daemon warning

2014-06-30 Thread Stewart, Larry C Sr CTR DISA JITC (US)
I just finished compiling BIND 9.10.0-P2 on my Solaris 10 x86 platform. I am replacing BIND 9.6-ESV-R7-P4 which I have been running in a chroot environment I have configured the Solaris service admin to run /nithr/sbin/named -t /dns -u dnsuser when I start the dns server now since I have upgrade

incomplete NSEC3 chains

2014-06-30 Thread Klaus Darilion
Release: BIND 9.9.5 I regularly perform key rollovers and zone validation of an inline-signed zone. The zone validator receives NOTIFYs and then it transfers the zone and validates it (using dnssec-verify and validns). I also regularly call "rndc retransfer" to make sure to have an correct zone.

rate-limit and Facebook IP's

2014-06-30 Thread Reindl Harald
am i the only one facing all day long serveral facebook networks hit RRL on both nameservers? for me there are only two options to explain that: * facebook is too dumb to cache responses (TTL a day) * that's part of a well distributed amplification trying not make much noise on the single involv