Does the CVE-2011-1910 vulnerability affect the BIND 9.7.0-P2?

2011-06-10 Thread YABUKI Youichi
The BIND security advisory for CVE-2011-1910 does not mention about versions 9.7.0, 9.7.0-P1 and 9.7.0-P2. Does the CVE-2011-1910 vulnerability affect these versions? ___ bind-users mailing list bind-users@lists.isc.org

Re: Does the CVE-2011-1910 vulnerability affect the BIND 9.7.0-P2?

2011-06-10 Thread Mark Andrews
In message 201106100709.qaa04...@osspc4.sra.co.jp, YABUKI Youichi writes: The BIND security advisory for CVE-2011-1910 does not mention about versions 9.7.0, 9.7.0-P1 and 9.7.0-P2. Does the CVE-2011-1910 vulnerability affect these versions? No, they are not affected.

Re: Does the CVE-2011-1910 vulnerability affect the BIND 9.7.0-P2?

2011-06-10 Thread Stephane Bortzmeyer
On Fri, Jun 10, 2011 at 04:09:31PM +0900, YABUKI Youichi yab...@sraoss.co.jp wrote a message of 7 lines which said: The BIND security advisory for CVE-2011-1910 does not mention about versions 9.7.0, 9.7.0-P1 and 9.7.0-P2. 9.7.0* is not supported, I believe. IF you use the 9.7 branch, you

How to improve bind caching dns server performance

2011-06-10 Thread kshitij mali
HI All, I am repeated facing SERVFAIL error with respond to dig command . but when i dig to known domian like yahoo,gmail.orkut etc then no problem . i think there is some perfomance issue with mycaching dns server how to check the reson lookup failure and how to improve the preformance .

Catchall BIND configuration for DNS parking service

2011-06-10 Thread Gianfranco Pra Floriani
Hello there, I'm trying to configure BIND (BIND 9.7.3) as a catchall DNS server for a parking domain service. This is a way to let users/clients park their domains automatically by pointing primary and secondary DNS servers there. It should work with ANY TLD (both generic and countrycodes).

why bind unable to find log files

2011-06-10 Thread kshitij mali
why bind unable to find log files where file is present at location with all permisions === tail -f /var/log/messages logging channel 'resolver_file' file '/var/log/resolver.log': file not found == [root@relay virusmails]# ls -l

Re: Does the CVE-2011-1910 vulnerability affect the BIND 9.7.0-P2?

2011-06-10 Thread Adam Tkac
On 06/10/2011 01:45 PM, Chris Thompson wrote: On Jun 10 2011, Mark Andrews wrote: In message 201106100709.qaa04...@osspc4.sra.co.jp, YABUKI Youichi writes: The BIND security advisory for CVE-2011-1910 does not mention about versions 9.7.0, 9.7.0-P1 and 9.7.0-P2. Does the CVE-2011-1910

Re: How to improve bind caching dns server performance

2011-06-10 Thread David Sparro
On 6/10/2011 5:04 AM, kshitij mali wrote: HI All, I am repeated facing SERVFAIL error with respond to dig command . but when i dig to known domian like yahoo,gmail.orkut etc then no problem . i think there is some perfomance issue with mycaching dns server how to check the reson lookup failure

Re: How to improve bind caching dns server performance

2011-06-10 Thread Lyle Giese
On 06/10/11 07:53, David Sparro wrote: On 6/10/2011 5:04 AM, kshitij mali wrote: HI All, I am repeated facing SERVFAIL error with respond to dig command . but when i dig to known domian like yahoo,gmail.orkut etc then no problem . i think there is some perfomance issue with mycaching dns server

Re: Does the CVE-2011-1910 vulnerability affect the BIND 9.7.0-P2?

2011-06-10 Thread Chris Thompson
On Jun 10 2011, Adam Tkac wrote: Hello Chris, that was too short cut from ncache.c. 9.7.0* contains: /* * Copy the type to the buffer. */ isc_buffer_availableregion(buffer, r); if (r.length 2)

Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2

2011-06-10 Thread Per-Olof Axelsson
When I run the following dig command below I sometimes get different answers, generally 20-30 minutes after restarting BIND. It doesn't matter if I run dig from a remote host or locally on the problematic DNS server. The two servers in question run on entirely different hardware and operating

Re: Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2

2011-06-10 Thread Phil Mayers
On 10/06/11 15:50, Per-Olof Axelsson wrote: When I run the following dig command below I sometimes get different answers, generally 20-30 minutes after restarting BIND. It doesn't This might be the problem resolving CNAMEs that was discussed on the list recently:

Re: BIND 9.7 Serial Number Decrease Problem

2011-06-10 Thread Barry Finkel
On 07/06/11 13:51, I wrote: I now have this situation on one Solaris 10 slave; the problem probably also exists on the other Sol 10 slave and the two Ubuntu hardy slaves: The _tcp zone on the master MS DNS Server: 1238 600 86400 3600 The _tcp zone on the BIND 9.7.3-P1 Solaris 10 server

ksk in a volume

2011-06-10 Thread Noel Rocha
Hello, I have a question about dnssec when zones are dynamically updated and very time are changed for users. KSK needs be stored in key-directory? I want to store in unmounted volume and I will mount when is need. P.S: I have some KSKs and ZSKs. Thanks in advance, Noel Rocha

Re: Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2

2011-06-10 Thread Tony Finch
Phil Mayers p.may...@imperial.ac.uk wrote: This might be the problem resolving CNAMEs that was discussed on the list recently: https://lists.isc.org/pipermail/bind-users/2011-May/thread.html#83714 Bind 9.8.0 intermittent problem with non-recursive responses It was fixed in 9.8.1 But note

Re: Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2

2011-06-10 Thread Doug Barton
On 6/10/2011 8:36 AM, Phil Mayers wrote: It was fixed in 9.8.1, or you can apply the patch that the FreeBSD guys have: http://www.freebsd.org/cgi/cvsweb.cgi/ports/dns/bind98/files/patch-bin__named__query.c?rev=1.1 I can't take credit for that, it came from Mark. :) -- Nothin' ever

Re: remove me

2011-06-10 Thread Ricardo Ide
remove me! From: Doug Barton do...@dougbarton.us To: Phil Mayers p.may...@imperial.ac.uk Cc: bind-users@lists.isc.org Sent: Friday, June 10, 2011 4:34 PM Subject: Re: Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2 On 6/10/2011 8:36 AM, Phil Mayers wrote: It

Re: Problem resolving CNAME in BIND 9.8.0 and 9.8.0-P2

2011-06-10 Thread Lyle Giese
On 06/10/11 09:50, Per-Olof Axelsson wrote: When I run the following dig command below I sometimes get different answers, generally 20-30 minutes after restarting BIND. It doesn't matter if I run dig from a remote host or locally on the problematic DNS server. The two servers in question run

Re: How to improve bind caching dns server performance

2011-06-10 Thread Mark Andrews
In message 4df21e85.2020...@lcrcomputer.net, Lyle Giese writes: On 06/10/11 07:53, David Sparro wrote: On 6/10/2011 5:04 AM, kshitij mali wrote: HI All, I am repeated facing SERVFAIL error with respond to dig command . but when i dig to known domian like yahoo,gmail.orkut etc then no

Re: Catchall BIND configuration for DNS parking service

2011-06-10 Thread Mark Andrews
Named really isn't designed to be a catch all server. It's designed to serve the configured zones and only the configured zones. That being said the later versions of named allow zones to be added via rndc so the configuration effort required to add a new zone is much lower. e.g. rndc

Re: why bind unable to find log files

2011-06-10 Thread Mark Andrews
Are you starting named with -t chroot-directory? If so you need to look at the path relative to the chroot-directory. Mark In message banlktikttvvag6kbophyfxzzlqk+cbt...@mail.gmail.com, kshitij mali w rites: --===0107398317155429819== Content-Type: multipart/alternative;

Re: remove me

2011-06-10 Thread Mark Andrews
In message 936805.37724...@web161304.mail.bf1.yahoo.com, Ricardo Ide writes: remove me Did you bother to follow the link at the end of the message you replied to before posting this? The same one that will be at the end of this message.