named.conf splitting

2012-02-17 Thread Nick Edwards
Hi, In a recent discussion on another list, it was discussed the pros and cons of splitting the main conf file to a per domain. In binds case it would be to /etc/named.d/*.conf So each zone would have a file in that directory containing only the relevant info eg: zone "example.com" { ty

DNSSEC and slaves error

2012-03-07 Thread Nick Edwards
I am an old hand at bind, but - DNSSEC Newbie alert :-> I am after clarification on how slaves handle DNSSEC. I have two slaves, both were stale, like since Feb 9 ! One I directly control, the second, I do not, so I can not provide details on how that one is configured, but given it is a reputab

Re: DNSSEC and slaves error

2012-03-07 Thread Nick Edwards
On 3/7/12, Mark Andrews wrote: >> resigned it again as about 3 months using:dnssec-signzone -a -e >> +15724800 -K keys/ -N INCREMENT guilty_domain.here > > You should have fed dnssec-signzone the old signed zone not the unsigned > zone. > > dnssec-signzone -f guilty_domain.here.signed -N

Re: DNSSEC and slaves error

2012-03-07 Thread Nick Edwards
On 3/8/12, Nick Edwards wrote: > On 3/7/12, Mark Andrews wrote: > >>> resigned it again as about 3 months using:dnssec-signzone -a -e >>> +15724800 -K keys/ -N INCREMENT guilty_domain.here >> >> You should have fed dnssec-signzone the old signed zone no

Re: DNSSEC and slaves error

2012-03-08 Thread Nick Edwards
Thanks, that did the trick! On 3/8/12, Mark Andrews wrote: > > In message > > , Nick Edwards writes: >> On 3/8/12, Nick Edwards wrote: >> > On 3/7/12, Mark Andrews wrote: >> > >> >>> resigned it again as about 3 months using:dnssec-si

Re: DNS Blackholing

2012-12-04 Thread Nick Edwards
Hi All, Is there a way for RPZ zone file to act on domain AND subdomains without using two separate entries? At present I can only get them to match on one or the other unless I do example.comblah *.example.com blah I'm sure I've missed the obvious, but thought I'd ask

nxdomain

2013-08-28 Thread Nick Edwards
Hi, In just testing a few things with our authoritative server, I made a typo, and, much to my surprise the server responds NXDOMAIN to requests from unauthed requesters, this used to return REFUSED, when did this error change? (bind 9.9.3-P2) ___ Pleas

Re: nxdomain

2013-08-28 Thread Nick Edwards
ile-format text; interface-interval 0; dnssec-enable yes; dnssec-validation yes; }; On 8/28/13, Matus UHLAR - fantomas wrote: > On 28.08.13 23:13, Nick Edwards wrote: >>In just testing a few things with our authoritative server, I made a >>typo, and, much to my surprise t

Re: nxdomain

2013-08-28 Thread Nick Edwards
Mark, On 8/29/13, Mark Andrews wrote: > > In message > > , Nick Edwards writes: >> The typos was more of how I came about my request, forget the typo as >> such, it the actual answer, to use a more common well known name, if >> I type >> >> ~$ host w

Re: nxdomain

2013-08-29 Thread Nick Edwards
easy. On 8/29/13, Mark Andrews wrote: > > In message > > , Nick Edwards writes: >> Mark, >> >> On 8/29/13, Mark Andrews wrote: >> > >> > In message >> > >> > , Nick Edwards writes: >> >> The typos was more of how I c

Re: Logs problem with Bind 9.9.4

2014-08-08 Thread Nick Edwards
bugger off with your dictatorship do not bring it here like you take it every list you go to, well, those that you have not been kicked off of that is On 8/2/14, Reindl Harald wrote: > why do you reply off-list, in HTML and top-posting? > ___ Please vi

Re: Logs problem with Bind 9.9.4

2014-08-08 Thread Nick Edwards
maybe he will, when you learn to stop being so offensive and abusive on every list you decide to join, and to tink a cvertain blacklsit operator on this list a few days ago said you were well behaved, hrmmm are you paying him you off so he wont list you again in his rbl On 8/3/14, Reindl Harald

shutting up logs

2015-05-14 Thread Nick Edwards
skipping nameserver 'ns5.concord.org' because it is a CNAME, while resolving '210.128-25.119.138.63.in-addr.arpa/PTR' I have logs grow by about 30 megs a day with pretty much only this in it (of course not always same remote server), how do I shut this up ? My logging statments are logging {

lookout timesouts

2016-09-19 Thread Nick Edwards
Hi, We have a customer who has their own cache server, but in the afternoons before they close up for the day, they commit off-site backups, this process takes them about 90 mins, anyone trying to use the internet in this time fails 99.9% of the time due to DNS lookup errors, but if they use an ex

Re: lookout timesouts

2016-09-21 Thread Nick Edwards
Thanks Mark, it's likely reason, they are using a microtek or such junk if my memory serves me correct, we will drop in a juniper and see if that resolves it. On Tue, Sep 20, 2016 at 7:51 AM, Mark Andrews wrote: > > In message qozh...@mail.gmail.com>, Nick Edwards writ

Re: authority

2016-10-24 Thread Nick Edwards
On Tue, Oct 25, 2016 at 12:11 AM, Reindl Harald wrote: > identical like the first one > > Which IP should be use? >> > > i don't understand your question > > Since you have NOTHING to do with ISC or even remotely with bind, if you dont understand , LEAVE IT TO SOMEONE WHO DOES but you just cant

Re: authority

2016-10-24 Thread Nick Edwards
On Tue, Oct 25, 2016 at 12:42 AM, Reindl Harald wrote: > > > >> > don't get me wrong but that question shows that you are not ready to run a > public dns server - there is no "local" or > when you make statements like that to be sure you include the fact you have NOTHING to do with ISC or bind.

Re: authority

2016-10-24 Thread Nick Edwards
On Tue, Oct 25, 2016 at 7:11 AM, Reindl Harald wrote: > > i don't understand your question >> >> >> Since you have NOTHING to do with ISC or even remotely with bind, if you >> dont understand , LEAVE IT TO SOMEONE WHO DOES >> > > and YOU have something to do with ISC? > i doubt! > > since i m

Re: authority

2016-10-24 Thread Nick Edwards
On Tue, Oct 25, 2016 at 7:14 AM, Reindl Harald wrote: > > > > this is a public mailing list - so what! > > when someone don't yet get the connection between nameservers, webserver > and ip-addresses he is not ready to connect public servers and that's > completly independent of the fact you ra el

Re: BIND 9.11.6-P1 build fails on Solaris

2019-04-30 Thread Nick Edwards
lots of things failing in recent times, even with CentOS, mostly because of openssl min version changes, and most recently even latest releases wont build now because of a change in min python versions *sigh*, i'm just going to leave it as is, thats all we can do. On Fri, Apr 26, 2019 at 5:05 AM