RHEL, Centos, Fedora rpm 9.14.7

2019-10-18 Thread Carl Byington via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 https://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEAREKAAYFAl2qWNcACgkQL6j7milTFsF8BwCfYQAStqPziT2iCMWxyquxo/3n

Re: Is inline-signing recommended?

2019-10-18 Thread Daniel Stirnimann
Hello Alessandro, On 18.10.19 19:20, Alessandro Vesely wrote: > Did a better way arrive between 2014 and 2017? What does that warning > mean? The how to in this article manually creates keys or does key rollovers. Most DNS software have automated that part, see for example section Policy

Confused about query_source(-v6) address statement

2019-10-18 Thread Robert Senger via bind-users
Hi there, I found these two inconsistent statements in the net about how bind9's query_source_(-v6) address statements work: From: https://docstore.mik.ua/orelly/networking_2ndEd/dns/ch10_15.htm "Note that query-source applies only to UDP-based queries; TCP-based queries always choose the

Re: RHEL, Centos, Fedora rpm 9.14.6

2019-10-18 Thread Petr Mensik
Hello Jóhann, I am packager of BIND in RHEL and Fedora. I would like everyone would use our BIND packages. But we have some modifications, as was already mentioned. Some of them are important for FreeIPA to work, some provide bind-sdb build to use SDB features. Also some other changes that

Is inline-signing recommended?

2019-10-18 Thread Alessandro Vesely
Hi all, reading about the various ways to sign zones, inline-signing seems to be the simplest one. However, a 2014 Swiss howto I found has this obscure warning: Update Nov 2017: DNSSEC zone signing as described here is outdated. We strongly recommend against the method described in

Re: Change source IP at outgoing packet send by Bind9 as forwarder.

2019-10-18 Thread CpServiceSPb .
Thanks for the tip. Adding query-source address binded (lan) IP; port 53; to named.conf.options . According to preliminary tests, this is it is ! пт, 18 окт. 2019 г. в 15:41, CpServiceSPb . : > > Have you tried the query-source option? (You might also need > > transfer-source and

Re: Change source IP at outgoing packet send by Bind9 as forwarder.

2019-10-18 Thread Tony Finch
CpServiceSPb . wrote: > So how is to change Bind9 , what and where is to set up and waht setting > that Bind9 would send forwarding packet via wan interface but would use > address what it is binded to or internal, if it is binded to 127.0.0.1 and > 192.168.0.1 ? Have you tried the query-source

Re: Change source IP at outgoing packet send by Bind9 as forwarder.

2019-10-18 Thread CpServiceSPb .
May be I posted my question too complicated. So, let' s try with examples. As I wrote I have Asterisk as well at the server binded only to internal IP with external trunks that is it connects time to time to external VoIP provider, that is through wild Internet, via wan interface. I have