Re: DNSSEC auto-dnssec issue bind-9.7.2-P3

2011-01-21 Thread Zbigniew Jasiński
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 W dniu 2011-01-19 18:38, Hauke Lampe pisze: Another thing you might check: With dnssec-enable no; in named.conf, BIND still does its automatic DNSSEC signing but won't add RRSIG to responses. I ran across such a configuration lately. Your

Re: DNSSEC auto-dnssec issue bind-9.7.2-P3

2011-01-21 Thread Kalman Feher
The only way I can replicate the behaviour is with dnssec-enable no or with an unsigned version of the zone in another view. Assuming you've not overlapped your views in such a way (it was a very contrived test), I think you'll need to provide a bit more information on your configuration.

Re: DNSSEC auto-dnssec issue bind-9.7.2-P3

2011-01-21 Thread Zbigniew Jasiński
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 W dniu 2011-01-21 11:23, Kalman Feher pisze: The only way I can replicate the behaviour is with dnssec-enable no or with an unsigned version of the zone in another view. Assuming you've not overlapped your views in such a way (it was a very

Re: get a domain's dns records

2011-01-21 Thread Joseph S D Yao
On Fri, Jan 21, 2011 at 02:19:45PM +0800, p...@mail.nsbeta.info wrote: I'm jsut curious, how does who.is know the dns records in my domain (nsbeta.info)? The page shows some of my RRs exactly: http://who.is/dns/nsbeta.info/ The title of the page is, Nsbeta.info DNS Lookup |

Re: get a domain's dns records

2011-01-21 Thread Barry Margolin
In article mailman.1415.1295616325.555.bind-us...@lists.isc.org, Joseph S D Yao j...@tux.org wrote: On Fri, Jan 21, 2011 at 02:19:45PM +0800, p...@mail.nsbeta.info wrote: I'm jsut curious, how does who.is know the dns records in my domain (nsbeta.info)? The page shows some of my

Re: when one view doesn't have the zone

2011-01-21 Thread Barry Margolin
In article mailman.1407.1295579612.555.bind-us...@lists.isc.org, p...@mail.nsbeta.info wrote: In fact I want to the clients that match view_b to fall into the default view, say it's view_c. There is no fall-through in views. The search stops when it finds the first view that matches.

Re: get a domain's dns records

2011-01-21 Thread Dave Knight
On 2011-01-21, at 8:50 AM, Barry Margolin wrote: In article mailman.1415.1295616325.555.bind-us...@lists.isc.org, Joseph S D Yao j...@tux.org wrote: On Fri, Jan 21, 2011 at 02:19:45PM +0800, p...@mail.nsbeta.info wrote: I'm jsut curious, how does who.is know the dns records in my domain

Re: get a domain's dns records

2011-01-21 Thread Phil Mayers
On 21/01/11 13:50, Barry Margolin wrote: In articlemailman.1415.1295616325.555.bind-us...@lists.isc.org, Joseph S D Yaoj...@tux.org wrote: On Fri, Jan 21, 2011 at 02:19:45PM +0800, p...@mail.nsbeta.info wrote: I'm jsut curious, how does who.is know the dns records in my domain

Re: get a domain's dns records

2011-01-21 Thread pyh
Dave Knight writes: I guess the tool just always assumes that there's probably a www worthy asking about But how does the site know I have a sub domain test.nsbeta.info and its name servers? I didn't think that I have got this sub domain be public. Regards.

Re: DNSSEC auto-dnssec issue bind-9.7.2-P3

2011-01-21 Thread Kalman Feher
On 21/01/11 2:05 PM, Zbigniew Jasiński szo...@nask.pl wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 W dniu 2011-01-21 11:23, Kalman Feher pisze: The only way I can replicate the behaviour is with dnssec-enable no or with an unsigned version of the zone in another view. Assuming

Re: get a domain's dns records

2011-01-21 Thread Torinthiel
Dnia 2011-01-21 08:50 Barry Margolin napisał(a): In article mailman.1415.1295616325.555.bind-us...@lists.isc.org, Joseph S D Yao j...@tux.org wrote: On Fri, Jan 21, 2011 at 02:19:45PM +0800, p...@mail.nsbeta.info wrote: I'm jsut curious, how does who.is know the dns records in my domain

RE: get a domain's dns records

2011-01-21 Thread Todd Snyder
It seems to do a regular lookup, plus maybe an ANY But I've also noticed that it seems to find test.domain.com. I often put a 'test.whatever.com. IN A 127.0.0.1' into zones and a couple I checked it found them, even though it shouldn't have by normal means it also found a 'blog' record I had

RE: get a domain's dns records

2011-01-21 Thread Lightner, Jeff
It checks for test.domain - I saw it do that for my zone. For us it isn't a subdomain but simply an A record. Apparently when it found your record it went ahead and did another check for your sub-zone. I'm surprised that it does not check for ftp.zone. Whenever we're doing acquisitions here

Re: get a domain's dns records

2011-01-21 Thread Phil Mayers
On 21/01/11 14:21, p...@mail.nsbeta.info wrote: Dave Knight writes: I guess the tool just always assumes that there's probably a www worthy asking about But how does the site know I have a sub domain test.nsbeta.info and its name servers? I didn't think that I have got this sub domain be

Re: why queries rejected?

2011-01-21 Thread John Wobus
It might not be your bug. It might be other sites. As was said, bind can log info that would help explain it. Or if the number is rising continuously, you can capture a bunch of dns queries with tcpdump or a similar program and look over a sample of the rejected queries. On Jan 18, 2011, at

BIND 9.8.0b1 Released Today

2011-01-21 Thread Sue Graves
Introduction BIND 9.8.0b1 is the first beta release of BIND 9.8. This document summarizes changes from BIND 9.7 to BIND 9.8. Please see the CHANGES file in the source code release for a complete list of all changes. Download The latest development versions of BIND 9 software can always be found

failed multi-view zone transfer

2011-01-21 Thread jeffreyp
greetings, i'm in the midst of an odd problem (to me, anyway) and would appreciate any pointers. three servers, all running bind-9.7.2-P3 compiled from source with the same options. one master; two slaves. two views: internal and external. one master and one slave are on the same subnet

Re: BIND 9.8.0b1 Released Today

2011-01-21 Thread pyh
Sue Graves writes: New Features 9.8.0 * BIND now supports a new zone type, static-stub. This allows the administrator of a recursive nameserver to force queries for a particular zone to go to IP addresses of the administrator's choosing, on a per zone basis, both globally or per view. I.e.

Re: BIND 9.8.0b1 Released Today

2011-01-21 Thread JINMEI Tatuya / 神明達哉
At Fri, 21 Jan 2011 14:00:19 -0500 (EST), Paul Wouters p...@xelerance.com wrote: * BIND now supports a new zone type, static-stub. This allows the administrator of a recursive nameserver to force queries for a particular zone to go to IP addresses of the administrator's choosing, on a