Re: Email migration and MX records

2023-01-06 Thread Bruce Johnson via bind-users
No one realistically has a choice about dealing with either for email. In any case, we found a vastly simpler way of doing this; our cloud email security/anti-spam provider (Barracuda) can spool mail for delivery if our systems go offline for up to 96 hours, so we’re setting them to not deliver

Email migration and MX records

2023-01-03 Thread Bruce Johnson via bind-users
We’re making an O365 tenant switchover for our domain (a subdomain of the arizona.edu domain) and moving from our Barracuda cloud email SMTP to the University’s tenant, but email cannot flow until the Arizona.edu O365 tenant can take over our email domain. In anticipation I set our TTL for MX r

Re: Move from Development to Production

2022-08-26 Thread Bruce Johnson via bind-users
That’s the wrong repo, the stable repo is here: https://copr.fedorainfracloud.org/coprs/isc/bind/ It works very well with Rocky Linux 8.6 at least. On Aug 26, 2022, at 12:50 PM, David C. Templeton mailto:david.temple...@troycable.com>> wrote: Sorry for any confusion. I started with 9.18.4 beca

Re: Setting Up An Running Your Own Dmarc using Bind DNS

2022-06-27 Thread Bruce Johnson via bind-users
On Jun 27, 2022, at 11:34 AM, Stephane Bortzmeyer mailto:bortzme...@nic.fr>> wrote: Also, I do not understand the writing of "hundreds of lines of code". The code to load DMARC records is in BIND for a very long time since they are just TXT records. @ IN TXT v=DMARC1; p=reject; rua=mailto:dmar

Re: Probably stupid simple question...

2022-06-01 Thread Bruce Johnson via bind-users
Thanks! On Jun 1, 2022, at 1:48 PM, Sandro mailto:li...@penguinpee.nl>> wrote: On 01-06-2022 20:07, Bruce Johnson via bind-users wrote: I am migrating our BIND system to a new server/BIND version, and have a question about dynamically updated zone files (we have one dynamic zone). I a

Probably stupid simple question...

2022-06-01 Thread Bruce Johnson via bind-users
I am migrating our BIND system to a new server/BIND version, and have a question about dynamically updated zone files (we have one dynamic zone). I am just copying all the configuration and zone files to the new server, do I need to run rndc freeze before shutting down bind and moving them or w

Has anyone run Sophos Server Protection on a linux system running bind?

2022-02-18 Thread Bruce Johnson via bind-users
We getting a centralized IT push to install the university’s sophos product on all servers, including linux: https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/SPLCommandLineOptions.html We have three systems running bind: a primary and two secondaries; all are runnin

odd MX entry error in zone file

2022-02-03 Thread Bruce Johnson via bind-users
I added a new zone to our domain today and ran named-checkzone and got the following when it ran: named-checkzone -t /var/named/chroot Pharmacy.Arizona.EDU /etc/Pharmacy.Hosts zone Pharmacy.Arizona.EDU/IN: getaddrinfo(xxx1.barracudanetworks.com) failed: System error zone Pharmacy.Arizona.EDU

Re: Error staring named, permissions denied on named.ca

2021-12-09 Thread Bruce Johnson via bind-users
Ugh, forgot about that…that was it. Thanks! On Dec 9, 2021, at 3:48 PM, Mark Andrews mailto:ma...@isc.org>> wrote: Almost certainly SELinux or AppArmor on the new platform getting in the way. On 10 Dec 2021, at 06:08, Bruce Johnson via bind-users mailto:bind-users@lists.isc.org&g

Error staring named, permissions denied on named.ca

2021-12-09 Thread Bruce Johnson via bind-users
I'm setting up a new secondary for our domain with the intent to shut down an existing one (which is running on a very old OS and bind version) Running Rocky Linux (replacement for CentOS 8.5) using the isc bind-esv package here https://copr.fedorainfracloud.org/coprs/isc/bind-esv/ instead of th

Re: named service suddenly fails to start

2021-11-04 Thread Bruce Johnson via bind-users
On Nov 4, 2021, at 12:05 PM, Reindl Harald mailto:h.rei...@thelounge.net>> wrote: ExecStartPre=/bin/bash -c if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -t /var/named/chroot -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi (code=exi this nons

Re: named service suddenly fails to start

2021-11-04 Thread Bruce Johnson via bind-users
On Nov 4, 2021, at 12:01 PM, Bruce Johnson mailto:john...@pharmacy.arizona.edu>> wrote: This morning our server started failing to reload or start. checking the status reveals not a lot of info: systemctl status named-chroot ● named-chroot.service - Berkeley Internet Name Domain (DNS) Loaded:

named service suddenly fails to start

2021-11-04 Thread Bruce Johnson via bind-users
This morning our server started failing to reload or start. checking the status reveals not a lot of info: systemctl status named-chroot ● named-chroot.service - Berkeley Internet Name Domain (DNS) Loaded: loaded (/usr/lib/systemd/system/named-chroot.service; enabled; vendor preset: disabled

DKIM setup

2021-08-11 Thread Bruce Johnson via bind-users
I’m trying to set up DNS records for DKIM in our system; we have a hybrid O365/On-Prem Exchange server and separate Mailman list server, all of which send email from our domain (and are in the spf list in DNS.) I’m a little unclear on the syntax described here: (https://kb.isc.org/docs/aa-00725