AW: AW: Specifying NSEC3 salt with dnssec-policy

2024-10-01 Thread Klaus Darilion via bind-users
> > I always had the impression that dnssec-signzone is a stand-alone > > utility and signing is done either with dnssec-signzone or with > > Bind's dnssec-policy. Does it really work to use dnssec-signzone on a > > zone and journal that is managed by named? > > No, it doesn't work like that. You

AW: Specifying NSEC3 salt with dnssec-policy

2024-10-01 Thread Klaus Darilion via bind-users
Hi Matthijs! I always had the impression that dnssec-signzone is a stand-alone utility and signing is done either with dnssec-signzone or with Bind's dnssec-policy. Does it really work to use dnssec-signzone on a zone and journal that is managed by named? Regards Klaus -- Klaus Dar

AW: AW: AW: Specifying NSEC3 salt with dnssec-policy

2024-10-01 Thread Klaus Darilion via bind-users
Hi Petr! > It can be said that the interface pushes people to follow RFC 9276, i.e. > no salt and no extra iterations. > > It is an pointless exercise which only makes servers easier to DoS for > no benefit. I understand your decision to push people towards RFC 9276. > Why do you need extra sal

Specifying NSEC3 salt with dnssec-policy

2024-09-30 Thread Klaus Darilion via bind-users
Hello! With "auto-dnssec maintain;" I was used to specify the NSEC3 salt with 'rndc signing -nsec3param'. Today I used the "dnssec-policy" and I failed to specify the salt manually. Are there any tricks/workarounds to manually specify the NSEC3 salt? I know that actually the salt should be "-"

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-09 Thread Klaus Darilion via bind-users
As we still have several timeouts I downgraded our server to 9.18. If you know another workaround or need someone to test new version please let me know. Thanks Klaus From: Klaus Darilion Sent: Saturday, September 7, 2024 12:36 AM To: Klaus Darilion ; Ondřej Surý Cc: Klaus Darilion via bind

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Klaus Darilion via bind-users
Correcting myself: event with { reuseport no; }; and UV_THREADPOOL_SIZE=12 still timeouts happen, but the situation improved a lot. Regards Klaus From: bind-users On Behalf Of Klaus Darilion via bind-users Sent: Saturday, September 7, 2024 12:21 AM To: Ondřej Surý Cc: Klaus Darilion via bind

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Klaus Darilion via bind-users
From: Ondřej Surý Sent: Friday, September 6, 2024 4:08 PM To: Klaus Darilion Cc: Petr Špaček ; bind-users@lists.isc.org; Klaus Darilion via bind-users Subject: Re: Sporadic Timeouts after upgrading to bind9.20 Are your running with options { reuseport no; }; ? You might want to try that

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Klaus Darilion via bind-users
From: Ondřej Surý Sent: Friday, September 6, 2024 4:10 PM To: Klaus Darilion Cc: Klaus Darilion via bind-users Subject: Re: Sporadic Timeouts after upgrading to bind9.20 Hmm, what is the churn in the zones? How often there’s IXFR and how large those changes are? Every 30 minutes. See logs

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Klaus Darilion via bind-users
As there just was another IXFR, for the records, here is another trace with debug symbols installed. Thanks Klaus PID 1605200 - process TID 1605200: #0 0x7b8ceb529ee0 epoll_pwait - /usr/lib/x86_64-linux-gnu/libc.so.6 #1 0x7b8cec52c9fa - 1 - /usr/lib/x86_64-linux-gnu/libuv.so.1.0.0 #

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Klaus Darilion via bind-users
I just happened again. I have not yet installed the debug symbols. I query the SOA every second with 1 second timeout. Here are the traces. I happened a few times in a row. Below are the traces. I noticed the timeout happened during Bind9 starting an inbound IXFR: Sep 06 07:20:55 named[1605200]

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-06 Thread Klaus Darilion via bind-users
/lib/x86_64-linux-gnu/libuv.so.1.0.0 #3 0x7b8cec5177fe - 1 - /usr/lib/x86_64-linux-gnu/libuv.so.1.0.0 #4 0x7b8ceb49ca94 - 1 - /usr/lib/x86_64-linux-gnu/libc.so.6 #5 0x7b8ceb529c3c - 1 - /usr/lib/x86_64-linux-gnu/libc.so.6 -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob

RE: Sporadic Timeouts after upgrading to bind9.20

2024-09-04 Thread Klaus Darilion via bind-users
Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria From: Ondřej Surý Sent: Wednesday, September 4, 2024 7:23 PM To: Klaus Darilion Cc: bind-users@lists.isc.org Subject: Re: Sporadic Timeouts after upgrading to bind9.20 Klaus, is that recursive or authoritative

Sporadic Timeouts after upgrading to bind9.20

2024-09-04 Thread Klaus Darilion via bind-users
qps we see it more often. Before I dig into the problem, are there any specific changes to 9.20 that I should look at? Maybe some default value changes for socket buffers, thread handling ...? Thanks Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020

AW: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records

2024-03-26 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Jan > Schaumann via bind-users > Gesendet: Dienstag, 26. März 2024 14:44 > An: bind-users@lists.isc.org > Betreff: Re: [OFF-TOPIC] Question about ClouDNS (and others') ALIAS records > > Karl Auer wrote: > > I'm puzzled by the C

AW: Crafting a NOTIFY message from the command line?

2024-03-21 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Arsen > STASIC > Gesendet: Donnerstag, 21. März 2024 08:47 > An: Petr Špaček > Cc: bind-users@lists.isc.org > Betreff: Re: Crafting a NOTIFY message from the command line? > > * Petr Špaček [2024-03-20 09:32 (+0100)]: > > On 1

AW: Problem upgrading to 9.18 - important feature being removed

2024-02-27 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Carsten ... > It would be nice to have a "dry-run" mode in BIND 9, where BIND 9 would > report steps it would do because of "dnssec-policy", but will not execute the > changes. If this Bind9 is only a hidden primary, disable all

AW: migration from auto-dnssec to dnssec-policy deletes keys immediately

2024-01-08 Thread Klaus Darilion via bind-users
Hi all! I also know a colleague which was hit by the same issue, causing problems to their zone. Migrating from auto-dnssec to dnssec-policy can lead to operational issues. For example that problem with different algos should be mentioned in https://kb.isc.org/docs/dnssec-key-and-signing-p

AW: Why are XFRs to Secondaries equally fast?

2023-07-27 Thread Klaus Darilion via bind-users
Hi Petr! > > For example, there are 8 secondaries (Mumbai, LosAngeles, Melbourne, > > Atlante, SaoPaulo...) to which the XFR took 2361 seconds. > > > > Are there some mechanisms in Bind that put multiple XFRs together into > a > > common stream? Or do you have any other ideas how it come that seve

Why are XFRs to Secondaries equally fast?

2023-07-27 Thread Klaus Darilion via bind-users
several XFRs are equally fast? Thanks Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support

AW: Tools to mesure performance and benchmarking of a DNS

2023-06-21 Thread Klaus Darilion via bind-users
There are several tools with different features and behavior. I would take alook at dnsperf, kxdpgun and flamethrower regards > -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von > sami.ra...@sofrecom.com > Gesendet: Mittwoch, 21. Juni 2023 17:59 > An: bind-users@lists.isc.org >

AW: Bind not sending notifies for some time

2023-03-27 Thread Klaus Darilion via bind-users
> > On 24. 3. 2023, at 14:36, Klaus Darilion via bind-users us...@lists.isc.org> wrote: > > > > Is there some rate liming in Bind? > > https://bind9.readthedocs.io/en/stable/reference.html#namedconf- > statement-notify-rate For the records: Increasing the n

RE: Bind not sending notifies for some time

2023-03-24 Thread Klaus Darilion via bind-users
> > https://bind9.readthedocs.io/en/stable/reference.html#namedconf-statement-notify-rate Will that feature throttle Notifys or stop them completely for some minutes? Thanks Klaus -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the developmen

Bind not sending notifies for some time

2023-03-24 Thread Klaus Darilion via bind-users
Hi! root@cc-tld-sbg1:/var/log/tld-acct-by-customer# dpkg -l|grep bind9 ii bind9 1:9.18.6-1+ubuntu22.04.1+isc+1 amd64Internet Domain Name Server Please help me debugging this issue: We have a TLD zone with ~3mio delegations and updates every f

AW: Correlation between NOTIFY-Source and AXFR-Source

2023-03-09 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Mark > Andrews > Gesendet: Donnerstag, 9. März 2023 21:04 > An: Jan-Piet Mens > Cc: bind-users@lists.isc.org > Betreff: Re: Correlation between NOTIFY-Source and AXFR-Source > > Named just uses the notify to trigger an early re

Correlation between NOTIFY-Source and AXFR-Source

2023-03-09 Thread Klaus Darilion via bind-users
Hello! I always was quite sure that Bind will request XFR from the Primary that sent the NOTIFY. config: masters { X.X.X.4; X.X.X.20; }; Bind Version 9.11.5.P4+dfsg-5.1+deb10u8 But I just saw this in the logs that the first NOTIFY is received from .20, but AXFR is perf

AW: DNS DDoS protection

2023-02-27 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Bob > Harold > Gesendet: Freitag, 24. Februar 2023 19:26 > An: bind-users > Betreff: DNS DDoS protection > > Before answering this question, can you tell me the proper place where I > should be asking this question? > > "We ar

AW: Simplistic serial number roll back

2023-02-20 Thread Klaus Darilion via bind-users
Yes it does. I guess all name servers offer a command to force a transfer of the zone without checking the serial. The ones I use support that: Bind: rndc retransfer NSD: nsd-control force_transfer PowerDNS: pdns_control retrieve Knot: knotc zone-retransfer regards Klaus > -Ursprünglich

Is there an rndc command to get the list of configured zones?

2022-09-20 Thread Klaus Darilion via bind-users
I checked all options of rndc to get the list of zones configured/served by bind - but I can't find any. Is it really not possible to get this list from a running Bind process? Thanks Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Au

AW: BIND 9.18.6 disables RSASHA1 at runtime?

2022-09-13 Thread Klaus Darilion via bind-users
> Can you propose log line? > > Should it be one line per algorithm? Or one line with all disabled? Or > one one with all enabled? What log level? Log category? It it okay it > will be almost always logging GOST? ... I am not using Red Hat, but when debugging DNSSEC issues it would be helpful to

AW: High memory consumption in bind 9.18.2

2022-05-19 Thread Klaus Darilion via bind-users
Von: Petr Špaček > Gesendet: Donnerstag, 19. Mai 2022 12:22 > An: Klaus Darilion > Cc: bind-users@lists.isc.org > Betreff: Re: High memory consumption in bind 9.18.2 > > On 18. 05. 22 22:39, Ondřej Surý wrote: > > Hi Klarstein, > > > > Gathering the output of na

AW: AW: High memory consumption in bind 9.18.2

2022-05-18 Thread Klaus Darilion via bind-users
> differences are not small, for some configurations it can be even 2x or > 3x more on 9.16 than it is on 9.18. > > If you encounter it again please get back to us so we can diagnose it. > > Thank you! > Petr Špaček > > > On 18. 05. 22 8:56, Klaus Darilion via bind-u

AW: High memory consumption in bind 9.18.2

2022-05-17 Thread Klaus Darilion via bind-users
I remember we had similar issues with 9.18 (isc ppa packages) and hence wen't back to 9.16. But I can not remember the details. regards Klaus > -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Ondrej > Surý > Gesendet: Mittwoch, 18. Mai 2022 08:37 > An: Raman kumar > Cc: bind

AW: Why did my DNS bill go up?

2022-04-14 Thread Klaus Darilion via bind-users
Hi Andrew! DNSSEC is more costly: more Ressource Records to hold on disk, to hold in memory and more queries and more IP traffic. If the DNSSEC signing is also done by the DNS provider there would be additional ressources for the signing service and risks when doing something wrong. For a sing

AW: all resource record types and examples

2022-04-13 Thread Klaus Darilion via bind-users
As I have such a zone I will paste it here. But fore sure it is not complete as it was created some time ago. regards Klaus $ cat types.test $TTL 60 ; 1 minute @ IN SOA sec1.rcode0.net. rcodezero.ipcom.at. ( 36 ; serial

AW: Bind 9, dnssec, and .key .private files physical deletion after the key id becomes deleted from zone (the key becomes outdated)

2022-01-24 Thread Klaus Darilion via bind-users
IIRC, Bind needs the key as long as there are signatures in the zone generated by this key. After key deactivation I waited the RRSIG lifetime before deleting them. regards Klaus Von: bind-users Im Auftrag von egoitz--- via bind-users Gesendet: Montag, 24. Jänner 2022 13:00 An: bind-users@lis

AW: AW: Deprecating auto-dnssec and inline-signing in 9.18+

2021-08-10 Thread Klaus Darilion via bind-users
> On 10-08-2021 13:38, Klaus Darilion wrote: > > Hi Matthijs! > > > >> We would like to encourage you to change your configurations to > >> 'dnssec-policy'. See this KB article for migration help: > >> > >> https://kb.isc.org/docs/d

AW: Deprecating auto-dnssec and inline-signing in 9.18+

2021-08-10 Thread Klaus Darilion via bind-users
Hi Matthijs! > We would like to encourage you to change your configurations to > 'dnssec-policy'. See this KB article for migration help: > > https://kb.isc.org/docs/dnssec-key-and-signing-policy Some comments to this KB article and dnssec-policy: - The article should mention how to retrie

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
Do you think that we can get rid of CNAME too? regards Klaus > -Ursprüngliche Nachricht- > Von: Ondřej Surý > Gesendet: Montag, 9. August 2021 19:19 > An: Klaus Darilion > Cc: Mark Andrews ; bind-users@lists.isc.org > Betreff: Re: Does BIND supports ANAME RR >

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
Does every application that uses gethostbyname have a benefit of HTTPS/SVCB? That is what I meant. regards Klaus > -Ursprüngliche Nachricht- > Von: Mark Andrews > Gesendet: Montag, 9. August 2021 15:55 > An: Klaus Darilion > Cc: Evan Hunt ; Gaurav Kansal ; bind- > u

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
> On 09.08.21 13:55, Klaus Darilion via bind-users wrote: > >But honestly SVCB will not solve the ANAME problem. I will take years > > until all resolvers/client would support SVCB whereas ANAME would be > > implemented in the authoritative name server > > resolving on

AW: Does BIND supports ANAME RR

2021-08-09 Thread Klaus Darilion via bind-users
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Evan > Hunt > Gesendet: Samstag, 7. August 2021 20:21 > An: Gaurav Kansal > Cc: bind-users@lists.isc.org > Betreff: Re: Does BIND supports ANAME RR > > On Sat, Aug 07, 2021 at 11:05:51PM +0530, Gaurav Kansal wrote: > > I need t

failed trust-anchor-telemetry queries

2021-07-27 Thread Klaus Darilion via bind-users
Hello! Bind version: 9.16.19-1+ubuntu18.04.1+isc+1 Recently I discovered these logs: 09:13:12 named[3234]: _default: sending trust-anchor-telemetry query '_ta-/NULL' 09:13:12 named[3234]: validating ./NSEC: no valid signature found 09:13:12 named[3234]: validating ./SOA: no valid signatu

AW: New BIND releases are available: 9.11.32, 9.16.16, and 9.17.13

2021-05-20 Thread Klaus Darilion via bind-users
Nevertheless I think there is a bug. IIR the previous default was 100% (switch to AXFR if IXFR would be grater than AXFR) and we also saw plenty of AXFR although the IXFR difference was very small and far away from 100% regards Klaus > -Ursprüngliche Nachricht- > Von: bind-users Im Auf

9.16 needs more RAM then 9.11

2021-04-19 Thread Klaus Darilion
Hello! On our servers where we use Bind 9.16, named needs approx. 29G RAM. On the servers with Bind 9.11 named needs approx. 25G RAM. Is this a known issue? Are there some config options to tune memory consumption? Thank Klaus ___ Please visit https:

AW: AXFR Problems sind Upgrade to 9.16.12

2021-03-15 Thread Klaus Darilion
on: bind-users Im Auftrag von Klaus > Darilion > Gesendet: Donnerstag, 11. März 2021 21:24 > An: bind-users@lists.isc.org > Betreff: AXFR Problems sind Upgrade to 9.16.12 > > Hello! > > Our setup: Customer Primary --> bind-1 --> bind-2 --> public secondaries > (

AW: AXFR Problems sind Upgrade to 9.16.12

2021-03-11 Thread Klaus Darilion
I will - in the meantime: do you have older ppa packages somewhere on archive? Thanks Klaus > -Ursprüngliche Nachricht- > Von: Ondřej Surý > Gesendet: Donnerstag, 11. März 2021 21:49 > An: Klaus Darilion > Cc: bind-users@lists.isc.org > Betreff: Re: AXFR Proble

AW: AXFR Problems sind Upgrade to 9.16.12

2021-03-11 Thread Klaus Darilion
I just wanted to add, that AXFR of all other hosted zones work fine (even bigger ones). Only this single zone fails. Thanks Klaus > -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Klaus > Darilion > Gesendet: Donnerstag, 11. März 2021 21:24 > An: bind-user

AXFR Problems sind Upgrade to 9.16.12

2021-03-11 Thread Klaus Darilion
Hello! Our setup: Customer Primary --> bind-1 --> bind-2 --> public secondaries (NSD/bind) Today we upgraded bind-1 and bind-2 from: 9.16.6-3+ubuntu18.04.1+isc+3 ---> 9.16.12-2+ubuntu18.04.1+isc+1 AXFR from customer to bind-1 still works. But since the upgrade, bind-2 can not transfer the

AW: AW: How to prepublish additional DNSKEY

2020-07-15 Thread Klaus Darilion
Thanks - now it works. Klaus Von: Shumon Huque Gesendet: Donnerstag, 9. Juli 2020 13:44 An: Daniel Stirnimann Cc: Klaus Darilion ; bind-users@lists.isc.org Betreff: Re: AW: How to prepublish additional DNSKEY On Thu, Jul 9, 2020 at 6:44 AM Daniel Stirnimann mailto:daniel.stirnim...@switch.ch

AW: How to prepublish additional DNSKEY

2020-07-09 Thread Klaus Darilion
> > So, how is the correct process to add an additional DNSKEY (only the public > key is known). > > I think you are looking for `dnssec-importkey`. Indeed. I imported the key and got a .key and .private file. I put those files in the same directory as the other keys, gave read permissions to bi

How to prepublish additional DNSKEY

2020-07-08 Thread Klaus Darilion
Hello all! A signed zone shall be moved to another DNS provider. Hence I want to add the public KSK of the gaining DNS provider as additional DNSKEY to the zone. My setup ist: Bind1 as hidden primary --> Bind2 as bump-in-the-wire signer -> public facing secondaries I tried to add the DNSKEY t

AW: NSEC3 salt change - temporary performance decline

2020-06-09 Thread Klaus Darilion
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Cathy > Almond > Gesendet: Dienstag, 9. Juni 2020 14:30 > An: bind-users@lists.isc.org > Betreff: Re: NSEC3 salt change - temporary performance decline ... > > FYI this will be fixed in the June 2020 BIND releases (in 9.11.20, >

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
> Am 15.04.20 um 10:08 schrieb Ondřej Surý: > > you need to stop being rude to people on the bind-users mailing list, > > personal attacks are not acceptable behaviour here. You should apologize > > to Klaus. > > it's not a personal attack to clearly point out that discussions of > distribution le

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
Thanks for answer! So actually it is just a cosmetic change not addressing a real problem. I will miss the bind9 service :-( Klaus > -Ursprüngliche Nachricht- > Von: Ondřej Surý > Gesendet: Mittwoch, 15. April 2020 10:15 > An: Klaus Darilion > Cc: bind-users@lists.is

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
> -Ursprüngliche Nachricht- > Von: bind-users Im Auftrag von Reindl > Harald > Gesendet: Mittwoch, 15. April 2020 09:17 > An: bind-users@lists.isc.org > Betreff: Re: Debian/Ubuntu: Why was the service renamed from bind9 to > named? > > > > Am 15.04.2

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
> > It would be great if you undo this change before release of 18.04 > > you confuse the upstream project with your distribution > > bind9 was completly wrong in the debian world as well as apache2 for > httpd, on sane distributions it's "httpt" and "named" all the years > beause it's nonsense t

AW: Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-15 Thread Klaus Darilion
20 um 08:56 schrieb Reindl Harald: > > > > > > Am 15.04.20 um 08:51 schrieb Klaus Darilion: > >> Hello! > >> > >> What is the rationale of: > >> > >> bind9 (1:9.13.6-1) experimental; urgency=medium > >> ... > >> * Rename

Debian/Ubuntu: Why was the service renamed from bind9 to named?

2020-04-14 Thread Klaus Darilion
Hello! What is the rationale of: bind9 (1:9.13.6-1) experimental; urgency=medium ... * Rename the init scripts to named to match the name of the daemon Since years, Debian and Ubuntu User, and plenty of scripts and automation software (Puppet ...), know that the service is called "bind9". I

max-ixfr-ratio values

2020-03-22 Thread Klaus Darilion
max-ixfr-ratio introduced with 9.17.0 sounds like a workaround instead of a bugfix. Anyway, can you recommend a sensible settings? I.e. when does the performance problem of "large" IXFR starts to happen? Does this depend on the ratio of the IXFR-size to zone-size, or does it depend on the siz

What happens if the max-tcp-connections limit is reached?

2020-03-04 Thread Klaus Darilion
Hello all! Will bind refuse (close) the new TCP connections, or will it accept the new connection and closes the longest idle TCP connection? Or even better? Thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: NSEC3 salt change - temporary performance decline

2020-01-29 Thread Klaus Darilion
Am 21.01.2020 um 16:40 schrieb Ondřej Surý: > We are currently investigating performance degradation related to big IXFRs. > Do you use ixfr-from-differences in your BIND configuration? You could try > enforcing AFRX on salt change. > > This is currently tracked as > https://gitlab.isc.org/is

Re: NSEC3 salt change - temporary performance decline

2020-01-29 Thread Klaus Darilion
Hello Niels! Thanks for bringing this to attention. I have reported it before [1][2] without response. We see this regulary. AFAIS it happens actually always, but if the IXFR is small, the performance decline is so short that you usually won't notice it. The bigger the zonechange ie NSEC3 change

Re: BIND setup for GSLB (Global Service Load Balancing)

2019-10-02 Thread Klaus Darilion
Am 12.09.2019 um 17:39 schrieb Roberto Carna: Hi people, is it possible to setup BIND in order to implement GSLB (Global Service Load Balancing) between two sites ? I need a near Active-Active scenario between two datacenters in different locations, and I want to do this with an open source so

Re: journal file is out of date: removing journal file

2019-07-31 Thread Klaus Darilion
Hi Tony! Am 31.07.2019 um 12:44 schrieb Tony Finch: > Klaus Darilion wrote: >> >> What does the log message "journal file is out of date: removing journal >> file" exactly mean? Is it somehow problematic? > > After loading a zone, named discovers the seri

journal file is out of date: removing journal file

2019-07-30 Thread Klaus Darilion
Hello! BIND 9.12.2-P2, max-journal-size 1m; What does the log message "journal file is out of date: removing journal file" exactly mean? Is it somehow problematic? I have bind as bump in the wire signer, and regularly problems with slow zone updates for a specific zone which often, almost every

Re: IXFR fallback to AXFR if diff is bigger than zone

2019-07-12 Thread Klaus Darilion
Hi Tony! Am 12.07.2019 um 13:00 schrieb Tony Finch: > Yes, that is curious. Are you sure it isn't actually doing an > IXFR-flavoured AXFR of the whole zone, rather than a delta? We have a setup with severals Bind in a row: hidden master customer (software unknown) | | V o

IXFR fallback to AXFR if diff is bigger than zone

2019-07-12 Thread Klaus Darilion
Hi! I wonder how Bind as master handles IXFR when the requested IXFR would be much than the AXFR. (For example: if you change the NSEC3 salt). Are there some mechanisms to detect such a situation and trigger a fallback to AXFR or will Bind always perform IXFR? thanks Klaus PS: AFAIK the max jou

Re: Bind max socket/query per IP

2019-05-22 Thread Klaus Darilion
Am 21.05.2019 um 22:31 schrieb Ict Security: Under heavy load, Bind becomes extremely load above a certain number of Qps but, if i query an alias IP address (where normally queries don't arrive), Bind answers immediately. btw - how high is the "extremely load"? Klaus _

Re: BIND 9.10 fast only on alias IP

2019-05-22 Thread Klaus Darilion
Am 20.05.2019 um 20:16 schrieb Ict Security: How could i increase the number of socket on a single IP address, since Bind is working perfectly on the secondary address, when the first one is stucked? If the incoming traffic is bursty it may happen that the receive queue of the socket is full a

Re: max file size or line count for BIND zone file

2019-04-25 Thread Klaus Darilion
Am 25.04.2019 um 14:10 schrieb Martin Meadows via bind-users: Wondering if anyone is aware of a max file size or max number of lines that a given BIND zone file can contain? IF you use a journal, things may get complicated if your journal is over 2G: https://kb.isc.org/docs/aa-01627 regar

Bind Auth responds slow during incoming XFR

2019-03-27 Thread Klaus Darilion
Hello! We have a problem with Bind [2] during incoming IXFR. When there is a huge IXFR (ie 1,8GB tranferred in 15minutes [1]), the response time heavily increases. Using dsc's newest "Reponse Time Indexer" we clearly see that Bind answers slow: Response Time normal during Window

Re: Operational Notification: Extremely large zone transfers can result in corrupted journal files or server process termination

2018-07-16 Thread Klaus Darilion via bind-users
Am 14.07.2018 um 00:38 schrieb Matthew Pounsett: > On 13 July 2018 at 06:04, Michał Kępień wrote: > >> Hopefully this will shed some light on the matter: >> >> https://gitlab.isc.org/isc-projects/bind9/issues/339#note_12805 >> >> That is helpful, thanks. That comment says the issue require

Fwd: Operational Notification: Extremely large zone transfers can result in corrupted journal files or server process termination

2018-07-09 Thread Klaus Darilion
What is an "extraordinarily large zone transfer"? We do have regularly AXFR and IXFRs around 2GB. Is this "extraordinarily large"? regards Klaus Weitergeleitete Nachricht Betreff: Operational Notification: Extremely large zone transfers can result in corrupted journal file

Re: timestamp in journal

2018-07-09 Thread Klaus Darilion
Hi Anand! Am 09.07.2018 um 14:04 schrieb Anand Buddhdev: On 09/07/2018 13:50, Klaus Darilion wrote: Hi Klaus, named-journalprint dumps the journal without any time information. Does the journal include time information? (Timestamp of add/del) If yes, can I somehow extract the timestamps

timestamp in journal

2018-07-09 Thread Klaus Darilion
Hi! named-journalprint dumps the journal without any time information. Does the journal include time information? (Timestamp of add/del) If yes, can I somehow extract the timestamps? thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo

Re: Slow reply under heavy load (on a specific NIC ip)

2018-06-15 Thread Klaus Darilion
Am 04.06.2018 um 14:20 schrieb Ict Security: Hi guys, we are running a Bind 9.x Server, everything is going fine. Under particular heavy load mometns, with some hundreds of concurrent queries coming in, sometime Bing stops answering for some seconds or answer with important delays. But, when i

Re: sporadic timeouts querying bind9

2018-04-23 Thread Klaus Darilion
This time with log file attached Thanks Klaus Am 23.04.2018 um 14:55 schrieb Klaus Darilion via bind-users: > Hi all! > > Upgrading to Ubuntu 16.04 with Bind 9.10.3 did not solved the problem. > > I enabled debug log (trace 2) and query logging. Unless my monitoring > tr

Re: sporadic timeouts querying bind9

2018-04-23 Thread Klaus Darilion via bind-users
locking operations in bind? Thanks Klaus Am 15.03.2018 um 14:45 schrieb Klaus Darilion: > Hi! > > I use bind 9.9.5.dfsg-3ubuntu0.17 with around 20 slave zones (from small > to huge). > > I query the SOA of every configured zone once a second to monitor bind. > > Once

Re: Suggestions for a distributed DNS zone hosting solution I'm designing

2018-03-17 Thread Klaus Darilion
Hi Latitude! Short answer: I think 2s delay is not possible in a distributed system with many global distributed slaves and limited ressources. Long answer: It all depends on how much money you have and time in setting up such a service - long comments inline. Am 07.03.2018 um 07:10 schrieb

sporadic timeouts querying bind9

2018-03-15 Thread Klaus Darilion
Hi! I use bind 9.9.5.dfsg-3ubuntu0.17 with around 20 slave zones (from small to huge). I query the SOA of every configured zone once a second to monitor bind. Once a day my script reports timeouts (3 seconds) querying a SOA. This server is a test server, hence it is idle except the monitoring ch

Re: are journal files required on slave?

2018-03-15 Thread Klaus Darilion
Am 14.03.2018 um 15:20 schrieb Tony Finch: > Klaus Darilion wrote: >> >> I have now set >> max-journal-size 50M; >> and restartet bind a few times. But the journal files are still GBytes. >> When should Bind flush the journal into the zone file? >

Re: are journal files required on slave?

2018-03-14 Thread Klaus Darilion
Am 14.03.2018 um 13:38 schrieb Tony Finch: > Klaus Darilion wrote: >> >> Thanks for the detailed answer. So I will use a few MBytes. But would it >> be possible to set max-journal-size=0? > > There's a minimum journal size (the calculation in the code comes to

Re: are journal files required on slave?

2018-03-14 Thread Klaus Darilion
Am 14.03.2018 um 13:04 schrieb Tony Finch: > Klaus Darilion wrote: >> >> But on a server with slave-zone only (fetched by ixfr) - do I need a >> journal at all? How can I disable it - by setting the max-size to 0? > > The journal reduces the cost of re-writing zone

Re: Maximum zone file size

2018-03-14 Thread Klaus Darilion
Am 14.03.2018 um 13:10 schrieb Ray Bellis: > On 14/03/2018 12:08, Anand Buddhdev wrote: > >> Not that I know of. The amount of RAM in a server is probably the most >> significant limit for loading zones into BIND. > > Anand is correct - there's no intrinsic limit other than RAM. > > I personal

Maximum zone file size

2018-03-14 Thread Klaus Darilion
Hi! I couldn't find it online - is there a limit on the zone file size? Thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.or

are journal files required on slave?

2018-03-14 Thread Klaus Darilion
Hi! The default setting of max-journal-size filled my disk. I do have plenty of zone from KByte to GByte. So I wonder, what would be the perfect size to configure. So, I wondered - do I need a journal at all? I know the journal is needed for ixfr-from-differences and DDNS. But on a server with sl

questions about rndc zonestatus

2017-12-19 Thread Klaus Darilion
Hi! I would like to use this feature to check the status of my slave zones. # rndc zonestatus nic.at name: nic.at type: slave files: /etc/bind/zones/nic.at serial: 2017121119 nodes: 77 next refresh: Tue, 19 Dec 2017 08:34:53 GMT expires: Tue, 02 Jan 2018 07:50:08 GMT secure: yes inline signing: n

Re: How to check slave zone freshness

2016-02-10 Thread Klaus Darilion
On 10.02.2016 09:27, Klaus Darilion wrote: > > > On 08.02.2016 14:58, Tony Finch wrote: >> Klaus Darilion wrote: >>> >>> I want to monitor the freshness of my slaves zones. Is it somehow >>> possible to extract the status of slave-zones from bind?

Re: How to check slave zone freshness

2016-02-10 Thread Klaus Darilion
On 08.02.2016 14:58, Tony Finch wrote: > Klaus Darilion wrote: >> >> I want to monitor the freshness of my slaves zones. Is it somehow >> possible to extract the status of slave-zones from bind? > > If you are running 9.10 or later you can use `rndc zonestatus`.

Re: How to check slave zone freshness

2016-02-09 Thread Klaus Darilion
On 08.02.2016 20:49, Mark Andrews wrote: > With a modern nameserver that supports the expire edns option you can > also do "dig +expire soa zone @server" which will tell you how long > until the zone will expire on this server. Aha, but isn't this a different kind of information? A zone which is

Re: How to check slave zone freshness

2016-02-08 Thread Klaus Darilion
Am 08.02.2016 um 14:58 schrieb Tony Finch: > Klaus Darilion wrote: >> >> I want to monitor the freshness of my slaves zones. Is it somehow >> possible to extract the status of slave-zones from bind? > > If you are running 9.10 or later you can use `rndc zonestatus`

Re: How to check slave zone freshness

2016-02-08 Thread Klaus Darilion
Am 08.02.2016 um 14:59 schrieb Warren Kumari: > The standard, compatible way to do this is simply to do a lookup for the > SOA record and make sure that the serial number matches what you expect > it to be / what is on the master. I'm not sure what monitoring tool you > are using (or if you are w

How to check slave zone freshness

2016-02-08 Thread Klaus Darilion
Hi! I want to monitor the freshness of my slaves zones. Is it somehow possible to extract the status of slave-zones from bind? Thanks Klaus ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mai

Re: rndc (and now nsupdate too)

2014-08-19 Thread Klaus Darilion
Am 31.07.2014 21:08, schrieb /dev/rob0: The proper tool to manage named configuration and operation, and which in the best Unix ethic is well suited for automation, is rndc(8). You can not always use rndc. For example you can add and delete zones, but you can not modify zones via rndc. regards

Re: Reload BIND to listen on additional interface?

2014-08-14 Thread Klaus Darilion
If you manually configure the listen-on IP addresses, that may help: http://linux-ip.net/html/adv-nonlocal-bind.html regards Klaus On 31.07.2014 13:24, Johannes Kastl wrote: > Hi everyone, > > in the quest to use a master behind a Router with changing IPs, I set > up a VPN and told bind on both

Retrying failed zone transfer

2014-07-22 Thread Klaus Darilion
Hi! I have a Bind 9.9.5 running as slave. The master is not configured correctly and rejects the zone transfer. It seems that if Bind has never received the zone yet, it tries endlessly to fetch the zone (see below), ~3 times per second. It would be nice if Bind for example retries only every min

dynamically adding/removing TSIG configuration

2014-07-07 Thread Klaus Darilion
Hi! I currently use rndc addzone/delzone to manage zones on my slave. I now want to add TSIG for some of these zones and I want to be able to enable/disable TSIG dynamically per zone. Unfortunately I haven't found a nice solution yet. My results are: 1. delzone/addzone with adding the tsig key n

incomplete NSEC3 chains

2014-06-30 Thread Klaus Darilion
Release: BIND 9.9.5 I regularly perform key rollovers and zone validation of an inline-signed zone. The zone validator receives NOTIFYs and then it transfers the zone and validates it (using dnssec-verify and validns). I also regularly call "rndc retransfer" to make sure to have an correct zone.

Re: Bind ignoring signing -nsec3param when inline-signing a zone

2014-06-05 Thread Klaus Darilion
before calling "rndc signing nsec3param" - this is not nice. Are there any workarounds for that? IMO it would be cool if Bind would store NSEC3 options outside of the zone. Thanks Klaus On 05.06.2014 14:02, Klaus Darilion wrote: > Hi! > > Today I managed that Bind 9.9.5 crea

Bind ignoring signing -nsec3param when inline-signing a zone

2014-06-05 Thread Klaus Darilion
Hi! Today I managed that Bind 9.9.5 created a signed zone with all RRs signed except the SOA. The private RRs showed "finshed signing". Only after another "rndc loadkeys" also the SOA was signed. Unfortunately I can not reproduce the problem, but I suspect it may be related to the order how I add

  1   2   >