Re: Forwarding request to another DNS server but the same domain

2014-04-30 Thread John Miller
e's nameservers? What's preventing you from setting up a second recursive nameserver in each office? John On Wed, Apr 30, 2014 at 4:32 PM, Jeronimo L. Cabral wrote: > Dear John, this is my scenario: > > 1) Office 1: people work with some machines and fill up a local master &g

Re: Forwarding request to another DNS server but the same domain

2014-04-30 Thread John Miller
nual: "Forwarding occurs only on those queries for which the server is not authoritative and does not have the answer in its cache." What exactly are you trying to achieve? John On Wed, Apr 30, 2014 at 3:55 PM, Jeronimo L. Cabral wrote: > Dear, I would like to ask for solution rela

Re: Dig for a reverse zone transfer

2014-04-22 Thread John Miller
Hi Roberto, Yep, that should do it. John On Tue, Apr 22, 2014 at 4:11 PM, Roberto Carna wrote: > Dear, what are the dig syntaxis in order to get a reverse zone > transfer from a DNS server ??? > > is this correct: > > dig @ 1.168.192.in-addr.arpa axfr > > T

Re: Can Master replicate zone options in Slave's named.conf.local file ???

2014-04-16 Thread John Miller
nto config management it goes. John On Wed, Apr 16, 2014 at 1:53 PM, Roberto Carna wrote: > OK Jeff, thanksso the only way to write these bottom lines in the > Slave is by hand (except if use scp or something similar)??? > > zone "company.com" { > type

Re: Clients Matching Multiple Views

2014-04-11 Thread John Wobus
would be a good thing to know. John Wobus Cornell U ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: how to modify the cache

2014-02-14 Thread John Miller
Are you trying to override the IP address locally, or are you just trying to get the correct value into cache? John On Fri, Feb 14, 2014 at 8:52 AM, houguanghua wrote: > Hi all, > Bind provides rndc tools to operate the cache. But how to change a record > in the cache. For example: &g

Re: DNS passthrough on no explicit result?

2014-01-31 Thread John Miller
rom derived A or records. > > > Vernon Schryverv...@rhyolite.com > Indeed, the intent of my words was that SPF only makes sense if it's public--presumably you set up trust between your internal mail servers in other ways. It's not required for SMTP to work--plen

Re: DNS passthrough on no explicit result?

2014-01-31 Thread John Miller
lic as well? If everything can be public, why the question? If you want internal-only records, why not just do split horizon of some sort where you use zoneedit as a slave and your local BIND view as a master? That way you have two views, one for internal IPs, and one for external IPs.

Re: Variable SOAs in negative responses

2014-01-28 Thread John Levine
that Gmail (or whoever) would suddenly start sending so much spam that it would swamp the real mail and make them worth listing are extremely low. I realize there are DNSBLs that list on the merest whiff of spam and don't care if they block legitimate mail. That's not what we're tal

Variable SOAs in negative responses

2014-01-27 Thread John Levine
A friend (really) asks this question: they have some DNSBLs, which get a lot of queries. Sometimes the answer has A or TXT records, meaning the corresponding address is listed in the DNSBL, sometimes it's NXDOMAIN which means the address isn't. For addresses that aren't listed, some of the NXDOMA

Re: Rate-limiting - working? How to test?

2014-01-17 Thread John Horne
ry-errors (can’t remember which off the top of my head). > Yup, that was it :-) I had no 'query-errors' logging set up. I now see the queries being rate-limited (or they would be if I removed/changed the 'log-only' option.) Thanks, John. __

Rate-limiting - working? How to test?

2014-01-17 Thread John Horne
bind logs contain anything about rate limiting). Thanks, John. ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Can we do a sub-domain delegation with godaddy?

2014-01-15 Thread John Levine
Large cheap hosting services like Godaddy do not deal well with exceptions. Pointing the 2LD at your servers is normal, delegating a subdomain is an exception. If you have web or other hosting there, you can still point the DNS records back at them as needed

Re: Query regardign CNAME

2014-01-01 Thread John Levine
>>>xyz.gov.in. DNAME xyz.in. >On 01.01.14 18:16, John Levine wrote: >>Except that DNAME only applies to names under xyz.gov.in, not to >>xyz.gov.in itself. > >Usually because xyz.gov.in must already have SOA and NS records and >therefore it's not possib

Re: Query regardign CNAME

2014-01-01 Thread John Levine
he same file to zone files for both >domains as Leonard Mills recommended. is the easiest way to do it if you're using BIND. R's, John ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bin

Re: DDNS update forwarding

2013-12-12 Thread John Miller
On 12/11/2013 08:42 PM, Mark Andrews wrote: In message <52a8e44a.1070...@brandeis.edu>, John Miller writes: Hello folks, I'm getting ready to revamp our dynamic DNS setup here on campus, and am curious: what is everyone doing for update forwarding? Have you seen certain clients tha

DDNS update forwarding

2013-12-11 Thread John Miller
been bitten by leaving update forwarding disabled? John ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Refreshing cache in other DNS Servers

2013-10-16 Thread Manson, John
I would add that Windows PC OSs by default have the dns client cache set to 'enable'. John Manson U.S. House of Representatives | HIR Data Communications | Washington, DC 20515 Desk: 202-226-4244 | NCC: 202-226-6430 | john.man...@mail

Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread John Oliver
On Mon, 14 Oct 2013 11:08:33 -0500, /dev/rob0 wrote: > On Mon, Oct 14, 2013 at 10:06:07AM +0100, Phil Mayers wrote: >> On 10/13/2013 10:34 PM, John Oliver wrote: >> >> >Venting aside, does anyone have a contact at GoDaddy that doesn't >> >suffer from a ter

Re: Terrible trouble with DNSSEC and GoDaddy

2013-10-14 Thread John Oliver
On Mon, 14 Oct 2013 11:08:33 -0500, /dev/rob0 wrote: > On Mon, Oct 14, 2013 at 10:06:07AM +0100, Phil Mayers wrote: >> On 10/13/2013 10:34 PM, John Oliver wrote: >> >> >Venting aside, does anyone have a contact at GoDaddy that doesn't >> >suffer from a ter

Terrible trouble with DNSSEC and GoDaddy

2013-10-13 Thread John Oliver
s all my fault, and I should abandon IPv6 because it just doesn't work with DNSSEC? Venting aside, does anyone have a contact at GoDaddy that doesn't suffer from a terminal case of rectal-cranial invesrion? I'm mainly experimenting with DNSSEC, and don't want to

Re: TXT Record Format with multiple records?

2013-10-12 Thread John Levine
>Please forgive my ignorance, and sorry about all the details. I have >not been able to find a detailed specification. TXT records haven't changed since RFC 1034 and 1035. You can have multiple strings per record, and multiple records per name. At the application level, some applications glom mu

Re: TXT Record Format with multiple records?

2013-10-11 Thread John Levine
>How, precisely, is the second (or third) string added? plugh.example TXT "foo" "bar" ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.o

NS record TTL versus nameserver's A record TTL

2013-10-08 Thread John Wobus
essed by a "best practice"? -If neither of the above, is there a "hidden practice that knowing folk often follow to dodge remote nameserver deficiencies"? FYI, I only received the report fourth hand and can't tell you the nameserver software that had this issue. J

What is proper fault-tolerant behavior?

2013-09-17 Thread Manson, John
To add to Len's comments, bind will keep going to the partially broken Fedora dns as long as it has the fastest response time. As a short term fix, you can use the 'blackhole' option to prevent your dns from sending queries to that IP. John Manson U.S. House of Representat

Re: how-to configure BIND or any DNS implementation for cloud infrastructure

2013-08-30 Thread John Miller
looking to run a nameserver hosted in EC2/Rackspace/etc., you can install whatever DNS server you like--you're managing the box yourself. John On Fri, Aug 30, 2013 at 12:01 PM, Odimegwu David wrote: > Is it possible for one to configure BIND or any DNS implementation for the > cloud? >

Re: Strange problem with a query deleting a record...

2013-08-24 Thread John E.P. Hynes
browser never asks for anything but an A record, which succeeds. I've contacted the site in question with this info, so hopefully it'll get resolved. I'll keep the list posted on any results or info for posterity. -John -- Please consider the environment bef

Re: ISO or virtual appliance

2013-08-21 Thread John Miller
tion, you need to understand the innards and be prepared to do your own maintenance, or you need to pay someone for support. John On 08/21/2013 02:34 PM, Manish Rane wrote: Hi Guys, Is there any ISO or virtual appliance available for BIND? Which ease out the deploy and configur

Re: Internernal view is answering to external ping

2013-08-02 Thread John Wobus
it is a client issue. On the other hand if both give the same unwanted answer, you have evidence it is a server configuration issue. John Wobus Cornell University IT ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: resolving-problem

2013-07-23 Thread John Wingenbach
nward. Do not bother using +trace when your system is not by default performing the entire resolution. When you find the system which is failing to resolve the name, then you know it is a problem w/ that system and it's next step towards the internet. -- John On 7/23/2013 12:35 PM,

Re: RFC requirements for relative CNAME targets?

2013-07-18 Thread John Miller
On 07/18/2013 06:07 PM, Barry Margolin wrote: In article , John Miller wrote: I think what I was getting at was whether appending $ORIGIN to an unqualified target--only talking target, not label--was _required_ by the RFCs, and if so, the RFC/section. I'll read through 'em; was j

Re: RFC requirements for relative CNAME targets?

2013-07-18 Thread John Miller
Hi Ryan, Sorry I wasn't more clear in my original post. Barry hit the nail on the head: I was curious if the RFCs required BIND to append $ORIGIN to targets that aren't fully qualified. Sounds like they do. I appreciate the help! John On 07/18/2013 05:59 PM, Novosielski,

Re: RFC requirements for relative CNAME targets?

2013-07-18 Thread John Miller
On 07/18/2013 06:07 PM, Barry Margolin wrote: In article , John Miller wrote: I think what I was getting at was whether appending $ORIGIN to an unqualified target--only talking target, not label--was _required_ by the RFCs, and if so, the RFC/section. I'll read through 'em; was j

Re: RFC requirements for relative CNAME targets?

2013-07-18 Thread John Levine
FC 1034, page 34. R's, John ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: RFC requirements for relative CNAME targets?

2013-07-18 Thread John Miller
On Thu, Jul 18, 2013 at 4:29 PM, Charles Swiger wrote: > On Jul 18, 2013, at 1:18 PM, John Miller wrote: > > I know that for the following record in example.com's zone file: > > > > host.example.com. IN CNAME otherhost > > > > BIND will retur

Re: RFC requirements for relative CNAME targets?

2013-07-18 Thread John Miller
CNAME otherhost. be equally valid from an RFC perspective? Obviously this would also pertain to NS, MX, SRV, PTR, etc. records. John On Thu, Jul 18, 2013 at 4:12 PM, John Miller wrote: > Hey there folks, > > I know that for the following record in a zone file: > > host.exampl

RFC requirements for relative CNAME targets?

2013-07-18 Thread John Miller
Hey there folks, I know that for the following record in a zone file: host.example.com. -- John Miller Systems Engineer Brandeis University johnm...@brandeis.edu (781) 736-4619 ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: Reverse address entries

2013-07-05 Thread John Wobus
IPV6 poses challenges for some DNS strategies, e.g. setting up static "placeholder" DNS records for each address in a dynamically-addressed subnet. John Cornell University IT ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubsc

Re: How to suppress ADDITIONAL SECTION per zone

2013-07-05 Thread John Wobus
experience is: the RRL patch, used with its default parameters, simply does the job. John Cornell University IT ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users

Re: Bind unable to get MX reocrd from Parrent name server

2013-07-05 Thread John Wobus
se domains that are incorrectly set up. The ideal way to fix the issue is to get the owner of the domain to fix it. John Cornell University IT On Jul 5, 2013, at 7:59 AM, Fosiul Alam wrote: Hi thanks for reply, I am not the domain admin for "rbcaa.co.za" I can see they have issue wit

Re: Reverse address entries

2013-07-02 Thread John Horne
On Tue, 2013-07-02 at 12:02 -0700, Eduardo Bonsi wrote: > On 7/2/13 9:35 AM, John Horne wrote: > > > > We were alerted to the problem because we got long delays (around 20 > > seconds) when accessing a site doing a reverse lookup. That service > > then, no doubt

Re: Reverse address entries

2013-07-02 Thread John Horne
oing a reverse lookup. That service then, no doubt the same as with SMTP, then proceeded but without the reverse lookup answer. John. -- John Horne, Plymouth University, UK Tel: +44 (0)1752 587287Fax: +44 (0)1752 587001 ___ Please visit https:/

Re: bind-users Digest, Vol 1560, Issue 1

2013-07-02 Thread Manson, John
Give each instance of named a unique name: A-named, b-named, etc - Original Message - From: bind-users-requ...@lists.isc.org [mailto:bind-users-requ...@lists.isc.org] Sent: Tuesday, July 02, 2013 08:00 AM To: bind-users@lists.isc.org Subject: bind-users Digest, Vol 1560, Issue 1 Send

Re: Answers from cache or authority section?

2013-06-25 Thread John Horne
On Tue, 2013-06-25 at 17:20 +0100, Phil Mayers wrote: > On 25/06/13 16:53, John Horne wrote: > > > servers. However, there is a whole load of muttering that Microsoft and > > AD won't like that; it's all integrated with each other; running the DNS > > zone on Li

Re: Answers from cache or authority section?

2013-06-25 Thread John Horne
On Tue, 2013-06-25 at 17:07 +0100, Steven Carr wrote: > On 25 June 2013 16:53, John Horne wrote: > > So what I now do not understand is why (at home) I can do several > > reverse lookups for different IP addresses, and they all give me an > > answer. Likewise i

Re: Answers from cache or authority section?

2013-06-25 Thread John Horne
that the internal servers should be just that - internal. Ideal would be moving the reverse zone onto the Internet-facing Linux servers. However, there is a whole load of muttering that Microsoft and AD won't like that; it's all integrated with each other; running the DNS zone on Linux servers w

Answers from cache or authority section?

2013-06-25 Thread John Horne
they are only provided by our internal servers, then all the lookups should fail. Comments? Corrections to where I have gone wrong? I should point out that I have for a long time banged on at management about the fact that our internal name servers are visible on the Internet but cannot be acc

Re: RPZ - how to modify NS records in answer?

2013-06-21 Thread John Horne
On Fri, 2013-06-21 at 17:11 +0100, John Horne wrote: > > My understanding is that RPZ can do this, but I just cannot seem to > configure the RPZ zone file to enable this. The zone file contains: > = > $TTL 1H > @ SOA LOCALHOST. hostmaster.plymouth.ac.

RPZ - how to modify NS records in answer?

2013-06-21 Thread John Horne
ill returns both 'dns0' and 'dns1'. Likewise using just '.' as the rdata made no difference. So, I'm wondering what the RPZ zone file should contain to enable an NS record to be omitted from the reply? Thanks, John. -- John Horne, Plymouth University, UK Tel

Re: Secondary DNS question...

2013-06-20 Thread John Miller
, so won't make any assumptions there. That said, some general info: outside MXes use authoritative DNS to send to you; your incoming MX servers use recursive DNS to do any reverse lookups on sender IPs, to query DNSBLs, and to get SPF/DKIM/DMARC info; outgoing MXes use recursive DNS to find outside MX

Re: PTR files

2013-06-17 Thread John Miller
it's clear that your issue is with BIND and how you've configured it. John On Mon, Jun 17, 2013 at 11:37 PM, Doug Barton wrote: > Norman, > > It's virtually certain that the error you're seeing is not related to > BIND. You would almost certainly get your pro

Rate-Limit Question

2013-06-14 Thread Manson, John
We are running Bind 9.9.2 and would like to invoke the rate-limit option but named says 'unknown option'. Do we need to upgrade bind to get this option? Using this syntax: rate-limit { responses-per-second 5; window 5; }; Thanks John Manson US House of Representatives CAO/HI

Re: DNS Amplification Attacks... and a trivial proposal

2013-06-14 Thread John Levine
ore, and there are at least that many open resolvers (think random networked printers and such) so a factor of 4 in the amplification ratio isn't important. When Doug said they were switching to chargen, he wasn't kidding. There's an unlimited number of

Re: DNS Amplification Attacks... and a trivial proposal

2013-06-13 Thread John Levine
>So, may I infer that rather than being put off until the end of the >century, which seemed to be the previous implementation timeline, >pervasive implementation of BCP 38 may now be expected at around the >time that 32-bit UNIX clocks are anticipated to wrap-around to negative? Perhaps, but I thi

Re: DNS Amplification Attacks... and a trivial proposal

2013-06-13 Thread John Levine
>>The real solution is BCP 38... > >I agree completely John. I cannot do otherwise. But I have to ask the >obvious elephant-in-the-room question... How is that comming along so far? Based on discussions I've had with people who work at large networks and in policy

Re: DNS Amplification Attacks... and a trivial proposal

2013-06-13 Thread John Levine
. The real solution is BCP 38, to keep spoofed packets out of the network in the first place. With widely implemented BCP 38, open resolvers wouldn't matter since you could only DoS yourself, or at worst someone else on your own network segment. R's, John _

Re: Queries using forwarders

2013-06-03 Thread John Miller
ries. It's a pretty common anti-malware/anti-spam practice, and also gets used (for example) in wifi captive portals. John On 06/03/2013 03:36 PM, Ward, Mike S wrote: Hello all, I was trying to follow the thread on the NXDOMAIN and got lost. :) I have a question about using forwarders.

Re: Help on NXDOMAIN to try next forwarder in the list

2013-05-31 Thread John Wobus
A-record answers. It's up to the zone's maintainer to assure the (hopefully temporary) inconsistency doesn't cause issues. John Wobus Cornell Univ IT ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: 9.3.3 - SPF record checks

2013-05-30 Thread John Horne
On Fri, 2013-05-31 at 06:53 +1000, Mark Andrews wrote: > In message <1369923655.1952.6.camel@jhorne.config>, John Horne writes: > > Hello, > > > > I noticed in the 9.3.3 announcement the following new SPF check: > > > >Adds a new configuratio

9.3.3 - SPF record checks

2013-05-30 Thread John Horne
t=1 If it is being deprecated, then checking for an SPF record and finding no corresponding TXT record makes sense, but finding a TXT record and warning that there is no SPF record would seem a little pointless. John. -- John Horne, Plymouth University, UK Tel:

Re: Mailing list "reply-to" setting

2013-05-08 Thread John Levine
>> Any chance someone can correct the settings on this mailing list to >> reply to the list by default instead of the user posting the message? This is a religious argument. Please, leave it alone. >And, If I might add, adding a tag to the subject like [bind-users] would >be extremely nice. It'

resolver, search command....

2013-05-08 Thread John Williams
my resolv.conf looks  like nameserver 10.10.10.10 nameserver 10.10.10.20 search path1.mydomain.com path2.mydomain.com I would expect if I type the following: dig myhost It would search for that host in path1 or path2 listed above.  It does not, a +trace shows the resolver querying the root

Views Question

2013-04-30 Thread Manson, John
If the 'type' info in a zone statement determines master or slave, can you have 2 views in the same named.conf file, one with type master zones and the other with type slave zones? John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515

Re: This didn't work....

2013-04-29 Thread John Miller
from not delegating to dc1 as well, and not including glue for both of the dc2 IPs. Any reason not to delegate/glue dc1 as well? > Anyways...I guess at this point the problem lies with the ADS setup > > Definitely could be. But make sure your delegation is rock-solid first.

Re: This didn't work....

2013-04-26 Thread John Miller
nto this, it looks as though the department may have set their AD domain up as "foo.example.com" when in reality it should be "ads.foo.example.com." Can you clarify this? John ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Mirror Masters

2013-04-23 Thread Manson, John
all slaves so they get notifies from both. I'm guessing it has to do with being master for a zone and not acting on notifies it may receive. Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226

Solaris 11

2013-04-15 Thread Manson, John
I searched www.isc.org<http://www.isc.org> to no avail. Is bind 9.9.x compatible with Solaris 11? Anything out of the ordinary with compiling and such? Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 2

Re: Simple question about zone and CNAME

2013-04-05 Thread John Wobus
DNAME? Or SRV records. Surely browsers are adding support in the next day or two? John ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https

Recursion Issue

2013-03-28 Thread Manson, John
http://www.digwebinterface.com/? Is one of the internet sites I use. John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail.house.gov<mailto:john.man...@mail.house.

RE: Recursion issue

2013-03-28 Thread Manson, John
mailto:cli...@buxtonfamily.us] Sent: Thursday, March 28, 2013 12:57 PM To: Manson, John Cc: bind-users@lists.isc.org Subject: Re: Recursion issue On Mar 28, 2013, at 9:05 AM, Manson, John wrote: > I disagree with your statement about recursion. > What stops an authoritative server from doing recursi

RE: Recursion issue

2013-03-28 Thread Manson, John
, 2013 11:49 AM To: Manson, John Cc: bind-users@lists.isc.org Subject: Re: Recursion issue On Mar 28, 2013, at 8:27 AM, Manson, John wrote: > From the internet: > Answer records > > name class typedatatime to live > test.gopleader.govIN CNAME testwww.house.g

RE: Recursion issue

2013-03-28 Thread Manson, John
: test.gopleader@mercury.house.gov: test.gopleader.gov. 300 IN CNAME testwww.house.gov. -Original Message- From: Chris Buxton [mailto:cli...@buxtonfamily.us] Sent: Thursday, March 28, 2013 11:49 AM To: Manson, John Cc: bind-users@lists.isc.org Subject: Re: Recursion issue On Mar 28

RE: Recursion issue

2013-03-28 Thread Manson, John
:15:00) So the first lookup does not fully resolve due to recursion. Does this help? -Original Message- From: Chris Buxton [mailto:cli...@buxtonfamily.us] Sent: Thursday, March 28, 2013 11:13 AM To: Manson, John Cc: bind-users@lists.isc.org Subject: Re: Recursion issue On Mar 28, 2013,

Recursion issue

2013-03-28 Thread Manson, John
e the House server name displayed in the browser url bar and in dig results. Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail.house.gov<mailto:john.

FW: CVE-2013-2266 Question

2013-03-27 Thread Manson, John
Will dig and rndc be updated as well? Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail.house.gov<mailto:john.man...@mail.house.gov>

Hack Attempt?

2013-03-27 Thread Manson, John
se. Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail.house.gov<mailto:john.man...@mail.house.gov> ___ Please visit https://lists

Re: spf ent txt records.

2013-03-22 Thread John Levine
>It is or would have been, very little cost to publish SPF records. Not until we fix the provisioning problem. (News flash: in 99.9% of the Internet, people do not edit master files with vi.) In the early days of SPF, it was remarkably hard to get TXT records provisioned, even though TXT records

Re: spf ent txt records.

2013-03-22 Thread John Levine
>I've not been keeping up with the IETF; is there a document that >describes what looks like a de facto standard of using _pname labels >with TXT RRs that is being followed by at least DMARC and DANE in >*._tcp.example.com, *._smimecert.example.com, and _dmarc.example.com No, but Dave Crocker is w

Re: spf ent txt records.

2013-03-22 Thread John Wobus
for future efforts of the SPF-sort, and it's been fortunate for the SPF effort that TXT records were available to them without a lot of earlier-established complicated rules of use, so they could use TXT records to jump-start their efforts. John Wobus Cornell U ___

Re: 3rd party CNAMEs and open recursion

2013-03-04 Thread John Miller
n't ideal. Far better to separate things out. John Verne Verne Britton, Lead Systems Programmer voice: (304) 293-5192 x230 Systems Support Group(in WV, call 1-800-253-1558) West Virginia Net

Re: disabling lame server logging

2013-02-27 Thread Manson, John
Syslog-ng Use the named default logging. John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail.house.gov<mailto:john.man...@mail.house.

Re: Resolver behavior on expired TTLs

2013-02-21 Thread John Miller
Thanks, Matus. Much appreciated--a SERVFAIL is much better than an NXDOMAIN in this scenario. John On 02/21/2013 10:41 AM, Matus UHLAR - fantomas wrote: On 21.02.13 10:38, John Miller wrote: Here's something I hadn't put much thought into until recently--it's never been a

Resolver behavior on expired TTLs

2013-02-21 Thread John Miller
RVFAIL, but I could see NXDOMAIN as well. Does anyone know the answer? John ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Cannot create A record issue

2013-02-20 Thread John Miller
Just to cover all the bases, you're doing your lookup directly against your server, correct? Easy to accidentally query a different nameserver and not see what you're expecting. Otherwise I'd second Warren's suggestion to double-check your serial number. John On

Re: high volume from outside our networks question

2013-02-01 Thread John Wobus
ynamical updating and the views need to serve identical versions of the zone, then you need to arrange things so the zone is in just one view. The master of a zone with no dynamical updating could reference the same zone file from multiple views but that is about the only case that it would w

Transfers-out

2013-01-08 Thread Manson, John
Can this option be used in a 'slave' config to prevent out-bound transfers? Transfers-out 0; The 9.9.2 ARM is ambiguous. Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail

FW: Named stopped loging?

2012-12-28 Thread Manson, John
I would like to retract this post after I had a long conversation with my co-worker who is just back from leave. Sorry for the bother. From: Manson, John Sent: Friday, December 28, 2012 10:54 AM To: 'bind-users@lists.isc.org' Subject: Named stopped loging? Good Day Running 9.9.2 f

Named stopped loging?

2012-12-28 Thread Manson, John
2012. Named stopped and restarted @ Fri Dec 28 10:14:31 EST 2012. 9.9.2 bug or what? No named.conf or syslog-ng changes recently. Using the default named logging and syslog-ng as always. Thanks John Manson US House of Representatives CAO/HIR/NAF/Data-Communications Senior Network Communications

Re: Getting RPZ statistics

2012-12-08 Thread John Hascall
ption is to just send back a "403 Forbidden". One bit I think a little bit clever is I figured out how to make one file be legal html and legal javascript so if I'm not sure which it might be it doesn't matter. Now, if I could just encode a legal image in it too! :)

Re: Getting RPZ statistics

2012-12-07 Thread John Hascall
now their machine is probably infected with malware. John --- John Hascall, j...@iastate.edu Team Lead, NIADS (Network Infrastructure, Authentication & Directory Services) IT Services, The Iowa State University o

Re: DNS Blackholing

2012-12-04 Thread John Hascall
--- John Hascall, j...@iastate.edu Team Lead, NIADS (Network Infrastructure, Authentication & Directory Services) IT Services, The Iowa State University of Science and Technology > On 12/4/2012 6:00 AM, John

Re: DNS Blackholing

2012-12-03 Thread John Hascall
We have found that RPZ works quite well for us. We have 366825 names in our RPZ zone at present and scaling thus far has been a non-issue. John --- John Hascall, j...@iastate.edu Team Lead, NIADS (Network Infrastructure

TCP retransmission counters for

2012-11-30 Thread Manson, John
XFR-style IXFR ended John Manson US House of Representatives CAO/HIR/NAF/Data-Communications Senior Network Communications Specialist Desk: 202-226-4244 TCC: 202-226-6430 ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe

Re: Change in statistics format

2012-11-15 Thread John Miller
Thanks, Evan. That's exactly what I wanted to know. I'm already running the statistics server, so I'd certainly prefer to leverage that rather than rely on a bunch of regexes to parse the statistics file. I'll let the folks at Hyperic know about the upcoming schema chan

Re: Change in statistics format

2012-11-15 Thread John Miller
Thank you! Just downloaded a copy, and looks pretty straightforward. John On 11/15/2012 12:13 PM, Jan-Piet Mens wrote: Thanks, Phil. Those were my thoughts as well. For the present, I'll write my own monitoring plugin to parse the XML data. If you need some inspiration, I wrote a bit

Re: Change in statistics format

2012-11-15 Thread John Miller
Thanks, Carsten, I've opened bug #4619 and indeed asked Hyperic to parse the XML output. I agree, it's much nicer than trying to parse the rndc.stats file! If anyone here has already written a BIND plugin for Hyperic, let me know--I'd love to have a copy and see if it'll

Re: Change in statistics format

2012-11-15 Thread John Miller
Thanks, Phil. Those were my thoughts as well. For the present, I'll write my own monitoring plugin to parse the XML data. John On 11/15/2012 11:47 AM, Phil Mayers wrote: On 15/11/12 16:44, John Miller wrote: Hello everyone, When did BIND 9 switch over from the older I think tha

Change in statistics format

2012-11-15 Thread John Miller
ormat, and wanted to be sure I had my ducks in a row. -- John Miller Systems Engineer Brandeis University johnm...@brandeis.edu ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list

Bind 9.9.2 ADB Question Update

2012-11-15 Thread Manson, John
arting Nov 14 15:46:41 local@mercury named[2920]: [ID 873579 daemon.info] adb: grow_names finished Nov 14 16:01:11 local@mercury named[2920]: [ID 873579 daemon.info] adb: grow_names to 8191 starting Nov 14 16:01:12 local@mercury named[2920]: [ID 873579 daemon.info] adb: grow_names finished J

Bind 9.9.2 ADB Question

2012-11-14 Thread Manson, John
is dynamic cache-memory allocation as it increases and decreases as needed. Is there are ARM entry that explains this? Thanks John Manson CAO/HIR/NAF Data-Communications | U.S. House of Representatives | Washington, DC 20515 Desk: 202-226-4244 | TCC: 202-226-6430 | john.man...@mail.house.gov

<    1   2   3   4   5   6   7   8   9   >