Re: [Pdns-users] Different RRSIG's on master and slaves

2013-09-25 Thread mvdgeijn
I've compared the master and first slave DNS server, and I noticed a few differences. The first difference is the configuration on line 2. The master: 1 0 1 ab and the slave: 1 1 1 ab. What does the second number stand for? I can't find it in the documentation. Is this causing the difference betwee

Re: [Pdns-users] Different RRSIG's on master and slaves

2013-09-25 Thread mvdgeijn
I did some other tests, and the fix for this problem seems to be to delete the records for the domain in the cryptokeys table on the slave servers, and after that update the serial. Is there a way to force this using the pdnssec or pdns_control tools from the master server? Regards, Marc -- Vi

[Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread Fredrik Roubert
Hello! My ISP is running a slave DNS service, using PowerDNS 3.0 as this is the version included in Ubuntu 12.04 LTS. I've already read this post, about DNSSEC in 3.0 being "explicitly deprecated": http://mailman.powerdns.com/pipermail/pdns-users/2012-July/009099.html But seeing that my ISP's po

Re: [Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread bert hubert
On Wed, Sep 25, 2013 at 10:49:39AM +0200, Fredrik Roubert wrote: > But what does it mean? What exactly is it in my configuration that makes > PowerDNS 3.0 unable to handle it? Is it something I could change to make > PowerDNS 3.0 play along as a slave server? No, sorry. And in general, if you are

Re: [Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread Peter van Dijk
Hello Frederik, On Sep 25, 2013, at 10:49 , Fredrik Roubert wrote: > My ISP is running a slave DNS service, using PowerDNS 3.0 as this is the > version included in Ubuntu 12.04 LTS. I've already read this post, about > DNSSEC in 3.0 being "explicitly deprecated": > > http://mailman.powerdn

Re: [Pdns-users] Different RRSIG's on master and slaves

2013-09-25 Thread Klaus Darilion
I wonder why there are cryptokeys in the slave at all. What kind of setup do you use? Online-signing on the master and pre-signed on the slaves? klaus On 25.09.2013 09:53, mvdgeijn wrote: I did some other tests, and the fix for this problem seems to be to delete the records for the domain in t

Re: [Pdns-users] Different RRSIG's on master and slaves

2013-09-25 Thread mvdgeijn
On both the master and slave servers "pdnssec show-zone" shows that the zone is not pre-signed. Regards, Marc -- View this message in context: http://powerdns.13854.n7.nabble.com/Different-RRSIG-s-on-master-and-slaves-tp10349p10362.html Sent from the PowerDNS mailing list archive at Nabble.com

Re: [Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread Christof Meerwald
On Wed, 25 Sep 2013 10:49:39 +0200, Fredrik Roubert wrote: > My ISP is running a slave DNS service, using PowerDNS 3.0 as this is the > version included in Ubuntu 12.04 LTS. I've already read this post, about > DNSSEC in 3.0 being "explicitly deprecated": > > http://mailman.powerdns.com/piper

Re: [Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread Michael Ströder
Fredrik Roubert wrote: > My ISP is running a slave DNS service, using PowerDNS 3.0 as this is the > version included in Ubuntu 12.04 LTS. I've already read this post, about > DNSSEC in 3.0 being "explicitly deprecated": > > http://mailman.powerdns.com/pipermail/pdns-users/2012-July/009099.ht

Re: [Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread Fredrik Roubert
On Wed 25 Sep 11:00 CEST 2013, Peter van Dijk wrote: > If that's not it, check your zone file for any lines containing TYPE in > uppercase, or any entry over 255 in > http://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml#dns-parameters-4 Ah, thank you, this is interesting. My zone f

Re: [Pdns-users] PowerDNS 3.0: Can't deal with multi-part NSEC mappings yet

2013-09-25 Thread Peter van Dijk
Hello Fredrik, On Sep 26, 2013, at 2:46 , Fredrik Roubert wrote: > On Wed 25 Sep 11:00 CEST 2013, Peter van Dijk wrote: > >> If that's not it, check your zone file for any lines containing TYPE in >> uppercase, or any entry over 255 in >> http://www.iana.org/assignments/dns-parameters/dns-parame