Re: rndc-key has expired

2011-03-23 Thread Eivind Olsen
> I edit the file named.conf > modification > update-policy { > grant * self * A TXT; > }; > to update-policy local; > it seems more logical. > but I'm still stuck on the validation of isc dlv. the script tells me > lost keys Which script? What exactly does it say? I'm guessing you mi

Reverse dns issue

2011-03-23 Thread Olivier Destras
Hi, I'm using a software which uses bind and I'm experiencing a problem with the reverse dns function of bind. I only have private adresses on my network but the nodes also have dns names. There is a server on this network, which is also a name server, that has internet through a gateway. When

Re: rndc-key has expired

2011-03-23 Thread fakessh @
I use and bind rndc and dlv isc for dnssec my zone config like this zone "renelacroute.fr" { type master; file "/var/named/renelacroute.fr.hosts"; auto-dnssec maintain; update-policy local; key-directory "/var/named/keys/"; allow-transfer { 213.2

Re: openssl pkcs#11 engine patch

2011-03-23 Thread Billy Glynn
Hi Emil, For me, I had the same problem. I'm running RHEL5, openssl-0.9.8l with the ISC patch and integrating with the AEP Keyper PKCS#11 lib. After applying the ISC patch, I found that this worked for me: # ./Configure linux-elf -m32 -pthread --pk11-libname=/opt/Keyper/PKCS11Provider/pkcs11.so

Re: rndc-key has expired

2011-03-23 Thread fakessh @
hi isc hi list hi guru of bind errors continue to recur rndc-key expired But I apply the command for create the key dnssec-keygen -a HMAC-MD5 -b 512 -n HOST rndc-key Le mercredi 23 mars 2011 à 16:24 +0100, fakessh @ a écrit : > I use and bind rndc and dlv isc for dnssec > my zone config like

Re: rndc-key has expired

2011-03-23 Thread Joseph S D Yao
What is this??? To: "fakessh @" On Tue, Mar 22, 2011 at 02:59:22PM +0100, fakessh @ wrote: > hi bind guru > > > It appears after the log that my signature rndc-key has expired. how to > update it > -- > gpg --keyserver pgp.mit.edu --recv-key 092164A7 > http://pgp.mit.edu:11371/pks/lookup?op

Re: rndc-key has expired

2011-03-23 Thread fakessh @
hi guru I'm walking on the same server rndc and named Le mercredi 23 mars 2011 à 14:46 -0400, Joseph S D Yao a écrit : > What is this??? To: "fakessh @" > > > On Tue, Mar 22, 2011 at 02:59:22PM +0100, fakessh @ wrote: > > hi bind guru > > > > > > It appears after the log that my signature

Re: rndc-key has expired

2011-03-23 Thread fakessh @
I can wait how long before this ends? Le mercredi 23 mars 2011 à 14:46 -0400, Joseph S D Yao a écrit : > What is this??? To: "fakessh @" > > > On Tue, Mar 22, 2011 at 02:59:22PM +0100, fakessh @ wrote: > > hi bind guru > > > > > > It appears after the log that my signature rndc-key has ex

Re: Reverse dns issue

2011-03-23 Thread Mark Andrews
In message <4d8a0386.3080...@laas.fr>, Olivier Destras writes: > Hi, > > I'm using a software which uses bind and I'm experiencing a problem with > the reverse dns function of bind. > I only have private adresses on my network but the nodes also have dns > names. There is a server on this netwo

Q on clients-per-query, max-clients-per-query

2011-03-23 Thread Fr34k
Hello, # The ARM says: # clients-per-query, max-clients-per-query These set the initial value (minimum) and maximum number of recursive simultaneous clients for any given query () that the server will accept before dropping additional clients. named will attempt to self tune this value and chan

Re: rndc-key has expired

2011-03-23 Thread Mark Andrews
In message <1300893881.12273.67.camel@localhost.localdomain>, "fakessh @" write s: > I use and bind rndc and dlv isc for dnssec=20 > my zone config like this > > > zone "renelacroute.fr" { > type master; > file "/var/named/renelacroute.fr.hosts"; > auto-dnssec maintain;

Re: Q on clients-per-query, max-clients-per-query

2011-03-23 Thread Mark Andrews
In message <60834.75625...@web121403.mail.ne1.yahoo.com>, Fr34k writes: > Hello, > > # The ARM says: # > clients-per-query, max-clients-per-query > These set the initial value (minimum) and maximum number of recursive > simultaneous clients for any given query () that the serv > er > will accep