Re: [Pdns-users] How to create zone via API?

2024-04-01 Thread Otto Moerbeek via Pdns-users
On Mon, Apr 01, 2024 at 04:57:08PM +0700, Bino Oetomo via Pdns-users wrote: > Dear All. > > I'm trying to playing with PDNS API. > > I try to create new zone. > > The json payload is : > ``` > { > "name": "domain07.bino.", > "kind": "Native", > "records": [ > { >

Re: [Pdns-users] Recursor getting pegged at 100% CPU

2024-03-15 Thread Otto Moerbeek via Pdns-users
On Fri, Mar 15, 2024 at 05:25:20PM +0100, Otto Moerbeek via Pdns-users wrote: > > Op 15 mrt. 2024, om 17:01 heeft Tim Burns via Pdns-users > > het volgende geschreven: > > > > Hello all, I’m experiencing a performance degradation while using the > > Recursor th

Re: [Pdns-users] Recursor getting pegged at 100% CPU

2024-03-15 Thread Otto Moerbeek via Pdns-users
> Op 15 mrt. 2024, om 17:01 heeft Tim Burns via Pdns-users > het volgende geschreven: > > Hello all, I’m experiencing a performance degradation while using the > Recursor that I haven’t been able to root cause, and I was hoping to get some > insight on what might be causing it, or some

Re: [Pdns-users] Understanding why pdns-recursor 4.8.6 queries DS extremely often

2024-03-12 Thread Otto Moerbeek via Pdns-users
On Tue, Mar 12, 2024 at 08:43:20AM +0100, Thomas Mieslinger via Pdns-users wrote: > While analyzing a spam run, I found the following queries and responses > for the not delegated domain YALRDRK.net > > For _dmarc.ja<> the queries and responses look as expected. > > For default._bimi.jaqg<> a

[Pdns-users] PowerDNS Recursor 4.8.7, 4.9.4 and 5.0.3 released

2024-03-07 Thread Otto Moerbeek via Pdns-users
Hello, Today we have released PowerDNS Recursor 4.8.7, 4.9.4 and 5.0.3. These releases are maintenance releases that fix a few bugs. The most important ones are: * The regression with respect to the ZoneToCache function in the preceding releases has been solved. *

Re: [Pdns-users] DNSSEC: How to add TA for . to recursor of self hosted . zone

2024-03-04 Thread Otto Moerbeek via Pdns-users
On Mon, Mar 04, 2024 at 05:01:12PM +0100, Jan Huijsmans via Pdns-users wrote: > Hello, > > I'm tryting to setup a DNSSEC lab environment with an isolated DNS set. > > Service setup: > > Servers > - hidden master root server (pdns-auth 4.6.3-1) > - queriable slave root servers (pdns-auth

Re: [Pdns-users] pdns-recursor help

2024-02-18 Thread Otto Moerbeek via Pdns-users
On Sun, Feb 18, 2024 at 01:35:04AM -0800, Bill MacAllister wrote: > On 2024-02-17 23:30, Otto Moerbeek wrote: > > On Sat, Feb 17, 2024 at 06:07:16PM -0800, Bill MacAllister wrote: > > > > > Okay, I set "dnssec=off" and look ups are working now. Guess I > > > need to educate myself about dnssec.

Re: [Pdns-users] pdns-recursor help

2024-02-17 Thread Otto Moerbeek via Pdns-users
On Sat, Feb 17, 2024 at 06:07:16PM -0800, Bill MacAllister wrote: > On 2024-02-17 12:08, Bill MacAllister via Pdns-users wrote: > > On 2024-02-17 00:31, Otto Moerbeek wrote: > > > > Your recursor is not able to get an answer from the root servers, at > > > least not for DS queries. > > > > > >

Re: [Pdns-users] pdns-recursor help

2024-02-17 Thread Otto Moerbeek via Pdns-users
On Sat, Feb 17, 2024 at 12:22:06AM -0800, Bill MacAllister via Pdns-users wrote: > I am new to Power DNS and am attempting to setup a Power DNS recursor > server. I am using Debian bookworm and I have installed the pdns-recursor > package. The server is listening and dig can connect to the

[Pdns-users] PowerDNS Recursor Security Advisory 2024-01

2024-02-13 Thread Otto Moerbeek via Pdns-users
Today we have released PowerDNS Recursor 4.8.6, 4.9.3 and 5.0.2. These releases fix PowerDNS Security Advisory 2024-01: crafted DNSSEC records in a zone can lead to a denial of service in Recursor. The Advisory follows: PowerDNS Security Advisory 2024-01: crafted DNSSEC records in a

Re: [Pdns-users] QNAME minimization support

2024-02-10 Thread Otto Moerbeek via Pdns-users
On Sat, Feb 10, 2024 at 10:41:12AM +0100, Otto Moerbeek via Pdns-users wrote: > On Fri, Feb 09, 2024 at 08:39:16PM -0800, Ask Bjørn Hansen via Pdns-users > wrote: > > > > > > > > On Feb 9, 2024, at 14:30, Jason Tremblett via Pdns-users > > > wrote

Re: [Pdns-users] QNAME minimization support

2024-02-10 Thread Otto Moerbeek via Pdns-users
On Fri, Feb 09, 2024 at 08:39:16PM -0800, Ask Bjørn Hansen via Pdns-users wrote: > > > > On Feb 9, 2024, at 14:30, Jason Tremblett via Pdns-users > > wrote: > > > > When querying with QNAME minimization on strict, the authoritative server > > is queried for entry.sample.zone and returns

Re: [Pdns-users] Any chance of an actual PowerDNS upgrade guide ?

2024-01-12 Thread Otto Moerbeek via Pdns-users
On Fri, Jan 12, 2024 at 05:01:18PM +, Laura Smith via Pdns-users wrote: > Hi > > The release notes for PowerDNS Recursor 5.0.1 link to what is claimed to be > an "upgrade guide", however the "guide" reads more like a version change log. > > Is there any chance we can actually be provided

[Pdns-users] PowerDNS Recursor 5.0.1 Released

2024-01-10 Thread Otto Moerbeek via Pdns-users
Hello, We are proud to announce the release of PowerDNS Recursor 5.0.1! This is the first public release of the 5.0 branch. Compared to the latest 4.9 release, this release features the ability to read settings from YAML files, enhancing structure, processing and error-checking

[Pdns-users] Second Release Candidate of PowerDNS Recursor 5.0.0

2023-12-20 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the second release candidate of PowerDNS Recursor 5.0.0. Compared to the latest 4.9 release, this pre-release features the ability to read settings from YAML files, enhancing structure, processing and error-checking of settings. There is also

[Pdns-users] First Release Candidate of PowerDNS Recursor 5.0.0

2023-12-06 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first release candidate of PowerDNS Recursor 5.0.0. Compared to the latest 4.9 release, this pre-release features the ability to read settings from YAML files, enhancing structure, processing and error-checking of settings. There is also

[Pdns-users] First beta release of PowerDNS Recursor 5.0.0

2023-11-10 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the first beta release of PowerDNS Recursor 5.0.0. Compared the the latest 4.9 release, this pre-release features the ability to read settings from YAML files, enhancing structure, processing and error-checking of settings. There is also an

[Pdns-users] PowerDNS Recursor 4.9.2 Releases

2023-11-08 Thread Otto Moerbeek via Pdns-users
Hello! Today we have released PowerDNS Recursor 4.9.2. This release is a maintenance release that fixes a few bugs and contains a few improvements. The most important ones are: * Two cache management edge cases that can occur when serve-stale is enabled have been

Re: [Pdns-users] Recursor 4.8.x Debian 12 repo

2023-10-31 Thread Otto Moerbeek via Pdns-users
The rec-4.8.5 Debian 12 package is now available again from our repo. Regards, -Otto > On 30/10/2023 15:23 CET Otto Moerbeek via Pdns-users > wrote: > > > Hello, > > an error crept into ont of the publishing proceses. > > I built a rec-4.8.5 for Debian 12,

Re: [Pdns-users] Recursor Container Issue

2023-10-31 Thread Otto Moerbeek via Pdns-users
Hello Alberto, It would help if you exactly describe what you did, with command line and the recursor.conf you used. That way we can try to reproduce. Also, did you check log messages from the recursor? It almost sounds like the recursor did not start because of an issue with the

Re: [Pdns-users] Recursor 4.8.x Debian 12 repo

2023-10-30 Thread Otto Moerbeek via Pdns-users
Hello, an error crept into ont of the publishing proceses. I built a rec-4.8.5 for Debian 12, which can be retrieved here: https://github.com/PowerDNS/pdns/actions/runs/6693473758/job/18184678477 We wil also make sure the package gets published in the regular place. This might take some time

Re: [Pdns-users] LUA for "filter-aaaa-on-v4"

2023-10-30 Thread Otto Moerbeek via Pdns-users
On Mon, Oct 30, 2023 at 04:35:25AM +, Djerk Geurts via Pdns-users wrote: > Hi all, > > Not had the opportunity to test this yet, but wanted to check with those more > experienced at LUA scripting if the following has any unexpected side effects: > > function preresolve(dq) > --

Re: [Pdns-users] pdns stop responding and restarted himself

2023-10-19 Thread Otto Moerbeek via Pdns-users
On Thu, Oct 19, 2023 at 11:36:13AM +0200, Steffan via Pdns-users wrote: > Hello, > > > > I have 2 dns servers. > Both running on centos with his own replicated mysql backends > > > > Yesterday both dns servers stopped responding for 3 minutes. > > In the periode of 3 minutes I see a lot

[Pdns-users] Second Alpha Release of PowerDNS Recursor 5.0.0

2023-10-17 Thread Otto Moerbeek via Pdns-users
Hello, We are proud to announce the second alpha release of PowerDNS Recursor 5.0.0. Compared the the latest 4.9 release, this pre-release features the ability to read settings from YAML files, enhancing structure, processing and error-checking of settings. There is also an

Re: [Pdns-users] Error prio events with loglevel 2

2023-09-17 Thread Otto Moerbeek via Pdns-users
On Sun, Sep 17, 2023 at 12:32:11PM +0200, Christoph via Pdns-users wrote: > Thanks for looking into this. > I've filed it as a github issue now. > > As a workaround I'm now trying to block these DNS queries in dnsdist, so > they do not reach recursor and the logs: > > addAction(QTypeRule(qtype

Re: [Pdns-users] Error prio events with loglevel 2

2023-09-16 Thread Otto Moerbeek via Pdns-users
On Sat, Sep 16, 2023 at 05:40:42PM +0200, Otto Moerbeek via Pdns-users wrote: > On Sat, Sep 16, 2023 at 05:19:01PM +0200, Otto Moerbeek via Pdns-users wrote: > > > On Sat, Sep 16, 2023 at 12:04:16PM +0200, Christoph via Pdns-users wrote: > > > > > Hello, > >

Re: [Pdns-users] Error prio events with loglevel 2

2023-09-16 Thread Otto Moerbeek via Pdns-users
On Sat, Sep 16, 2023 at 05:19:01PM +0200, Otto Moerbeek via Pdns-users wrote: > On Sat, Sep 16, 2023 at 12:04:16PM +0200, Christoph via Pdns-users wrote: > > > Hello, > > > > we changed our recursor loglevel from 3 to 2 with the intention to avoid > > logging the

Re: [Pdns-users] Error prio events with loglevel 2

2023-09-16 Thread Otto Moerbeek via Pdns-users
On Sat, Sep 16, 2023 at 12:04:16PM +0200, Christoph via Pdns-users wrote: > Hello, > > we changed our recursor loglevel from 3 to 2 with the intention to avoid > logging these events because they contain qnames: > > msg="qtype unsupported" error="Cannot push task" subsystem="taskq" level="0" >

Re: [Pdns-users] edns

2023-09-14 Thread Otto Moerbeek via Pdns-users
I asked for complete, unedited configs, both old and new. This waay I cannot help you. -Otto On Fri, Sep 15, 2023 at 02:09:11AM -0300, Alex Trevisol wrote: > in my old configuration it was enough to activate the option > # edns-subnet-whitelist List of netmasks and domains that we

Re: [Pdns-users] edns

2023-09-14 Thread Otto Moerbeek via Pdns-users
On Fri, Sep 15, 2023 at 12:49:56AM -0300, Alex Trevisol via Pdns-users wrote: > hello, > > I reinstalled my recuersor server, and took advantage of it and installed > pdns-recursor 4.9, but I did the basic configuration and activated Edns in > the same way it was before. >

[Pdns-users] First Alpha Release of PowerDNS Recursor 5.0.0

2023-09-13 Thread Otto Moerbeek via Pdns-users
We are proud to announce the first alpha release of PowerDNS Recursor 5.0.0. This pre-release features the ability to read settings from YAML files, enhancing structure, processing and error-checking of settings. There is also an internal change: the code processing the YAML file

Re: [Pdns-users] IXFR with PowerDNS

2023-09-12 Thread Otto Moerbeek via Pdns-users
On Mon, Sep 11, 2023 at 11:44:57AM +0200, Thomas Mieslinger via Pdns-users wrote: > Hi all, > > I switched an Active Directory Zone to IXFR instead of AXFR. > > When doing AXFR all records have "auth=1" in the MySQL Backend. > > When doing IXFR the individually updated records get "auth=0"

Re: [Pdns-users] Recursor Cache Sizing: Is more always better?

2023-09-10 Thread Otto Moerbeek via Pdns-users
On Sun, Sep 10, 2023 at 02:37:49PM +0200, Christoph via Pdns-users wrote: > > Another word of advice: see > > > > https://docs.powerdns.com/recursor/performance.html#threading-and-distribution-of-queries > > > > in particular the "imbalance" section. > > Thanks for the pointer, changing this

Re: [Pdns-users] Recursor Cache Sizing: Is more always better?

2023-09-09 Thread Otto Moerbeek via Pdns-users
On Sat, Sep 09, 2023 at 11:20:30AM +0200, Christoph via Pdns-users wrote: > > Agrreed, I think that general rules are hard to give for cache sizing, > > as each site and its users are different. Do remember that the packet > > cache was changed in 4.9.0, it is now shared between threads. This

Re: [Pdns-users] Recursor forwarder DoT configuration

2023-09-09 Thread Otto Moerbeek via Pdns-users
On Sat, Sep 09, 2023 at 08:07:02AM +0200, Christoph via Pdns-users wrote: > > I do wonder about the purpose of the recursor in the > > > > recursor -> dnsdist -> upstream-recursive > > > > case. You might as well use > > > > dnsdist -> upstream-recursive > > > > With a caching dnsdist. > >

Re: [Pdns-users] Recursor Cache Sizing: Is more always better?

2023-09-09 Thread Otto Moerbeek via Pdns-users
On Sat, Sep 09, 2023 at 09:59:19AM +0200, Winfried via Pdns-users wrote: > Hi Christoph, > > My recommendation is to limit the TTL to 12 or 6 hours and find out how many > cache entries are created during this time. Increase that by 50% and that's > your value. You'll see that it doesn't

Re: [Pdns-users] Recursor forwarder DoT configuration

2023-09-08 Thread Otto Moerbeek via Pdns-users
On Fri, Sep 08, 2023 at 11:56:07PM +0200, Christoph via Pdns-users wrote: > Thanks a lot for the fast reply, very much appreciated! > best regards, > Christoph I do wonder about the purpose of the recursor in the recursor -> dnsdist -> upstream-recursive case. You might as well use dnsdist

Re: [Pdns-users] Recursor forwarder DoT configuration

2023-09-08 Thread Otto Moerbeek via Pdns-users
On Fri, Sep 08, 2023 at 04:50:18PM +0200, Christoph via Pdns-users wrote: > Hello! > > I'm looking for documentation about configuring > recursor to talk DoT to a recursive resolver. > > This minimal config works: > > dot-to-port-853=yes > forward-zones-recurse=.=1.1.1.1:853;1.0.0.1:853 > >

Re: [Pdns-users] CPU Usage Regression in Recursor 4.9.1?

2023-09-04 Thread Otto Moerbeek via Pdns-users
On Mon, Sep 04, 2023 at 10:49:23AM +0200, Otto Moerbeek via Pdns-users wrote: > On Mon, Sep 04, 2023 at 10:30:38AM +0200, Christoph via Pdns-users wrote: > > > > > > Thanks, recursor is now running with aggressive-nsec-cache-size=0 > > > and I'll repor

[Pdns-users] PowerDNS Recursor 4.9.0 Released

2023-06-30 Thread Otto Moerbeek via Pdns-users
We are proud to announce the release of PowerDNS Recursor 4.9.0. Compared to the previous major (4.8) release of PowerDNS Recursor, this release contains the following major changes: * The performance impact of metrics collection has been reduced by using lock-free

Re: [Pdns-users] Pdns recursor - forward-zones-file not working

2023-06-19 Thread Otto Moerbeek via Pdns-users
On Mon, Jun 19, 2023 at 05:10:01PM +0100, Djerk Geurts via Pdns-users wrote: > Hi all, > > Reading up on recursor settings I found that with forward-zones-file one can > set recurse an RD flag and also add domains to an allow-notify-for list. > > "Zones prefixed with a ‘+’ are treated as with

Re: [Pdns-users] signatures were invalid: EXPKEYSIG 1B0C6205FD380FBB

2023-06-07 Thread Otto Moerbeek via Pdns-users
On Wed, Jun 07, 2023 at 06:03:29PM +0200, Otto Moerbeek via Pdns-users wrote: > On Wed, Jun 07, 2023 at 04:26:53PM +0100, Djerk Geurts via Pdns-users wrote: > > > Hi all, > > > > Is there an issue with the Ubuntu repo? I changes a host from > > foca

Re: [Pdns-users] signatures were invalid: EXPKEYSIG 1B0C6205FD380FBB

2023-06-07 Thread Otto Moerbeek via Pdns-users
On Wed, Jun 07, 2023 at 04:26:53PM +0100, Djerk Geurts via Pdns-users wrote: > Hi all, > > Is there an issue with the Ubuntu repo? I changes a host from > focal-auth-master to focal-auth-48 and encountering a GPG error, previously > the GPG key had been updated but I see the normal key listed

Re: [Pdns-users] Issues with forward-zones-recurse

2023-06-03 Thread Otto Moerbeek via Pdns-users
On Fri, Jun 02, 2023 at 08:07:16PM -0300, Thiago G. Alencar via Pdns-users wrote: > Hello, > > I have a strange situation. When the "forward-zones-recurse" option is > activated, after the expiration of record type A in the cache, the next > queries will have no response but will be NOERROR. >

[Pdns-users] First Beta Release of PowerDNS Recursor 4.9.0

2023-06-02 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the first beta release of PowerDNS Recursor 4.9.0. Compared to the previous major (4.8) release of PowerDNS Recursor, this release contains the following major changes: * The performance impact of metrics collection has been reduced by

[Pdns-users] Solution Engineer PowerDNS

2023-05-31 Thread Otto Moerbeek via Pdns-users
Hello, PowerDNS is looking for a Solutions Engineer to strengthen our Professional Services team. See

Re: [Pdns-users] LUA SRV records

2023-05-30 Thread Otto Moerbeek via Pdns-users
On Tue, May 30, 2023 at 11:33:32AM +0200, Kai Stian Olstad via Pdns-users wrote: > On 29.05.2023 15:44, George Asenov via Pdns-users wrote: > > Hello community, > > > > I already searched the documentation but couldn't find an answer to my > > questions. > > > > Is it possible to add LUA SRV

Re: [Pdns-users] DoT for recursor

2023-05-09 Thread Otto Moerbeek via Pdns-users
On Tue, May 09, 2023 at 01:34:51PM +0100, Djerk Geurts via Pdns-users wrote: > Hi all, > > Had a look and the only thing I could find is that DoT apparently is enabled > when configuring PowerDNS-recursor with specific upstream servers on port 853. > > Being relatively new to DoT and DoH I’m

[Pdns-users] First Alpha Release of PowerDNS Recursor 4.9.0

2023-04-12 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the first alpha release of PowerDNS Recursor 4.9.0. Compared to the previous major (4.8) release of PowerDNS Recursor, this release contains the following major changes: * The performance impact of metrics collection has been reduced by

[Pdns-users] PowerDNS Security Advisory 2023-02: Deterred spoofing attempts can lead to authoritative servers being marked unavailable

2023-03-29 Thread Otto Moerbeek via Pdns-users
Hello, Today we have released PowerDNS Recursor 4.6.6, 4.7.5 and 4.8.4 due to a low severity security issue found. Please find the full text of the advisory below. The [1]4.6, [2]4.7 and [3]4.8 changelogs are available. The [4]4.6.6 ([5]signature), [6]4.7.5 ([7]signature)

Re: [Pdns-users] How to create an account?

2023-03-26 Thread Otto Moerbeek via Pdns-users
The account field is just a text field that has no relation to any other field in the pdns data model. You can fill in anything you like. -Otto On Sun, Mar 26, 2023 at 04:35:05PM +0200, Paul van der Vlis via Pdns-users wrote: > Hello! > > I connot find how to create an account with

Re: [Pdns-users] Howto show settings of a domain

2023-03-15 Thread Otto Moerbeek via Pdns-users
On Tue, Mar 14, 2023 at 01:19:18PM +0100, Paul van der Vlis via Pdns-users wrote: > Hello, > > How can I show the settings of a domain with pdnsutil? I don't mean the > records, but settings like what you can set with commands as: > pdnsutil set-kind > pdnsutil set-account > pdnsutil

[Pdns-users] PowerDNS Recursor 4.8.3 Released

2023-03-07 Thread Otto Moerbeek via Pdns-users
Hello!, We are proud to announce the release of PowerDNS Recursor 4.8.3 This release is a maintenance release. The most important fixes concern the serve-stale functionality which could cause intermittent high CPU load. The serve-stale function is disabled by default. Please

Re: [Pdns-users] Blocklist file format

2023-03-06 Thread Otto Moerbeek via Pdns-users
There is, check RPZs: https://docs.powerdns.com/recursor/lua-config/rpz.html -Otto On Tue, Mar 07, 2023 at 08:46:54AM +0200, Adrian M via Pdns-users wrote: > Having a policy list implemented directly in pdns-resolver it will be a > very nice feature nowadays IMHO. > > On Sun, Mar 5,

[Pdns-users] PowerDNS Recursor 4.8.2 Released

2023-01-31 Thread Otto Moerbeek via Pdns-users
Hello, We are proud to announce the release of PowerDNS Recursor 4.8.2. This release is a maintenance release, fixing some issues, in particular: * Record and negative cache cleaning now maintains balance between shards in a better way * A case where the wrong EDNS

Re: [Pdns-users] tsig key not being accepted

2023-01-30 Thread Otto Moerbeek via Pdns-users
On Sat, Jan 28, 2023 at 09:58:22AM -0500, Larry Wapnitsky via Pdns-users wrote: > (domain names and keys changed in production from these values) > > I'm running the following: > > root@ns1:~# pdns_server --version > Jan 28 09:54:21 PowerDNS Authoritative Server >

Re: [Pdns-users] pdns_recursor issue

2023-01-26 Thread Otto Moerbeek via Pdns-users
On Thu, Jan 26, 2023 at 10:57:21PM +0100, Arien Vijn wrote: > > > On 26 Jan 2023, at 19:00, Otto Moerbeek wrote: > > [...] > > > I expect the aggressive cache workaround to function. > > It seems so indeed. > > > What is happening is that a query of a non-existent type (e.g. ) > > for

Re: [Pdns-users] pdns_recursor issue

2023-01-26 Thread Otto Moerbeek via Pdns-users
On Thu, Jan 26, 2023 at 05:37:12PM +0100, Arien Vijn via Pdns-users wrote: > Hi Peter, > > > On 26 Jan 2023, at 17:28, Peter van Dijk via Pdns-users > > wrote: > > [...] > > > After some brief investigation we somewhat suspect this is aggressive > > NSEC caching. Can you see if

Re: [Pdns-users] Proxy mapped address used for allow-from

2023-01-26 Thread Otto Moerbeek via Pdns-users
On Thu, Jan 26, 2023 at 03:07:17PM +0200, Robby Pedrica via Pdns-users wrote: > Thanks Otto, > > I agree with the docs, but then the actual operation/result is not > consistent unless I'm misunderstanding the operation or purpose of > proxy-protocol-from. > > *Product:* > > pdns-recursor > >

Re: [Pdns-users] pdns_recursor issue

2023-01-26 Thread Otto Moerbeek via Pdns-users
Hi, Please show your configuration. I do not think your analysis is to the point. If I repeat a scenario, I see a correct retrieval of the A record. So we have to find out what is different in your case. -Otto On Thu, Jan 26, 2023 at 01:30:54PM +0100, Arien Vijn via Pdns-users wrote:

Re: [Pdns-users] Proxy mapped address used for allow-from

2023-01-20 Thread Otto Moerbeek via Pdns-users
Please show your full configuration, including versions etc. Also, it is not clear which product you are using. The recursor docs say: "Note that once a Proxy Protocol header has been received, the source address from the proxy header instead of the address of the proxy will be checked against

[Pdns-users] Security Advisory 2023-01 for PowerDNS Recursor 4.8.0

2023-01-20 Thread Otto Moerbeek via Pdns-users
Hello, Today we have released PowerDNS Recursor 4.8.1 due to a high severity issue found. Please find the full text of the advisory below. The [1]changelog is available. The [2]tarball ([3]signature) is available from our download [4]server. Patches are available at

Re: [Pdns-users] Reloading metadata with bind-backend & sqlite

2022-12-19 Thread Otto Moerbeek via Pdns-users
Hello, You did not explain what you seeing and what you expect. The warning concerns performance. But your questions suggests you are seeing wrong data. Please be explicit. -Otto On Mon, Dec 19, 2022 at 11:02:34AM +0100, Thib D via Pdns-users wrote: > Hi Chris, > > I missed this

[Pdns-users] PowerDNS Recursor 4.8.0 Released

2022-12-12 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the release of PowerDNS Recursor 4.8.0. Compared to the previous major (4.7) release of PowerDNS Recursor, this release contains the following major changes: * [1]Structured Logging has been implemented for almost all subsystems. This

Re: [Pdns-users] why different parameters syntax on forward-zones and forward-zones-file

2022-11-29 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 29, 2022 at 09:55:54AM -0500, Kevin P. Fleming via Pdns-users wrote: > On Tue, Nov 29, 2022, at 08:45, Victor Hugo dos Santos via Pdns-users wrote: > > hello there, > > > > today we have to migrate an old configuration (what was using the > > forward-zones-file) to a new server using

Re: [Pdns-users] Recursor Cache entries per record

2022-11-28 Thread Otto Moerbeek via Pdns-users
Hello What Winfried says is true, with the note that a few more bits of the query are included in the hash, while some other pats are skipped; e.g. the recursor skips the EDSN ECS and Cookie bits when computing the hash. Also note that while the packet cache is per thread, the other cache

[Pdns-users] PowerDNS Recursor 4.5.12, 4.6.5 and 4.7.4 Released

2022-11-25 Thread Otto Moerbeek via Pdns-users
Hello, Today we have released a maintenance release of PowerDNS Recursor 4.5.12, 4.6.5 and 4.7.4, containing fixes for a few minor issues. In particular, RPZ IXFRs now time out if the server becomes unresponsive. For more details on the other fixes, consult the changelogs

[Pdns-users] First Release Candidate of PowerDNS Recursor 4.8.0

2022-11-18 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the first release candidate of PowerDNS Recursor 4.8.0. We invite all users to test this release candidate, so that we can release the final PowerDNS Recursor 4.8.0 soon. Compared to the previous major (4.7) release of PowerDNS Recursor, this

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-16 Thread Otto Moerbeek via Pdns-users
You start complaining within the hour. That is not thay way to get a response. I just lost all the motivation to help you. -Otto On Thu, Nov 17, 2022 at 12:17:01PM +0530, Raghvendra Choudhary via Pdns-users wrote: > any update on this? > > *Raghvendra Choudhary* > DevOps Engineer |

Re: [Pdns-users] DNS-over-TLS option

2022-11-14 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 15, 2022 at 11:36:44AM +1300, Michael Hallager wrote: > On 2022-11-14 19:29, Otto Moerbeek wrote: > > > The upgrade guide has pointers, but in this case there's also a blog > > post: > > > >

Re: [Pdns-users] DNS-over-TLS option

2022-11-13 Thread Otto Moerbeek via Pdns-users
On Mon, Nov 14, 2022 at 11:26:41AM +1300, Michael Hallager via Pdns-users wrote: > > Hi all, > > I am seeing the following option during compilation of PowerDNS Recursor, > however, can't find any documentation on its configuration. > > configure: Features enabled > configure:

Re: [Pdns-users] Recursor: NS selection logic, multiple IPs in forward-zones statement

2022-11-10 Thread Otto Moerbeek via Pdns-users
On Wed, Nov 09, 2022 at 09:00:12PM +0300, Andrey Vishnyakov via Pdns-users wrote: > Hi! > > What is the logic of pdns recursor choosing NS server when multiple items > are available like multiple IP addresses in a forward-zones statement? > > Looking through the source code I see that NS

Re: [Pdns-users] pdns-recursor ecs support config designs

2022-11-08 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 08, 2022 at 09:44:22AM +, Brian Candler via Pdns-users wrote: > On 08/11/2022 09:20, Robby Pedrica via Pdns-users wrote: > > > The CDN services work correctly when a branch uses the ISP-assigned DNS > > for that specific branch/link. But as mentioned, it's difficult to > > manage

Re: [Pdns-users] pdns-recursor ecs support config designs

2022-11-07 Thread Otto Moerbeek via Pdns-users
On Tue, Nov 08, 2022 at 08:35:33AM +0200, Robby Pedrica via Pdns-users wrote: > Hi all, > > I've searched pdns docs as well as threads here but can find nothing about > how to deploy ecs or more specifically, under which circumstance ecs can be > used. > > From what I understand of ecs, the

[Pdns-users] Second Beta Release of PowerDNS Recursor 4.8.0

2022-11-07 Thread Otto Moerbeek via Pdns-users
Hello, We are proud to announce the second beta release of PowerDNS Recursor 4.8.0. Compared to the previous major (4.7) release of PowerDNS Recursor, this release contains the following major changes: * [1]Structured Logging has been implemented for almost all

Re: [Pdns-users] pdns-recursor query logging of cached requests

2022-11-03 Thread Otto Moerbeek via Pdns-users
On Thu, Nov 03, 2022 at 02:08:53PM +0100, Marco Kleefman via Pdns-users wrote: > Hi, > > For compliancy reasons we are configuring query logging on our PowerDNS > recursor instances (running 4.7.3). > > For normal queries I see source-ip and content of DNS question. Example > logging: > >

Re: [Pdns-users] Help with "simple" config please

2022-10-31 Thread Otto Moerbeek via Pdns-users
Hello, Please read the [1]link below and post unedited config files. It also helps to explictly state the problem you are trying to solve, what commands you used to investigate, what you expected to see and what you actually saw. -Otto [1]

Re: [Pdns-users] Repeating log file entry for root server

2022-10-28 Thread Otto Moerbeek via Pdns-users
Hello, a.root-servers.net is the default name used by the dnsdist health checks. So no worries. With respect to pdns_recursor: logging all queries (with quiet=no) hurts performance. In general, you do not want to enable it on a production machine. -Otto On Fri, Oct 28, 2022 at

Re: [Pdns-users] Warning in syslog after upgrade to PowerDNS Authoritative Server 4.7

2022-10-28 Thread Otto Moerbeek via Pdns-users
Hello, 4.7.0 introduced (optional) GSS-TSIG support. Even with that support not compiled in will report about GSS-TSIG requests it could not handle. That might generate too much log spam, will discuss if this message should stay, maybe the level should be Debug. There is also a typo there: an

Re: [Pdns-users] PowerDNS Authoritative Server 4.7.0

2022-10-28 Thread Otto Moerbeek via Pdns-users
This is known, a 4.7.1 will be released very soon with this fixed. -Otto On Fri, Oct 28, 2022 at 07:12:03AM +, Henri Nougayrede via Pdns-users wrote: > Hi > > Same for ubuntu 4.7 .deb package. > I ran the SQL script >

[Pdns-users] First Beta Release of PowerDNS Recursor 4.8.0

2022-10-05 Thread Otto Moerbeek via Pdns-users
Hello, We are proud to announce the first beta release of PowerDNS Recursor 4.8.0. Compared to the previous major (4.7) release of PowerDNS Recursor, this release contains the following major changes: * [1]Structured Logging has been implemented for almost all subsystems.

Re: [Pdns-users] Protobuf - Telegraf

2022-10-01 Thread Otto Moerbeek via Pdns-users
On Sat, Oct 01, 2022 at 12:56:45AM +0100, Djerk Geurts via Pdns-users wrote: > Hi, > > Has anyone managed to get Protobuf output logged through Telegraf? Telegraf > is supposed to support Protobuf input but I’m getting the following error: > > … E! [inputs.socket_listener] Unable to parse

Re: [Pdns-users] structured logging [was: First Alpha Release of PowerDNS Recursor 4.8.0]

2022-09-23 Thread Otto Moerbeek via Pdns-users
On Fri, Sep 23, 2022 at 12:48:06PM +0200, Jan-Piet Mens via Pdns-users wrote: > > * [1]Structured Logging has been implemented for almost all > > subsystems. This allows for improved (automated) analysis of > > logging information. > > Is there any further documentation about

[Pdns-users] First Alpha Release of PowerDNS Recursor 4.8.0

2022-09-23 Thread Otto Moerbeek via Pdns-users
Hello! We are proud to announce the first alpha release of PowerDNS Recursor 4.8.0. Compared to the previous major (4.7) release of PowerDNS Recursor, this release contains the following major changes: * [1]Structured Logging has been implemented for almost all

Re: [Pdns-users] pdns-recursor (4.6) empty response after expiration of the TTL of the cached record

2022-09-22 Thread Otto Moerbeek via Pdns-users
On Thu, Sep 22, 2022 at 11:40:35AM +0200, Leeflangetje via Pdns-users wrote: > Thank you for digging into the issue with that domain :) > > The reason we never encountered this before the upgrade to 4.6 must be > the change in default behaviour regarding dnssec , which went from >

Re: [Pdns-users] pdns-recursor (4.6) empty response after expiration of the TTL of the cached record

2022-09-22 Thread Otto Moerbeek via Pdns-users
On Thu, Sep 22, 2022 at 09:41:57AM +0200, abang--- via Pdns-users wrote: > The "NSEC3 proving non-existence" of this zone is broken. See > https://dnsviz.net/d/riecis.nl/dnssec/?rr=all=all=all=on=.= > > You can workaround this issue by setting a NTA for it on your Recursors. It > is

Re: [Pdns-users] pdns-recursor (4.6) empty response after expiration of the TTL of the cached record

2022-09-22 Thread Otto Moerbeek via Pdns-users
When trying to check this domain I get an occasinal error: $ dig @1.1.1.1 riecis.nl ; <<>> dig 9.10.8-P1 <<>> @1.1.1.1 riecis.nl ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 30228 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 1,

[Pdns-users] PowerDNS Recursor 4.5.11, 4.6.4 and 4.7.3 Released

2022-09-20 Thread Otto Moerbeek via Pdns-users
Hello, Today we have released a maintenance release of PowerDNS Recursor 4.5.11, 4.6.4 and 4.7.3, containing fixes for a few minor issues and performance enhancements in the case Recursor is confronted with connectivity issues to authoritative servers. The changelogs are

Re: [Pdns-users] Will DoT disappear in favor of DoQ for recursor to auth?

2022-09-18 Thread Otto Moerbeek via Pdns-users
No plans. Currently, Recursor does not support outgoing DoQ. If/when we start supporting outgoing DoQ it would not *imply* dropping outgoing DoT. BTW, lookingt at https://talk.desec.io/t/dot-support-status/502: when I grep for desec I see this: 45.54.76.1 desec.io. 6 Good

Re: [Pdns-users] PDNS recursor cache sync

2022-09-17 Thread Otto Moerbeek via Pdns-users
Cache maintenace is alreayd quite a complex part of any recursor. IMO adding cache syncing would introduce way too much complexity te be worth the trouble to solve what in essense is a questionable firewall rule design. Maybe dnsdist with a packet cache in front of two recursors might be worth

Re: [Pdns-users] PDNS recursor cache sync

2022-09-17 Thread Otto Moerbeek via Pdns-users
Hello, cachs syncing is not something we have and even with it (or using a single resolver) there is an issue that records can change: the scenario: - a client asks the record, record gets cached - client A asks and gets cached value, - publisher of records changes the

Re: [Pdns-users] [dnsdist] Dnsdist not reading from the cache

2022-09-11 Thread Otto Moerbeek via Pdns-users
Please read https://blog.powerdns.com/2016/01/18/open-source-support-out-in-the-open/ -Otto On Fri, Sep 09, 2022 at 04:22:26PM +, SAMI RAHAL via Pdns-users wrote: > hi abang > > > yes i just changed the values in the email > for privacy reasons but it's the same value in the

Re: [Pdns-users] Is there any way to write an LUA record that will apply over multiple query names?

2022-09-06 Thread Otto Moerbeek via Pdns-users
On Tue, Sep 06, 2022 at 01:18:06AM -0400, Mohammad Ishtiaq Ashiq Khan via Pdns-users wrote: > Hello, > I am currently using PowerDNS as an authoritative server for my domain and > was experimenting with dynamic DNS via LUA records. From the documentation, > it seems like the LUA record is

[Pdns-users] Sharing data between threads in PowerDNS Recursor

2022-08-29 Thread Otto Moerbeek via Pdns-users
Hello, I just posted a new blog post: https://blog.powerdns.com/2022/08/29/sharing-data-between-threads-in-powerdns-recursor/ It describes some of the work we've done over the last few releases with respect to sharing of data between threads in PowerDNS Recursor. -Otto -- kind regards,

Re: [Pdns-users] Recursive Forwarders

2022-08-24 Thread Otto Moerbeek via Pdns-users
ries, 7% packet cache hits > Aug 24 16:12:17 cache1 pdns_recursor[491939]: stats: thread 0 has been > distributed 109 queries > Aug 24 16:12:17 cache1 pdns_recursor[491939]: stats: thread 1 has been > distributed 87 queries > > On Wed, Aug 24, 2022 at 4:02 PM Otto Moerbeek via Pdn

Re: [Pdns-users] Recursive Forwarders

2022-08-24 Thread Otto Moerbeek via Pdns-users
On Wed, Aug 24, 2022 at 09:51:49PM +0200, Leendert Meyer via Pdns-users wrote: > Hello Timothy, > > On Wednesday, 24 August 2022 20:09:11 CEST Holmes, Timothy via Pdns-users > wrote: > > > > > forward-zones-recurse=.=9.9.9.9;149.112.112.112;1.1.1.2;1.0.0.2 > > and also tried

Re: [Pdns-users] Recursive Forwarders

2022-08-24 Thread Otto Moerbeek via Pdns-users
On Wed, Aug 24, 2022 at 03:41:34PM -0400, Holmes, Timothy wrote: > Config is very default.. [snip] This file is mangled with the extra line wrappings. Also I do not see any forward-zones-recurse settings there. Please provide complete, actual amd unmangled information. -Otto

Re: [Pdns-users] Recursive Forwarders

2022-08-24 Thread Otto Moerbeek via Pdns-users
instance for the specified forwarder(s). > > > > > > I did confirm that dig's etc to 9.9.9.9 etc in CLI do allow just fine, so > > > there is no local firewall blockage. > > > > > > Any other thoughts? Seems odd, but I am new to PDNS.. > > > > Pl

Re: [Pdns-users] Recursive Forwarders

2022-08-24 Thread Otto Moerbeek via Pdns-users
am new to PDNS.. Please show the startup log. -Otto > > Best, Tim > > > > On Wed, Aug 24, 2022 at 3:13 PM Otto Moerbeek wrote: > > > On Wed, Aug 24, 2022 at 09:05:46PM +0200, Otto Moerbeek via Pdns-users > > wrote: > > > > > On Wed, Aug

Re: [Pdns-users] Recursive Forwarders

2022-08-24 Thread Otto Moerbeek via Pdns-users
On Wed, Aug 24, 2022 at 09:05:46PM +0200, Otto Moerbeek via Pdns-users wrote: > On Wed, Aug 24, 2022 at 02:09:11PM -0400, Holmes, Timothy via Pdns-users > wrote: > > > Hi Team, > > > > I have what I hope is a simple question I'm unable to find a better answer > &

  1   2   3   >