 Released)

2021-05-11 Thread Otto Moerbeek via Pdns-users
On Tue, May 11, 2021 at 07:01:08PM +0200, Michael Ströder via Pdns-users wrote: > HI! > > Was support for running on 32-bit platforms dropped? > > configure fails with: > > configure: error: size of time_t is 4, which is not large enough to fix > the y2k38 bug > > See build system: > >

Re: [Pdns-users] DNS query logging via protobufServer

2021-06-02 Thread Otto Moerbeek via Pdns-users
On Wed, Jun 02, 2021 at 07:05:02PM -0500, Tod Sandman via Pdns-users wrote: > I have been successfully exporting DNS queries via protobufServer, but I have > now been requested to not export PTR lookups. I removed PTR queries from the > protobufServer exportTypes: > > < {'A', '',

Re: [Pdns-users] Web GUI Recursor

2021-07-02 Thread Otto Moerbeek via Pdns-users
On Thu, Jul 01, 2021 at 10:45:12AM +, Ralph via Pdns-users wrote: > Hi together, > > I have a simple question: > Can someone please tell me what’s the time interval of the „numbers“ section > on the PowerDNS recursor web gui? > There are lots of remote ips with query numbers. I can‘t find

[Pdns-users] PowerDNS Recursor 4.5.4 Released

2021-07-02 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the release of PowerDNS Recursor 4.5.4. This release contains a fix to an issue where the answer to a non-existent DS query was missing a SOA record. In particular this can be a problem if PowerDNS Recursor is used as a forwarding target by a validating

[Pdns-users] First Release Candidate of PowerDNS Recursor 4.5.0

2021-04-28 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first release candidate of what should become PowerDNS Recursor 4.5.0. Compared to the last beta release, this release contains a few minor bug fixes and improvements. Compared to the previous major (4.4) release of PowerDNS Recursor, this

Re: [Pdns-users] Recursor address in Dnstap messages

2021-03-23 Thread Otto Moerbeek via Pdns-users
On Tue, Mar 23, 2021 at 07:56:07AM +0100, Hans Seidel via Pdns-users wrote: > unfortunately, the identify field does not work since it just contains the > string "DNS". I will probably file a feature request via github as next > step. The recursor fills in the value of server-id, which can be

[Pdns-users] First Beta Release of PowerDNS Recursor 4.5.0

2021-03-26 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first beta release of what should become PowerDNS Recursor 4.5.0. This release contains various bug fixes, improvements and new features. This first beta contains a rewrite of the way zone cuts are determined, reducing the number of outgoing

Re: [Pdns-users] Ask for upgrade pdns authoritative from 4.1.3 to 4.4.1

2021-03-26 Thread Otto Moerbeek via Pdns-users
On Fri, Mar 26, 2021 at 12:09:11PM +, Brian Candler via Pdns-users wrote: > On 26/03/2021 11:59, Wafa BEN KHOUD via Pdns-users wrote: > > Please, can you describe me how upgrade pdns authoritative from 4.1.3 to > > 4.4.1? > > 1. Read the release notes for the intervening major versions, in

[Pdns-users] PowerDNS Recursor 4.4.3 Released

2021-03-31 Thread Otto Moerbeek via Pdns-users
Hello! Today we are releasing PowerDNS Recursor 4.4.3. This release fixes a bug where corrupted Newly Discovered Domain files could crash the recursor on startup and a bug where the wrong TTL could be used when inserting records into the packet cache. Additionally, a few minor

Re: [Pdns-users] CPU consumption of pdns_recursor

2021-04-05 Thread Otto Moerbeek via Pdns-users
On Mon, Apr 05, 2021 at 02:40:17PM +, Nejedlo, Mark via Pdns-users wrote: > We recently replaced some Bind servers with PowerDNS recursor, and were > rather surprised to see CPU usage essentially double for the same workload. > My expectation was that the load would be more or less

Re: [Pdns-users] Recursor can't resolve login.authorize.net.cdn.cloudflare.net

2021-04-07 Thread Otto Moerbeek via Pdns-users
On Tue, Apr 06, 2021 at 08:49:59PM +0100, Tony Finch via Pdns-users wrote: > Seth Mattinen via Pdns-users wrote: > > > > Here's a partial trace (list refused posting the full trace). From my eye it > > looks like I'm just getting ServFail from cloudflare NS, or possibly a > > DNSSEC > >

Re: [Pdns-users] CPU consumption of pdns_recursor

2021-04-06 Thread Otto Moerbeek via Pdns-users
On Mon, Apr 05, 2021 at 05:30:11PM +, Nejedlo, Mark via Pdns-users wrote: Some thoughts: 2 distributior thread feels a bit overkill, 1 distributor thread should be able to feed 8 workers. Did you do measurements to come to this value? Your maintenance function looks like it could run for a

Re: [Pdns-users] CPU consumption of pdns_recursor

2021-04-06 Thread Otto Moerbeek via Pdns-users
On Tue, Apr 06, 2021 at 02:18:33PM +, Nejedlo, Mark via Pdns-users wrote: > Both 4.4/5 and proxy protocol were on my radar, but my priority was to > address the CPU usage. If there's performance gains to be had in upgrading, > I can certainly do that. Is 4.5GA likely to happen soon?

[Pdns-users] PowerDNS Recursor Alpha3 Released

2021-03-09 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the third alpha release of what should become PowerDNS Recursor 4.5.0. This release contains various bug fixes, improvements and new features. The second alpha was an internal release only and never went public. The upcoming 4.5.0 release includes

Re: [Pdns-users] Error using pdnsutil with MySQL backend

2021-04-13 Thread Otto Moerbeek via Pdns-users
See https://docs.powerdns.com/authoritative/upgrading.html -Otto On Tue, Apr 13, 2021 at 01:25:29PM +, tach yon via Pdns-users wrote: > Hi Peter, > > Oh I see, there was a syntax change that I didn't encounter whilst testing on > a temporary slave. Good to know, thanks! > > Also

[Pdns-users] Second Beta Release of PowerDNS Recursor 4.5.0

2021-04-14 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the second beta release of what should become PowerDNS Recursor 4.5.0. Compared to the first beta release, this release contains a few bug fixes and improvements, in particular a bugfix concerning zones with "Stranded DNSKEYSs", zones that are signed

Re: [Pdns-users] Change of behaviour for dont-query between pdns-recursor 4.3 and 4.4

2021-08-09 Thread Otto Moerbeek via Pdns-users
On Mon, Aug 09, 2021 at 11:11:42AM +0100, Kim Covil via Pdns-users wrote: > Hi, > > I haven't managed to find a similar issue while searching. We are testing > Vyos 1.4 which uses powerdns recursor as its caching/forwarding name > service. We have noticed a behaviour change between pdns-recursor

[Pdns-users] PowerDNS Recursor 4.4.5. and 4.5.5 Released

2021-07-30 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the release of PowerDNS Recursor 4.4.5. and 4.5.5. Both releases contain an improvement to work around broken authoritative servers sending replies without the "authoritative answer" (AA) bit set. The 4.5.5 release contains a fix to an issue

Re: [Pdns-users] pdns-recursor suddenly started to answer with content from . zone instead of what is configured in forward.zones.

2021-09-21 Thread Otto Moerbeek via Pdns-users
On Tue, Sep 21, 2021 at 06:20:16PM +0200, Peter van Dijk via Pdns-users wrote: > Hello Thomas, > > On Tue, 2021-09-21 at 13:53 +0200, Thomas Mieslinger via Pdns-users > wrote: > > dog.80 IN NSEC domains. NS DS RRSIG NSEC > > This looks like aggressive NSEC reuse ( >

[Pdns-users] PowerDNS Recursor 4.4.6 Released

2021-10-08 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the release of PowerDNS Recursor 4.4.6. This release contains fixes to the way RPZ updates are handled and a fix to a case where traffic to a forwarder could be throttled while it should not. Please refer to the [1]change log for additional

[Pdns-users] PowerDNS Recursor 4.5.6 Released

2021-10-11 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the release of PowerDNS Recursor 4.5.6. This release contains fixes to the way RPZ updates are handled and a fix to a case where traffic to a forwarder could be throttled while it should not. Additionally a few minor DNSSEC validation issues and a

[Pdns-users] First Alpha release of PowerDNS Recursor 4.6.0

2021-09-29 Thread Otto Moerbeek via Pdns-users
We are proud to announce the first alpha release of PowerDNS Recursor 4.6.0. Compared to the previous major (4.5) release of PowerDNS Recursor, this release contains two major sets of changes: * a rewrite of the outgoing TCP code, adding both re-use of connections and

Re: [Pdns-users] resource-limits metrics

2021-10-24 Thread Otto Moerbeek via Pdns-users
On Sun, Oct 24, 2021 at 06:43:59PM +0200, Christoph via Pdns-users wrote: > Hi Remi, > > Remi Gacogne wrote: > > This counter is increased when we encounter a network issue that does > > not seem to be caused by the remote end but by a problem on our side, > > like if the recursor runs out of

[Pdns-users] PowerDNS Recursor 4.6.0 Released

2021-12-17 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the release of PowerDNS Recursor 4.6.0. Compared to the previous major (4.5) release of PowerDNS Recursor, this release contains several sets of changes: * The ability to flush records from the caches on a incoming notify[1] requests.

Re: [Pdns-users] ZoneToCache for root zone not working

2021-12-20 Thread Otto Moerbeek via Pdns-users
On Tue, Dec 21, 2021 at 10:28:53AM +0500, Jahanzeb Arshad via Pdns-users wrote: > Greeting, > > I am having trouble in getting zonetocache working for the root zone. I > am using PowerDNS Recursor 4.6.0. > > I have following in my /etc/powerdns/recursor.lua configuration: > >

Re: [Pdns-users] ZoneToCache for root zone not working

2021-12-21 Thread Otto Moerbeek via Pdns-users
On Tue, Dec 21, 2021 at 01:06:03PM +0500, Jahanzeb Arshad wrote: > Thanks for the clarity.  > > I tried to resolve some top level domains NS and still getting high > latency. > > > $ dig ae ns @localhost > > ;; omitting > > ;; ANSWER SECTION: > ae. 3600 IN NS ns2.aedns.ae. > ae. 3600 IN NS

[Pdns-users] Second beta release of PowerDNS Recursor 4.6.0.

2021-11-17 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the second beta release of PowerDNS Recursor 4.6.0. Compared to the previous major (4.5) release of PowerDNS Recursor, this release contains several sets of changes: * The ability to flush records from the caches on a incoming

Re: [Pdns-users] Zone to Cache: url method support in powerdns repo package

2021-11-09 Thread Otto Moerbeek via Pdns-users
On Wed, Nov 10, 2021 at 07:15:11AM +0100, Otto Moerbeek via Pdns-users wrote: > On Wed, Nov 10, 2021 at 12:31:20AM +0100, Christoph via Pdns-users wrote: > > > > > > > Otto Moerbeek via Pdns-users: > > > * A new Zone to Cache[1] function

Re: [Pdns-users] Zone to Cache: url method support in powerdns repo package

2021-11-09 Thread Otto Moerbeek via Pdns-users
On Wed, Nov 10, 2021 at 12:31:20AM +0100, Christoph via Pdns-users wrote: > > > Otto Moerbeek via Pdns-users: > > * A new Zone to Cache[1] function that will retrieve a zone (using > > AXFR, HTTP, HTTPS or a local file) periodically and insert the

Re: [Pdns-users] Zone to Cache: url method support in powerdns repo package

2021-11-10 Thread Otto Moerbeek via Pdns-users
On Wed, Nov 10, 2021 at 08:23:58AM +0100, Otto Moerbeek via Pdns-users wrote: > On Wed, Nov 10, 2021 at 07:15:11AM +0100, Otto Moerbeek via Pdns-users wrote: > > > On Wed, Nov 10, 2021 at 12:31:20AM +0100, Christoph via Pdns-users wrote: > > > > > > > >

Re: [Pdns-users] PDNS Recursor - force IPv6

2021-11-16 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 16, 2021 at 08:53:02AM +, Brian Candler wrote: > On 16/11/2021 08:29, Otto Moerbeek via Pdns-users wrote: > > > Is there possible to get similar to unbound command to force usage of > > > IPv6 in PDNS Recursor? > > > > > > prefer-i

Re: [Pdns-users] PDNS Recursor - force IPv6

2021-11-16 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 16, 2021 at 08:22:30AM +, Marcin Gondek via Pdns-users wrote: > Hello, > > Is there possible to get similar to unbound command to force usage of IPv6 in > PDNS Recursor? > > prefer-ip6: > If enabled, prefer IPv6 transport for sending DNS queries to internet > nameservers.

Re: [Pdns-users] ODP: PDNS Recursor - force IPv6

2021-11-16 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 16, 2021 at 12:10:02PM +0100, Thomas Mieslinger via Pdns-users wrote: > For reasons, I have been unable to debug, my recursive servers > frequently only do IPv4 although IPv6 connected and authoritatives are > also IPv6 connected. > > Warming the recursors caches with dig

Re: [Pdns-users] Zone to Cache: url method support in powerdns repo package

2021-11-10 Thread Otto Moerbeek via Pdns-users
On Wed, Nov 10, 2021 at 11:31:53PM +0100, Christoph via Pdns-users wrote: > > > > > msg="Unable to load zone into cache, will retry" subsystem="ztc" > > > > > level=0 > > > > > ts="1636499834.251" exception="url method configured but libcurl not > > > > > compiled in" refresh="60" zone="." > > >

Re: [Pdns-users] overall cache hit rate in a dnsdist -> recursor environment

2021-10-28 Thread Otto Moerbeek via Pdns-users
On Thu, Oct 28, 2021 at 07:20:59PM +0200, Christoph via Pdns-users wrote: > Hi, > > > I'd like to calculate the overall percentage of > queries that got completely answered with a cached entry, > regardless of the type of cache (packet cache or not) and regardless > of whether the cache was in

[Pdns-users] Second alpha release of PowerDNS Recursor 4.6.0

2021-10-25 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the second alpha release of PowerDNS Recursor 4.6.0. Compared to the previous major (4.5) release of PowerDNS Recursor, this release contains several sets of changes: * A rewrite of the outgoing TCP code, adding both re-use of

[Pdns-users] First beta release of PowerDNS Recursor 4.6.0

2021-11-09 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the first beta release of PowerDNS Recursor 4.6.0. Compared to the previous major (4.5) release of PowerDNS Recursor, this release contains several sets of changes: * A rewrite of the outgoing TCP code, adding both re-use of connections

[Pdns-users] PowerDNS Recursor 4.4.7. and 4.5.7 released

2021-11-05 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the release of PowerDNS Recursor 4.4.7. and 4.5.7. Both releases are maintenance releases correcting an issue where a DS record with a SHA-256 digest could be ignored if a DS record with SHA-384 digest is also present. The 4.5.7 release also

[Pdns-users] First release candidate of PowerDNS Recursor 4.6.0.

2021-12-03 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the first release candidate of PowerDNS Recursor 4.6.0. Compared to the beta2 release, this release fixes an issue with incoming queries over TCP and with the systemd unit file for virtual hosting. Compared to the previous major (4.5) release of

Re: [Pdns-users] PowerDNS Recursor Performance and Tuning

2022-01-16 Thread Otto Moerbeek via Pdns-users
On Sun, Jan 16, 2022 at 09:39:01AM +0330, Hamed Haghshenas via Pdns-users wrote: > Hello Dears, > > > > I install PowerDNS Recursor 4.6.0 on CentOS Linux release 7.9.2009. and > configure it as bellow for Iran IP address. I want use it in my ISP > environment for large scale and lots of DNS

Re: [Pdns-users] PowerDNS Recursor Performance and Tuning

2022-01-16 Thread Otto Moerbeek via Pdns-users
On Sun, Jan 16, 2022 at 09:05:55AM +0100, Otto Moerbeek via Pdns-users wrote: > On Sun, Jan 16, 2022 at 09:39:01AM +0330, Hamed Haghshenas via Pdns-users > wrote: > > > Hello Dears, > > > > > > > > I install PowerDNS Recursor 4.6.0 on CentOS Li

Re: [Pdns-users] PowerDNS Recursor Performance and Tuning

2022-01-16 Thread Otto Moerbeek via Pdns-users
On Sun, Jan 16, 2022 at 01:11:55PM +0330, Hamed Haghshenas wrote: > Hello, > Thanks for your help. I changed them . > > > If you have 8G of RAM, likely the default cache sizes could be enlarged > (max-cache-entries for the record cache and max-packetcache-entries for the > packet cache) > > how

Re: [Pdns-users] PowerDNS Recursor Performance and Tuning

2022-01-16 Thread Otto Moerbeek via Pdns-users
On Sun, Jan 16, 2022 at 10:01:42AM +, Brian Candler wrote: > On 16/01/2022 09:41, Hamed Haghshenas via Pdns-users wrote: > > > quiet=no > > I need the logs and should export domains to my analyzer platform . > > There are more scalable ways of doing this.  The "standards-compliant" way > is

  1   2   3   >