Re: BIND9 Feature Request: inheritance-policy

2021-05-27 Thread JW λ John Woodworth
Thanks Tony!This is essentially what we do today.  In fact, I was ecstatic when acl's were finally able to be used for all address match-lists.However, (and I realize this not a common use case) with over 150,000 zones -- some in multiple views, with different sets of rules (e.g., allow-query, e

Re: BIND9 Feature Request: inheritance-policy

2021-05-27 Thread Tony Finch
JW λ John Woodworth wrote: > Greetings, I would like to request a new feature which I hope will make > management of the 'allow' match-lists a tad easier.In short, an option > such as 'allow-transfer' in view or zone contexts could extend the > match-list as defined in the options section. You c

BIND9 Feature Request: inheritance-policy

2021-05-27 Thread JW λ John Woodworth
Greetings, I would like to request a new feature which I hope will make management of the 'allow' match-lists a tad easier.In short, an option such as 'allow-transfer' in view or zone contexts could extend the match-list as defined in the options section.  This would flow from options->view->zon

Re: Problems with compiling BIND 9.17.10 or above ...

2021-05-27 Thread Ondřej Surý
Hi, you need to post full config.log, not just snippet of the console. But I would suggest to look into the config.log first. Ondrej -- Ondřej Surý — ISC (He/Him) My working hours and your working hours may be different. Please do not feel obligated to reply outside your normal working hours.

Fwd: Problems with compiling BIND 9.17.10 or above ...

2021-05-27 Thread Rick Dicaire
Now another problem comes up and I hope someone here can help me. The Configure process now produces the message: checking for OPENSSL... yes checking for OpenSSL >= 1.0.0 or LibreSSL >= 2.7.0... yes checking for OPENSSL_init_ssl... no checking for OPENSSL_init_crypto... no checking for CRYPTO

Re: BIND 9.16.17-snapshot - testers needed - recursive performance

2021-05-27 Thread Erich Eckner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I switched to the 9.16.17 release candidate yesterday and so far, it runs well on my 6 very-low traffic dns servers (one of which is also authoritative). Only thing, I noticed, is, that it uses more memory than 9.16.16 on the weakest of my

TCP connections left in CLOSE_WAIT in 9.16.15/16

2021-05-27 Thread usenet
Hello We updated on Monday from bind-9.16.6/8 to bind-9.16.15/16 on some public-facing authoritative nameservers. Since then, we are seeing a build-up of inbound TCP connections to port 53 being left in CLOSE_WAIT state indefinitely until named is restarted, or exhausting the tcp-clients limit if