Re: Freeze/thaw and signed zone files

2019-02-21 Thread Grant Taylor via bind-users
On 2/21/19 6:28 PM, @lbutlr wrote: rndc reload did not recreate (or at least update the time stamp) on the .signed file. Hum. Maybe it's something different about how you're doing DNSSEC than I am. I have BIND managing DNSSEC for me via "auto-dnssec maintain;". So I don't get .signed

Re: Freeze/thaw and signed zone files

2019-02-21 Thread @lbutlr via bind-users
On 21 Feb 2019, at 18:28, @lbutlr wrote: > Is the original random key that was generated at the time of signing kept > somewhere? NSEC3 seems to contain a 16 character hex sting that recurs > throughout the file. OK, I moved aside the signed file, resigned the domain using the 16 character

Re: Freeze/thaw and signed zone files

2019-02-21 Thread @lbutlr
>> OK, but rndc flush example.com results in: >> rndc: 'flush' failed: not found > > *FACEpalm* > > I'm sorry. I gave you the wrong command. You want "sync", not "flush". My > brain always thinks "flush the journal to disk" when it's really supposed to > be "sync the journal to disk". You

Re: Freeze/thaw and signed zone files

2019-02-21 Thread Grant Taylor via bind-users
On 02/21/2019 02:03 PM, @lbutlr via bind-users wrote: OK, but rndc flush example.com results in: rndc: 'flush' failed: not found *FACEpalm* I'm sorry. I gave you the wrong command. You want "sync", not "flush". My brain always thinks "flush the journal to disk" when it's really supposed

Re: Freeze/thaw and signed zone files

2019-02-21 Thread Noel Butler
On 22/02/2019 07:03, @lbutlr via bind-users wrote: >> I don't recall if reloading or thawing will automatically re-sign the zone >> or if you need to also explicitly "rndc sign $ZONE". > > Sign recreates the .jnl file, but doesn't touch the .signed file. > > Doing the following recreated the

Re: Freeze/thaw and signed zone files

2019-02-21 Thread @lbutlr via bind-users
> On 21 Feb 2019, at 13:41, Grant Taylor via bind-users > wrote: > > On 02/21/2019 01:34 PM, @lbutlr via bind-users wrote: >> I edited a zone file after issuing a rndc freeze command, added two new sub >> zones, changed the serial number, saved the file, and then did an rndc thaw. > > I

Re: Freeze/thaw and signed zone files

2019-02-21 Thread Grant Taylor via bind-users
On 02/21/2019 01:34 PM, @lbutlr via bind-users wrote: I edited a zone file after issuing a rndc freeze command, added two new sub zones, changed the serial number, saved the file, and then did an rndc thaw. I don't see an "rndc flush " in there. Which means that BIND likely still has the

Freeze/thaw and signed zone files

2019-02-21 Thread @lbutlr via bind-users
I edited a zone file after issuing a rndc freeze command, added two new sub zones, changed the serial number, saved the file, and then did an rndc thaw. In var/log.messages I get zone serial (2019020105) unchanged. zone may fail to transfer to slaves. which is the previous serial number. So,

Re:

2019-02-21 Thread Roberto Carna
Thanks a lot. Greetings !!! El mié., 20 feb. 2019 a las 16:55, Matus UHLAR - fantomas (< uh...@fantomas.sk>) escribió: > On 20.02.19 10:48, Roberto Carna wrote: > >You tell me to do this: > > > >zone "." { > >type master; > >file "empty.db"; > >}; > > > >The root zone Is "type master"

Re: Server can not resolve Domain

2019-02-21 Thread Niall O'Reilly
On 21 Feb 2019, at 9:28, Wolfgang Pähler wrote: > The domain is: paehler.coud Zonemaster reports problems with the (currently) delegated name servers. I've put a little more detail in a private message. Best regards, Niall O'Reilly ___ Please visit

Re: Server can not resolve Domain

2019-02-21 Thread Wolfgang Pähler
The domain is: paehler.coud Am 21. Februar 2019 10:12:50 MEZ schrieb Matus UHLAR - fantomas : >On 20.02.19 14:48, haidao wrote: >>we use a own nameserver on our System. I have install bind9 now ,and >>configure the zone files. At our Provider I have change the nameserver >>to our System. But the

Re: Server can not resolve Domain

2019-02-21 Thread Matus UHLAR - fantomas
On 20.02.19 14:48, haidao wrote: we use a own nameserver on our System. I have install bind9 now ,and configure the zone files. At our Provider I have change the nameserver to our System. But the Server can not resolve the name. I have search a lot of time,but I can not see the problem. would

Re: Combining forward with master zone.

2019-02-21 Thread Matus UHLAR - fantomas
On Wed, Feb 20, 2019 at 3:40 PM King, Harold Clyde (Hal) wrote: Could I just define needs.example.com as a zone in a separate file so: zone "example.com" { type master; notify no; file "static/antiphish.db"; }; zone "needs.example.com" { type forward; forwards{8.8.8.8;}; On 20.02.19 16:08,