Re: Is there a way to disable dnssec validation for a single zone?

2011-08-04 Thread Jan-Piet Mens
> The last time there was a dns issue with usdoj.gov, it took about 3 > weeks for them to fix it. Reeks of incompetence. -JP ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing li

RE: Is there a way to disable dnssec validation for a single zone?

2011-08-04 Thread Marc Lampo
Hello, As a *temporary* solution, you could configure you validating caching name server as authoritative for that name. The authoritative part/answer is taken before the cache, regardless of DS records in the parent indicating that RRSIG's should be present. One point of attention : don't have v

Re: BIND freezing up randomly under "real" load

2011-08-04 Thread Mark Andrews
In message , ian_ve...@nshe.nevada.edu writes: > > Am (was) prepping to deploy BIND 9.7.3-P3 (which is the version that came > with RHEL6.1) on RHEL6.1, sitting on top of OSPF anycast. Currently > running BIND 9.5.0-P2 (with Novell patches) on SLES 11 (with OSPF anycast) > just fine in produc

Re: Is there a way to disable dnssec validation for a single zone?

2011-08-04 Thread Mark Andrews
In message , "Dodson, Ron" writes: > Hello, > > Is there a way to disable dnssec validation for a single zone? No. > The people wh > o run the dns for ojp.usdoj.gov have broken dnssec. Usdoj.gov delegates ojp. > usdoj.gov and has a DS record for ojp.usdoj.gov. Ojp.usdoj.gov is unsigned, > an

Re: Strange SERVFAIL issue

2011-08-04 Thread Mark Andrews
In message <6439e580-7a85-4be3-bf86-67977e1c0...@otenet.gr>, Stuart Gall writes : > Jagan thanks for your help. > > I have resolved the problem, perhaps others will have the same issue. > Mandrivia configures bind with a bogon_acl config file which. > > // Filter out the bogon networks.

Problem with resolution

2011-08-04 Thread Baird, Josh
I'm having trouble with the resolution of www.pncactivepay.com. It appears that most nameservers will resolve this host to 208.86.144.222. Resolution for this host only works about half of the time, as shown by my logs below. When my resolvers are not able to get the real IP (208.86.144.22), th

BIND freezing up randomly under "real" load

2011-08-04 Thread Ian_Veach
Am (was) prepping to deploy BIND 9.7.3-P3 (which is the version that came with RHEL6.1) on RHEL6.1, sitting on top of OSPF anycast. Currently running BIND 9.5.0-P2 (with Novell patches) on SLES 11 (with OSPF anycast) just fine in production, but running into strange problem on new system, not

Is there a way to disable dnssec validation for a single zone?

2011-08-04 Thread Dodson, Ron
Hello, Is there a way to disable dnssec validation for a single zone? The people who run the dns for ojp.usdoj.gov have broken dnssec. Usdoj.gov delegates ojp.usdoj.gov and has a DS record for ojp.usdoj.gov. Ojp.usdoj.gov is unsigned, and has no corresponding dnskey record, so validation fai

Re: Strange SERVFAIL issue

2011-08-04 Thread Stuart Gall
Jagan thanks for your help. I have resolved the problem, perhaps others will have the same issue. Mandrivia configures bind with a bogon_acl config file which. // Filter out the bogon networks. These are networks // listed by IANA as test, RFC1918, Multicast, experi- // mental,