about server failure cache

2009-06-16 Thread liuqiang
hi, A recursive name server A receives a recursive query from a client,but the authoritative name server B for the query zone is dead. So name server A return a server failure answer to the client. I want to konw if name server A send a query to name server B when another client ask the

Re: queries with no RD bit set are truncating

2009-06-16 Thread Peter Andreev
Kevin, this server is totally non-recursive. Neither recurse option is enabled and packet size does not exceed 512 byte. May be it was some temporarly bugs due to mysterious causes. Below I post full sniffer's output for both queries: No. TimeSourceDestination

Re: Validating a DNSSEC installation

2009-06-16 Thread Chris Thompson
On Jun 15 2009, Chris Buxton wrote: On Jun 13, 2009, at 4:59 AM, Erik Lotspeich wrote: Is it normal that a validating resolver can't validate a domain it is authoritative for? Absolutely. As Alan Clegg wrote not long ago on this list, You presumably refer to https://lists.isc.org/pipermai

Re: Questions about DNAME records

2009-06-16 Thread Chris Buxton
On Jun 16, 2009, at 1:37 AM, Braebaum, Neil wrote: What I was getting at - probably worded poorly - was say I wanted to provide resolution for something like:- _service._tcp.example.com. if I'd previously created the DNAME record (example.com.IN DNAME example2.com.), would cre

Re: Questions about DNAME records

2009-06-16 Thread Michael Milligan
Chris Buxton wrote: > On Jun 15, 2009, at 2:37 AM, Braebaum, Neil wrote: > Now, ignoring that invalid "www" record, the zone above has an apex > (example.com itself) and then essentially infinite ghostly children. Any > valid query that lands in that domain (i.e. the qname ends in > example.com) bu

DNSDigger.com - An announcement and request for feature tips.

2009-06-16 Thread Jay Ess
DNSDigger.com - A massive reverse resolver that lets you dig deeper into the Net. DNSDigger.com is a service that lets you get more information about an domain name. It can show you what other domain names is hosted on a server. For example can that information be a valuable data for a hosting

Re: queries with no RD bit set are truncating

2009-06-16 Thread Mark Andrews
In message , Peter Andreev writes: > Kevin, this server is totally non-recursive. Neither recurse option is > enabled and packet size does not exceed 512 byte. May be it was some > temporarly bugs due to mysterious causes. I suspect someone has modified the server to mitigate it

RE: DNSDigger.com - An announcement and request for feature tips.

2009-06-16 Thread Frank Bulk
Sounds interesting. How is it different than these?: http://whois.webhosting.info http://www.domaintools.com/reverse-ip/ Frank -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Jay Ess Sent: Tuesday, June 16, 2009 7:19 PM To:

dynamic dns updates from cisco router dhcp

2009-06-16 Thread Dan Letkeman
Hello, I have setup dynamic dns updates from a cisco router which is handing out dhcp addresses. In the debug's i'm getting messages that say REFUSED and SERVFAIL when trying to do a dynamic update. I'm unsure as to where the problem lies, but I think it might have to do with the security on the

Re: DNSDigger.com - An announcement and request for feature tips.

2009-06-16 Thread Joe Baptista
Can DNSdigger see .GOD? What about .SATAN. Does DNSdigger see the Peking University on the China National TLD DNS? What happens if I ask it a question on the domain 北京大学.中国 or the equivalent ascii IDN of xn--1lq90ic7fzpc.xn--fiqs8s ? Well I tried digger. I know it does not speak Chinese, Peaki

Re: DNSDigger.com - An announcement and request for feature tips.

2009-06-16 Thread Joe Baptista
On Tue, Jun 16, 2009 at 10:36 PM, Frank Bulk wrote: > Sounds interesting. > > How is it different than these?: > http://whois.webhosting.info That one is a bit wacky. It tells me the TLD for the Peking University Domain Name : "xn--1lq90ic7fzpc.xn--fiqs8s" is Invalid! That's a lie. 300 milli

create journal file: permission denied

2009-06-16 Thread Dan Letkeman
Hello, I'm trying to setup ddns and the log file is showing that it cannot create the journal file 16-Jun-2009 22:03:30.145 update: info: client 172.16.56.111#63970: updating zone 'dan.net/IN': error: journal open failed: unexpected error 16-Jun-2009 22:03:30.211 update: info: client 172.16.56.1

Re: create journal file: permission denied

2009-06-16 Thread Mark Andrews
In message , Dan Le tkeman writes: > Hello, > > I'm trying to setup ddns and the log file is showing that it cannot > create the journal file > > > 16-Jun-2009 22:03:30.145 update: info: client 172.16.56.111#63970: > updating zone 'dan.net/IN': error: journal open failed: unexpected > error > 1

Re: Validating a DNSSEC installation

2009-06-16 Thread Chris Buxton
On Jun 16, 2009, at 4:08 AM, Chris Thompson wrote: On Jun 15 2009, Chris Buxton wrote: On Jun 13, 2009, at 4:59 AM, Erik Lotspeich wrote: Is it normal that a validating resolver can't validate a domain it is authoritative for? Absolutely. As Alan Clegg wrote not long ago on this list, You

Re: Validating a DNSSEC installation

2009-06-16 Thread Erik Lotspeich
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Chris, Thanks for your response -- that explains it. I hope that you don't mind if I continue this discussion with another question. I changed my configuration to use views to separate my external zone (for which BIND is authoritative) from inter