Re: [Pdns-users] Reset Data on Slave

2024-01-09 Thread Klaus Darilion via Pdns-users
Hi Sebastian! The term "cached data" usually does not refer to the data in the database, but to data cached in the PDNS process (packet cache, query cache). If you want to clean the "cache" the fastest method is to restart the PDNS process (a short service interruption). To adjust caching

Re: [Pdns-users] Adding multiple records to all zones at once

2023-10-13 Thread Klaus Darilion via Pdns-users
> Why not do something along the lines of (PostgreSQL syntax as that's > what I know, and completely untested): > > INSERT INTO records (domain_id, name, type, content, ttl) >SELECT domain.id, 'autoconfig.' || domains.name, 'CNAME, ' zone>, 3600 >FROM domains >JOIN records ON

Re: [Pdns-users] Problem with master and slave config

2023-10-12 Thread Klaus Darilion via Pdns-users
I have never used pdnsutil. Maybe the domain is created with type NATIVE instead of MASTER. Check the 'domains' table. Klaus Gesendet über BlackBerry Work (www.blackberry.com) Von: Pdns-users im Namen von Andres Alejandro Dobie via Pdns-users Gesendet:

Re: [Pdns-users] Return answer according to availability of a server

2023-09-27 Thread Klaus Darilion via Pdns-users
You can do this in PowerDNS Authoritative using LUA records, see: https://doc.powerdns.com/authoritative/lua-records/ regards Klaus > -Ursprüngliche Nachricht- > Von: Pdns-users Im > Auftrag von Riccardo Brunetti via Pdns-users > Gesendet: Dienstag, 26. September 2023 18:43 > An:

Re: [Pdns-users] listen on net iface

2023-07-28 Thread Klaus Darilion via Pdns-users
tiple PDNS processes writing into a single DB you can configure your HA manager to start PDNS only once the floating IP is migrated to the standby server. regards Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria > -Ursprüngli

Re: [Pdns-users] listen on net iface

2023-07-28 Thread Klaus Darilion via Pdns-users
Configure pdns to listen to the floating IP and set net.ipv4.ip_nonlocal_bind. Klaus Gesendet über BlackBerry Work (www.blackberry.com) Von: Pdns-users im Namen von lejeczek via Pdns-users Gesendet: 28.07.2023 06:05 An: pdns-users@mailman.powerdns.com Cc:

Re: [Pdns-users] IXFR Stability Feedback

2023-04-21 Thread Klaus Darilion via Pdns-users
> -Ursprüngliche Nachricht- > Von: William Edwards > Gesendet: Samstag, 15. April 2023 23:51 > An: Peter Thomassen > Cc: Klaus Darilion ; pdns- > us...@mailman.powerdns.com > Betreff: Re: [Pdns-users] IXFR Stability Feedback > > > > Op 15 apr. 2023 o

[Pdns-users] IXFR Stability Feedback

2023-04-15 Thread Klaus Darilion via Pdns-users
Hi! We have a customer zone with ~1.1 mio RRs (~200K NSEC3 RRs) with zone updates every few minutes. We use the Postgresql backend and replicate the zone to the secondaries using logical replication. It is not very smart pushing out 5GB of (almost same) data every few minutes, and it is

[Pdns-users] PowerDNS DB Backend with presigned Master Zones via API

2023-04-07 Thread Klaus Darilion via Pdns-users
it manually? Thanks Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] master receiving notifies from slave

2023-03-08 Thread Klaus Darilion via Pdns-users
PDNS sends only NOTIFYs for SLAVE zones is slave-renotify is turned on (globally, or per zone in domainmetadata table). So, if your SLAVEs shoudl not send NOTIFYs make sure to disable slave-renotify. If a PDNS instance slaves zones from a master, but also acts as master to other slaves, then

Re: [Pdns-users] ENUM NAPTR queries

2023-02-14 Thread Klaus Darilion via Pdns-users
. regards Klaus > -Ursprüngliche Nachricht- > Von: Alexis Fidalgo > Gesendet: Montag, 13. Februar 2023 16:02 > An: Klaus Darilion > Cc: pdns-users@mailman.powerdns.com > Betreff: Re: [Pdns-users] ENUM NAPTR queries > > No worries, I’m working now in a combination

Re: [Pdns-users] ENUM NAPTR queries

2023-02-13 Thread Klaus Darilion via Pdns-users
Probably things are different when using a dynamic backend vs. a DB backend. Unfortunately I am not familiar with the remote backend. regards Klaus > -Ursprüngliche Nachricht- > Von: Alexis Fidalgo > Gesendet: Montag, 13. Februar 2023 15:20 > An: Klaus Darilion >

Re: [Pdns-users] ENUM NAPTR queries

2023-02-13 Thread Klaus Darilion via Pdns-users
disabled the zone-cache, using an old PowerDNs version, or this feature is not supported with MongoDB. regards Klaus -- Klaus Darilion, Head of Operations nic.at GmbH, Jakob-Haringer-Straße 8/V 5020 Salzburg, Austria > -Ursprüngliche Nachricht- > Von: Pdns-users Im Auftrag von &g

[Pdns-users] Help needed debugging knot_control timeouts

2022-12-12 Thread Klaus Darilion via Pdns-users
Hello! We regularly use "pdns_control retrieve" (via TCP) to trigger zone transfers. Very often we receive: Timeout error: Error from remote in receive(): Resource temporarily unavailable Our PDNS is quite busy, plenty of NOTIFYs, SLAVE checks and incoming AXFRs. What exactly happens when

Re: [Pdns-users] INCEPTION-INCREMENT for a signed zone

2022-08-31 Thread Klaus Darilion via Pdns-users
Hi Tomas! I can not speak about INCEPTION-INCREMENT. But I remember when we had to decide which increment-method to choose we have chosen INCREMENT-WEEKS because it is the only method that works always - regardless of the serial format chosen by the zone editor. With INCREMENT-WEEKS the

Re: [Pdns-users] [dnsdist] Dnsdist not reading from the cache

2022-07-22 Thread Klaus Darilion via Pdns-users
In old dnsdist versions the chache was per "cookie". So make sure to test with DNS cookies. regards Klaus Von: dnsdist Im Auftrag von Jacob Bunk Nielsen via dnsdist Gesendet: Freitag, 22. Juli 2022 12:28 An: dnsd...@mailman.powerdns.com Betreff: Re: [dnsdist] Dnsdist not reading from the cache

Re: [Pdns-users] PowerDNS Authoritative 4.6.2, how to log served responses (i.e. NOERROR, NXDOMAIN, SERVFAIL, etc)?

2022-06-14 Thread Klaus Darilion via Pdns-users
Hi Dmitriy! Recently we had a similar requirement for our resolvers (which only do query logging, not response logging) and we decided to use packetbeat for this purpose. IT should be easy to integrate if you have an existing Elasic Search cluster! regards Klaus Von: Pdns-users Im Auftrag

Re: [Pdns-users] Question about DNSSEC + ALIAS (cname at the apex hack)

2022-05-31 Thread Klaus Darilion via Pdns-users
https://github.com/PowerDNS/pdns/issues/10150 Von: Pdns-users Im Auftrag von Klaus Darilion via Pdns-users Gesendet: Dienstag, 31. Mai 2022 06:35 An: j...@elsif.net; pdns-users@mailman.powerdns.com Betreff: Re: [Pdns-users] Question about DNSSEC + ALIAS (cname at the apex hack) Alias does

Re: [Pdns-users] Question about DNSSEC + ALIAS (cname at the apex hack)

2022-05-30 Thread Klaus Darilion via Pdns-users
Alias does not support dnssec. See issues on github. Klaus­ Gesendet über BlackBerry Work (www.blackberry.com) Von: Pdns-users im Namen von Jake via Pdns-users Gesendet: 30.05.2022 22:10 An: pdns-users@mailman.powerdns.com Betreff: [Pdns-users] Question about

Re: [Pdns-users] Questions about PowerDNS - CNAME@APEX, Capacity, management, etc...

2022-05-06 Thread Klaus Darilion via Pdns-users
Hi Jake! This answers are probably worth some for consulting. Anyways... > -Ursprüngliche Nachricht- > Von: Pdns-users Im ... > Does PowerDNS load all of the zones into memory, and then start serving > (like BIND), or does it load each zone and start serving said zone > immediately

Re: [Pdns-users] DNSSEC and CNAME records results NXDOMAIN

2022-04-22 Thread Klaus Darilion via Pdns-users
ove the root zone from your POwerDNS. regards Klaus > -Ursprüngliche Nachricht- > Von: Marijn > Gesendet: Freitag, 22. April 2022 19:18 > An: Klaus Darilion ; pdns- > us...@mailman.powerdns.com > Betreff: Re: [Pdns-users] DNSSEC and CNAME records results NXDOMAIN >

Re: [Pdns-users] DNSSEC and CNAME records results NXDOMAIN

2022-04-22 Thread Klaus Darilion via Pdns-users
ns1.mijn.host hostmaster.@ 0 10800 3600 604800 3600 > > Klaus Darilion schreef op 2022-04-22 18:06: > > I do not see any difference of the two cases. But in any case, > > returning an answer AND nxdomain is just broken. > > > > > > # dig @ns1.mijn.host. autodisco

Re: [Pdns-users] DNSSEC and CNAME records results NXDOMAIN

2022-04-22 Thread Klaus Darilion via Pdns-users
I do not see any difference of the two cases. But in any case, returning an answer AND nxdomain is just broken. # dig @ns1.mijn.host. autodiscover.egogo.eu ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 62514 ... ;; QUESTION SECTION: ;autodiscover.egogo.eu. IN A ;; ANSWER

[Pdns-users] How do I build Debian/Ubuntu packages?

2022-04-05 Thread Klaus Darilion via Pdns-users
Hi! Last time I build PDNS myself was 4.0. I just wanted to build packages for master, but found out that the build-auth-debian script has gone. What is the new way to build Debian packages? Thanks Klaus ___ Pdns-users mailing list

Re: [Pdns-users] RRSIG validity period

2022-03-30 Thread Klaus Darilion via Pdns-users
PowerDNS signature validity is always 3 weeks. Start is the second last Thursday 00:00 UTC, end is the next but one Thursday 00:00. Start End Thursday Thursday Today Thursday

Re: [Pdns-users] Negative cache upon zone creation

2022-02-24 Thread Klaus Darilion via Pdns-users
IIRC you are right. But there were several updatest o the zone cache after release. If you use 4.5 make sure to use latest 4.5.x version. regards Klaus -Ursprüngliche Nachricht- Von: Lucas Rolff Gesendet: Donnerstag, 24. Februar 2022 16:58 An: Klaus Darilion Cc: Andrea Biscuola ; Pdns

Re: [Pdns-users] Negative cache upon zone creation

2022-02-24 Thread Klaus Darilion via Pdns-users
Have you really disabled all caches? Also https://doc.powerdns.com/authoritative/settings.html#zone-cache-refresh-interval ? regards Klaus -Ursprüngliche Nachricht- Von: Pdns-users Im Auftrag von Andrea Biscuola via Pdns-users Gesendet: Donnerstag, 24. Februar 2022 15:12 An:

Re: [Pdns-users] powerdns frequently crashes and restarts

2022-02-18 Thread Klaus Darilion via Pdns-users
Von: Pdns-users Im Auftrag von Klaus Darilion via Pdns-users Gesendet: Freitag, 18. Februar 2022 09:58 An: Riccardo Brunetti ; Pdns-users@mailman.powerdns.com Betreff: Re: [Pdns-users] powerdns frequently crashes and restarts Look in the mysql-server log. Maybe it mentions which other transact

Re: [Pdns-users] powerdns frequently crashes and restarts

2022-02-18 Thread Klaus Darilion via Pdns-users
Look in the mysql-server log. Maybe it mentions which other transaction causes the deadlock. That my help to find the cause. Is this problem something new? I.e. started it after a PDNs or Mysql Upgrade? regards Klaus Von: Pdns-users Im Auftrag von Riccardo Brunetti via Pdns-users Gesendet:

Re: [Pdns-users] TSIG-Keys for TSIG-ALLOW-AXFR

2022-02-16 Thread Klaus Darilion via Pdns-users
No. This is a known issue. https://doc.powerdns.com/authoritative/settings.html#send-signed-notify regards Klaus Von: Pdns-users Im Auftrag von Stefan Becker via Pdns-users Gesendet: Dienstag, 15. Februar 2022 14:36 An: pdns-users@mailman.powerdns.com Betreff: [Pdns-users] TSIG-Keys for

Re: [Pdns-users] Serial increase not reflecte in database

2022-01-20 Thread Klaus Darilion via Pdns-users
> This would normally be fine, but the change seems to occur only in the > service itself and is not reflected in the SOA record stored in the > database. SOA-Edit does not influence/manipulate the serial in the DB. SOA-EDIT is used to fake the Serial (on outgoing NOTIFYs and responses which

[Pdns-users] How to stop automatic respawning

2021-10-06 Thread Klaus Darilion via Pdns-users
Hi! During random subdomain attacks we often hit the max-queue-length: pdns_server-customer1[51284]: 5001 questions waiting for database/backend attention. Limit is 5000, respawning This happens constantly (+50K q/s). Of course we try to filter with dnsdist/iptables/... but until our detection

Re: [Pdns-users] DNSSEC Algorithm Rollover Documentation

2021-05-04 Thread Klaus Darilion via Pdns-users
Hi Daniel! > -Ursprüngliche Nachricht- > Von: Daniel Stirnimann > Gesendet: Montag, 3. Mai 2021 11:27 > An: Klaus Darilion ; Pdns- > us...@mailman.powerdns.com > Betreff: Re: [Pdns-users] DNSSEC Algorithm Rollover Documentation > > Hello Klaus, > > The DNS

Re: [Pdns-users] DNSSEC Algorithm Rollover Documentation

2021-05-04 Thread Klaus Darilion via Pdns-users
Hi Daniel! Thanks for the info. > -Ursprüngliche Nachricht- > Von: Daniel Stirnimann > Gesendet: Montag, 3. Mai 2021 11:27 > An: Klaus Darilion ; Pdns- > us...@mailman.powerdns.com > Betreff: Re: [Pdns-users] DNSSEC Algorithm Rollover Documentation > > Hell

[Pdns-users] Does the Bind Backend support journaling/IXFR?

2021-05-04 Thread Klaus Darilion via Pdns-users
Hi all! Does the Bind backend support journaling and incoming/outgoing IXFR (as similar to Bind)? Thanks Klaus ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] DNSSEC Algorithm Rollover Documentation

2021-05-03 Thread Klaus Darilion via Pdns-users
Hi all! Is there somewhere documentation for an algorithm rollover? The cryptokeys table recently received the "published" column to "Implement published and unpublished dnskeys to allow algorith rollovers.":

Re: [Pdns-users] retaining cache

2020-05-27 Thread Klaus Darilion via Pdns-users
So you want probably Bind's stale-answer-enable=yes? Klaus Gesendet über BlackBerry Work (www.blackberry.com) Von: Mike via Pdns-users Gesendet: 27.05.2020 22:33 An: pdns-users@mailman.powerdns.com Betreff: [Pdns-users] retaining cache Hi, I already know

Re: [Pdns-users] PowerDNS Authoritative 4.3.0

2020-04-09 Thread Klaus Darilion via Pdns-users
> A notable new feature in 4.3 is support for hiding DNSSEC keys, which makes > it possible to do algorithm rollovers. This feature was contributed by Robin > Geuze of TransIP, thanks! Can someone please provide link to a bug report/pull request/ir similar? I want to understand why algorithm

Re: [Pdns-users] PowerDNS Authoritative 4.2.2 Released

2020-04-09 Thread Klaus Darilion via Pdns-users
> -Ursprüngliche Nachricht- > Von: Pdns-users Im Auftrag > von Erik Winkels via Pdns-users > Gesendet: Donnerstag, 9. April 2020 12:45 > An: pdns-annou...@mailman.powerdns.com; pdns- > d...@mailman.powerdns.com; pdns-users@mailman.powerdns.com > Betreff: [Pdns-users] PowerDNS

Re: [Pdns-users] Clarification on which TSIG key signs notifications

2020-04-01 Thread Klaus Darilion via Pdns-users
There is an issue on github about this. You are correct, pdns just uses the first tsig key returned by the backend. The workaround was a config option to disable signed notifications. Klaus Gesendet über BlackBerry Work (www.blackberry.com) Von: Matthew Monaco

Re: [Pdns-users] Hidden Master, Dynamic IPv4, IPv6 Privacy

2020-03-27 Thread Klaus Darilion via Pdns-users
DNS Master/Slave was not designed for dynamic IP addresses. As a workaround you could use some overlay whoch provides a static IP (OpenVPN, stunnel, ssh tunnels, ...) Regards Klaus Gesendet über BlackBerry Work (www.blackberry.com) Von: Matthew Monaco via

Re: [Pdns-users] Hhow to safely import a DNSSEC signed zone

2020-02-22 Thread Klaus Darilion via Pdns-users
tweak the domainmetadata, ie. for serial bumping. Also make sure that there are no zone changes while doing above process. regards Klaus Am 13.02.2020 um 12:59 schrieb Klaus Darilion via Pdns-users: Hello! I have thousands of DNSSEC presigned-signed zones which I slave with PowerDNS (type

[Pdns-users] Hhow to safely import a DNSSEC signed zone

2020-02-13 Thread Klaus Darilion via Pdns-users
Hello! I have thousands of DNSSEC presigned-signed zones which I slave with PowerDNS (type='SLAVE'). I want to move all these zones to PowerDNS as type='MASTER'. Basically this should be very simple: For each zone: BEGIN; UPDATE domains SET type='MASTER' where id=XXX; INSERT INTO cryptokeys

Re: [Pdns-users] How can I prevent that SOA and ANY queries are passed to a backend if NAPTR was requested?

2020-01-15 Thread Klaus Darilion
Am 15.01.2020 um 19:21 schrieb Matthias Kruzenski: Hello, I want to use PowerDNS to answer NAPTR queries through the pipe backend. This works, but PowerDNS does not pass a NAPTR request to the backend, but always a SOA request and then an ANY request. I only want to pass what was explicitly

Re: [Pdns-users] PowerDNS Authoritative Server 4.2.1

2019-12-13 Thread Klaus Darilion
Am 02.12.2019 um 15:58 schrieb Erik Winkels via Pdns-users: Please send us all feedback and issues you might have via the mailing list[4], or in case of a bug, via GitHub[5]. From [1] https://doc.powerdns.com/authoritative/changelog/4.2.html#change-4.2.1 Improvements Register a few known

[Pdns-users] domainmetadata caching question

2019-12-06 Thread Klaus Darilion
Hi all! I just recently found the "domain-metadata-cache-ttl" option. Reviewing the code it seems that this cache is only used for DNSSEC related data during handling of incoming queries. Is this correct? (it should be added to the docs). Further I wonder if it may be useful to change the

Re: [Pdns-users] Log all zone changes

2019-10-02 Thread Klaus Darilion
Am 27.09.2019 um 20:30 schrieb Vitali Quiering via Pdns-users: Hello, I just started using PowerDNS Authoritative Server recently and got to the point where I need all changes logged. Is there an option I missed? If there is none: How do you log your changes? We have a web interface which

Re: [Pdns-users] How should my backend tell pdns that pdns_server that it has changed the zone

2019-09-25 Thread Klaus Darilion
Am 24.09.2019 um 17:00 schrieb jb-wisemo via Pdns-users: On 24/09/2019 14:25, Pieter Lexis wrote: Hi Jakob, On 9/24/19 12:31 AM, jb-wisemo via Pdns-users wrote: I am creating a custom master-mode backend for a special use. But some questions are left open or vague by the documentation, here

Re: [Pdns-users] Race condition during AXFR while updating slaves with two supermasters in high availability

2019-09-25 Thread Klaus Darilion
Am 18.09.2019 um 13:55 schrieb Pieter Lexis: On 9/18/19 1:55 PM, Pieter Lexis wrote: This is a bug, there is a PR to fix this[1], but this PR has to be un-conflicted and re-reviewed. I have the patch rebased for 4.1, but not yet for 4.2. BUt in this case, it would even be better to not check

Re: [Pdns-users] PowerDNS authoritative server random timeouts

2019-09-25 Thread Klaus Darilion
I think, first you should find out if there is a problem with PowerDNS or the network - or inbetween. If this happens regularly, just use tcpdump to caputre all DNS traffic to a file (rotate files, keep only X files and choose X to not fill your complete hard disk). Or even simpler - just

[Pdns-users] SOA-EDIT questions

2019-09-04 Thread Klaus Darilion
Hi! I wonder how the SOA-EDIT feature (to keep signatures fresh on slaves) works in detail: - Will the master also send NOTIFYs with increased serials to keep the slave fresh, or does it rely that the refresh value is small and the slave checks for newer serials on the master? - SOA-EDIT

Re: [Pdns-users] Rate-Limit for NXDOMAIN

2019-05-04 Thread Klaus Darilion
Hi Bart! Am 30.04.2019 um 16:31 schrieb power...@bart.bim.be: In the normal case, suppressing responses may be a good thing to do, if the actual problem is that the DNS responses are part of a DoS attack (i.e. the DNS queries came in with spoofed source addresses). The responses cause your

Re: [Pdns-users] Rate-Limit for NXDOMAIN

2019-05-04 Thread Klaus Darilion
Hi Brian! Am 30.04.2019 um 15:37 schrieb Brian Candler: On 29/04/2019 22:14, Klaus Darilion wrote: Can you give an example how those dynblockrules can be used to filter above "attack"? The main problem with rate-limiting NXDOMAIN is, that you need to ask the authoritative to get

Re: [Pdns-users] Rate-Limit for NXDOMAIN

2019-04-29 Thread Klaus Darilion
Hi Nico! Am 26.04.2019 um 15:05 schrieb Nico CARTRON: Hi Markus, On 26-Apr-2019 14:55 CEST, wrote: Hello together, since recently we use two powerDNS Authoritative Servers (v.4.1.8) for managing our own domains. Is it possible, to rate-limit dns lookups for non-existing Domains?

[Pdns-users] Presigned Zones: does PDNS support all possible algorithms?

2019-03-21 Thread Klaus Darilion
Hi! If a zone is presigned, and PowerDNS is a slave (AXFR), will PowerDNS support all DNSSEC algorithms, or is there some limitiations that only allows the native supported algorithms [1]. Thanks Klaus [1] https://doc.powerdns.com/authoritative/dnssec/profile.html

Re: [Pdns-users] zone file verification

2019-01-31 Thread Klaus Darilion
I recommend other tools, eg: ldns-verify-zone and named-checkzone, named-compilezone PowerDNS is not very strict. It happens quite easily that a zone loaded and served by PowerDNS can not tranfered by a Bind slave. Hence, I recommend the tools from Bind to verify a zone. regards Klaus Am

Re: [Pdns-users] Multiple masters

2019-01-22 Thread Klaus Darilion
The answer is quite simple - multi master support in PDNS is only available in the docs ;-) https://github.com/PowerDNS/pdns/pull/5595 regards Klaus Am 15.12.2018 um 07:29 schrieb Don Stokes: Hi all, I'm looking to deploy PowerDNS in a slave configuration that has multiple (BIND) masters.

Re: [Pdns-users] Disabling DNSUPDATE for *some* zones?

2019-01-22 Thread Klaus Darilion
Sounds like allow-unsigned-update, similar to https://doc.powerdns.com/authoritative/settings.html#allow-unsigned-notify would be needed Klaus Am 02.01.2019 um 02:15 schrieb Kevin P. Fleming: I've got PowerDNS Auth happily running and serving a number of domains (primary and two

Re: [Pdns-users] PowerDNS Authoritative Server 4.0.6 & 4.1.5 and Recursor 4.0.9 & 4.1.5 Released

2018-11-09 Thread Klaus Darilion
> - Apply alias scopemask after chasing Can you please describe what the scopemask is about? The patch and also the issue does not contain any documentation. Thanks Klaus ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com

Re: [Pdns-users] SQL backends columns roles

2018-10-06 Thread Klaus Darilion
Am 04.10.2018 um 16:06 schrieb Rodrigo Severo - Fábrica: Hi, I'm trying to understand the role fulfilled by each column in the SQL backends. I have already read this page: https://doc.powerdns.com/authoritative/backends/generic-sql.html#queries but can't find any info on the "ordername"

Re: [Pdns-users] Performance issues

2018-07-30 Thread Klaus Darilion
Am 24.07.2018 um 13:54 schrieb Martijn Reening: > Hello everyone, > > We are seeing very vague issues with our PowerDNS setup where certain > sequences of requests can cause full queues and dropped queries. Under > normal circumstances, the server can handle more than 10 kqueries/sec, > but

Re: [Pdns-users] NOTIFYing with ALIAS records

2018-07-18 Thread Klaus Darilion
Am 10.07.2018 um 08:04 schrieb Scott Colby: - a script running on ns1 that checks if the ALIAS has changed and forces a NOTIFY to be sent (is this possible via the PowerDNS API?) Sending a NOTIFY is not sufficient. You also have to increase the serial before sending NOTIFY to make sure

Re: [Pdns-users] Notify message are not being sent, allow-axfr must be set at domain level for axfer to work for servers 2-6

2018-07-03 Thread Klaus Darilion
Which backend do you use? If sql, have you set the type in the domains table to "MASTER"? regards Klaus Am 27.06.2018 um 17:49 schrieb Walter Parker: > I have my system setup as follows: > > master=yes > allow-axfr-ips=216.128.133.2 208.94.147.124 208.94.147.125 208.94.147.135 > 208.94.150.198

Re: [Pdns-users] PDNS Auth Zone Distribution in a Global Network?

2018-07-02 Thread Klaus Darilion
Am 29.06.2018 um 23:23 schrieb Anthony Eden: Hello everyone, I am considering moving some or all of DNSimple's authoritative DNS service back over to PowerDNS within the next 6 months, but before I do so, I'm hoping to get in touch with one or more folks from the PowerDNS community who

Re: [Pdns-users] Native setups and AXFR for external providers

2018-07-02 Thread Klaus Darilion
Am 21.06.2018 um 16:29 schrieb Eric Raymond: We have two servers that manage our external zones, ServerA is set to Native using gmysql backend and sits in an internal network, and replicates to ServerB in our DMZ.  We also would like to have a AXFR sent to notify our external DNS provider,

Re: [Pdns-users] serveral ALIAS questions

2018-06-11 Thread Klaus Darilion
Am 11.06.2018 um 12:53 schrieb Klaus Darilion: > Hi! > > We soon put ALIAS into production. Hence, I have some questions to > better understand what's going on internally in PDNS. > > a) What happens if the backend query (from PDNS-auth to resolver) is > unanswer

[Pdns-users] serveral ALIAS questions

2018-06-11 Thread Klaus Darilion
Hi! We soon put ALIAS into production. Hence, I have some questions to better understand what's going on internally in PDNS. a) What happens if the backend query (from PDNS-auth to resolver) is unanswered? Will PDNS timeout the outstanding query or will it be kept on the list for ever? If it

Re: [Pdns-users] Authoritative server 4.1.2 released

2018-05-09 Thread Klaus Darilion
Am 08.05.2018 um 14:02 schrieb Peter van Dijk: * add tcp support for alias I have a question - the respective pull request mentions "resolve via stub resolver". Does this mean it uses the name servers configured in /etc/resolv.conf, or does it also use the resolver=... setting? Thanks Klaus

Re: [Pdns-users] Dynamic mangling and forward of DNS queries

2018-04-06 Thread Klaus Darilion
Am 15.03.2018 um 12:44 schrieb Marco Pizzoli: > - create a zone for every specific DNS entry I am "mangling": I understand > ALIAS works only for zone apex entries... No, it works for all lables. regards Klaus ___ Pdns-users mailing list

Re: [Pdns-users] Dynamic mangling and forward of DNS queries

2018-03-15 Thread Klaus Darilion
What about the "ALIAS" record in PowerDNS? Then the authoritative PDNS will use the configured resolver, which may be able to resolve the second domain. regards Klaus Am 26.02.2018 um 18:41 schrieb Marco Pizzoli: > Hi Aleksandr, > thanks for the prompt answer, but unfortunately no... > The

Re: [Pdns-users] [External] Re: Notification for domains to ip1:53 failed after retries

2018-01-17 Thread Klaus Darilion
Am 17.01.2018 um 11:31 schrieb Steve Zeng: > I came across this post and was concerned if the high number of NOTIFY/AXFR > overloaded PowerDNS, given that we have ~6,000 zones and ~100 BIND slaves. Do > you know if there is a built-in limit on the AXFR volume? Probably not the number of

Re: [Pdns-users] [External] Notification for domains to ip1:53 failed after retries

2018-01-17 Thread Klaus Darilion
nfigured master to > check the serial? Is it immediately right after it get NOTIFY from master? > > Thanks, > Steve >> On Jan 17, 2018, at 3:32 PM, Klaus Darilion <klaus.mailingli...@pernau.at> >> wrote: >> >> >> >> Am 17.01.2018 um 15:13 schri

Re: [Pdns-users] Notification for domains to ip1:53 failed after retries

2018-01-17 Thread Klaus Darilion
Am 17.01.2018 um 15:13 schrieb Steve Zeng: > Pieter, > > I checked BIND slaves logs around the time frame and found: > > 10-Jan-2018 18:11:17.211 notify: client 10.198.180.41#12149: received notify > for zone 'example.com' > 10-Jan-2018 18:11:17.211 general: zone lhr4.dqs.booking.com/IN:

Re: [Pdns-users] Meltdown impact on PowerDNS/dnsdist

2018-01-07 Thread Klaus Darilion
Am 06.01.2018 um 17:18 schrieb Michael Ströder: > bert hubert wrote: >> We have done some very tentative measurements on the Linux Meltdown >> workaround & impact on DNS performance. > > Besides the performance impact of the "fixes" doesn't this mean that > people should stop doing DNSSEC

[Pdns-users] PowerDNS Auth is slow on control socket

2018-01-05 Thread Klaus Darilion
Hi! We use the PowerDNS Auth control socket with TCP from another host extensivly to trigger "retrieve" requests. Several times a day we get the follwing error: # pdns_control --remote-address=... --remote-port=... --secret=... retrieve example.com Timeout error: Error from remote in receive():

Re: [Pdns-users] Intended use of multiple backends simultaneously.

2018-01-05 Thread Klaus Darilion
Hi! I do not understand in detail what you are trying to achieve. But when using multiple backends, the answer is still coming only from one backend - the one with the best matching zone. e.g. backend 1 hosts test.test and backend 2 hosts test.test.test. If there is a query for

Re: [Pdns-users] JPowerAdmin - new version

2017-12-28 Thread Klaus Darilion
Am 28.12.2017 um 21:56 schrieb Jivko Sabev: Greetings everyone, After a long haitus, the JPowerAdmin control panel has a new release. You can find the details at the following link: https://www.jpoweradmin.ca/ From your website: Key features ... » MBOXFW record support (email forwarding)

Re: [Pdns-users] Attempt to print an unset dnsname

2017-11-08 Thread Klaus Darilion
1.2017 17:01, Brian Candler wrote: >> On 07/11/2017 14:57, Klaus Darilion wrote: >>> But whatever I try I do not receive a core dump. >> >> Not answering your question directly, but what about running pdns >> directly under

Re: [Pdns-users] Attempt to print an unset dnsname

2017-11-07 Thread Klaus Darilion
isk space, write permissions, ulimit ... no core dump. I do not even see the added log message, nor any kernel logging about the aborted process. Do you have any ideas what I am doing wrong? Thanks Klaus Am 25.10.2017 um 10:53 schrieb Remi Gacogne: > Hi Klaus, > > On 10/2

Re: [Pdns-users] Attempt to print an unset dnsname

2017-10-25 Thread Klaus Darilion
Hi Peter! I need help again debugging this issue. I used c++filt to beautify the trace. I also added the log lines before -> see attachment. I do not understand how the stacktrace correlates with the exception error. I analyzed the stack trace and I do not see any access to a DNSName at the top

Re: [Pdns-users] Some questions regarding Postgres Replication / Native operation

2017-10-25 Thread Klaus Darilion
imal writes to PDNS only via nsupdate. > Is there any way to forward those requests to the writable instance or do I > have to specify the right one in the nsupdate dialog? > > Best regards, > Fabian > >> On 15. Oct 2017, at 21:00, Klaus Darilion <klaus.mailingli...

Re: [Pdns-users] Some questions regarding Postgres Replication / Native operation

2017-10-15 Thread Klaus Darilion
Am 07.10.2017 um 22:59 schrieb Fabian: Hi, I have some questions regarding the integration of PostgreSQL replication and PowerDNS operating in native mode. As the replication of Postgres is a master - slave replication the transactions on the slaves are read-only. - Is there a way to

[Pdns-users] Attempt to print an unset dnsname

2017-09-26 Thread Klaus Darilion
Hi! My PowerDNS 4.0.4 (with some modifications) exits often with "Exiting because communicator thread died with STL error: Attempt to print an unset dnsname" I have some hard time to find where this happens. The logged stack trace is: Sep 26 14:53:19 cc-reg-vie1 pdns[16802]:

Re: [Pdns-users] Performance drop after upgrade from auth 3.4.11 to 4.0.4

2017-09-22 Thread Klaus Darilion
Am 22.09.2017 um 10:43 schrieb Aki Tuomi: > To my inexpert eye it seems that in your original post, 4.1 was fastest > of the lot, so the database begin/commit + prepare cannot really explain > this since this has not been removed in 4.1? Obviously there were some changes - no more BEGIN/COMMIT

Re: [Pdns-users] Performance drop after upgrade from auth 3.4.11 to 4.0.4

2017-09-22 Thread Klaus Darilion
Update: I do see that the BEGIN/COMMIT exists in 4.0, but was removed in Master (4.1pre). That might explain why Master is faster :-) regards Klaus Am 22.09.2017 um 10:35 schrieb Klaus Darilion: > > > Am 21.09.2017 um 20:20 schrieb Aki Tuomi: >> Statements are supposed t

Re: [Pdns-users] Performance drop after upgrade from auth 3.4.11 to 4.0.4

2017-09-22 Thread Klaus Darilion
Am 21.09.2017 um 20:20 schrieb Aki Tuomi: > Statements are supposed to prepared once, not per every query. Indeed, that is the case, the "prepare" is only done once. But I see that simple SELECTs are wrapped into transactions. Maybe this is also a performance penalty: regards Klaus LOG:

Re: [Pdns-users] Performance drop after upgrade from auth 3.4.11 to 4.0.4

2017-09-21 Thread Klaus Darilion
Hi Bert! Am 19.09.2017 um 21:18 schrieb bert hubert: > Can you redo your measurements against 4.1rc1? We fixed a lot in there. > Would be interesting to know if 4.1 is already better. Targets: reg-tst1, reg-tst2. (they are identical: 4vCPUs, 8GB RAM, no other VMs running on this hypervisor)

Re: [Pdns-users] Powerdns authoritative with gmysql backend and wilcard not matching existent subdomains

2017-09-20 Thread Klaus Darilion
Am 20.09.2017 um 10:24 schrieb tbn: > This query performs well in bind, so can anyone point if/what I'm > doing wrong here ? > Also, can anyone try to reproduce this behaviour ? AFAIK this is correct behavior. See https://tools.ietf.org/html/rfc4592#section-2.2.1 Are you sure that Bind

Re: [Pdns-users] PowerDNS authoritative, galera

2017-09-19 Thread Klaus Darilion
Hi Nick! I found this old thread. I am not familiar with galera, Percona etc. but IMO the setup is to complex. Why do you use master-master replication between the slaves? The slaves get synced from the master, hence every slave can have its own DB, no clustering needed. if both slaves receive

[Pdns-users] Performance drop after upgrade from auth 3.4.11 to 4.0.4

2017-09-19 Thread Klaus Darilion
Hi! Setup: PowerDNS with gqgsql backend, several 100.000 zones (type=NATIVE) on a 4 CPU VM with 8GB Ram cache-ttl=120 negquery-cache-ttl=120 query-cache-ttl=240 distributor-threads=8 receiver-threads=1 I am running 2 tests with dnsperf: 1. query the SOA of every authoritative zone: every zone

Re: [Pdns-users] potential side effects of ALIAS records

2017-02-09 Thread Klaus Darilion
Hi Peter! Thanks for the answers. On 08.02.2017 18:53, Pieter Lexis wrote: >> - If ALIAS is not enabled, will PDNS just ignore these records? > ALIAS is always "enabled". When we encounter an ALIAS record for the name > queried, it is expanded. So, there is no means to disable ALIAS? Then this

[Pdns-users] potential side effects of ALIAS records

2017-02-08 Thread Klaus Darilion
Hi! I wonder if there are any potential side effects if I enable ALIAS support on my authoritative servers. - Will outstanding recursion somehow block or slow down the answering of normal ressource records? - Will the expanded ALIAS result locally cached? (besides the packet cache, e.g. based

[Pdns-users] Performance and Tuning Recommendation

2017-01-11 Thread Klaus Darilion
Hi! I hav some input for https://doc.powerdns.com/md/authoritative/performance/: Just recently we did some performance debugging and found out that plenty of CPU was wasted due to the default encryption between PDNS and the Postgres DB. By disabling encryption we achieved around 30% more q/s,

[Pdns-users] Multiple backends with same zone

2017-01-10 Thread Klaus Darilion
Hi! What is the expected result if a zone is provisioned in 2 active backends. eg: launch=bind,gpgsql I know PDNS checks both backends for the best matching zone (getAuth). But I would expect that if PDNS finds out that both backends provide the zone, only the first configured backend is

Re: [Pdns-users] pdns 4.0.3 missing in repos

2017-01-03 Thread Klaus Darilion
Oh, sorry for my confusion. Klaus Am 03.01.2017 um 10:03 schrieb Pieter Lexis: > Hi Klaus, > > On Tue, 3 Jan 2017 09:37:09 +0100 > Klaus Darilion <klaus.mailingli...@pernau.at> wrote: > >> https://repo.powerdns.com/ubuntu/pool/main/p/pdns/ (and debian and >

[Pdns-users] pdns 4.0.3 missing in repos

2017-01-03 Thread Klaus Darilion
Hi! https://repo.powerdns.com/ubuntu/pool/main/p/pdns/ (and debian and centos) only offers packages for 4.0.1, but not for 4.0.3. Is this on purpose? Thanks Klaus ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com

[Pdns-users] Improving slave performance - dealing with broken masters

2016-09-15 Thread Klaus Darilion
Hi! We use PDNS to fetch zone from our customer's master server and serve then our our name server. The problem is, if a big customer's master server is not available, PDNS is busy doing frehsness checks for the respective domains (e.g. 20 domains). Thus will also cause problems for

Re: [Pdns-users] github code

2016-05-23 Thread Klaus Darilion
Hi Bert! On 23.05.2016 10:02, bert hubert wrote: > On Mon, May 23, 2016 at 09:51:38AM +0200, Klaus Darilion wrote: >> I am a bit confused about the source code on github. Which branch is the >> current 3.x branch and which one is the upcoming 4.0 branch? > > Hi Klaus, >

[Pdns-users] github code

2016-05-23 Thread Klaus Darilion
Hi! I am a bit confused about the source code on github. Which branch is the current 3.x branch and which one is the upcoming 4.0 branch? Thanks Klaus ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com

[Pdns-users] strange TSIG problems

2016-04-08 Thread Klaus Darilion
Hi! I make some test to transfer zones from PDNS using TSIG. The strange thing is, that AXFR + TSIG always works. But querying PDNS using TSIG most of the time results in TSIG errors, e.g: I query with: dig @xx.xx.xx.x www.tld-box.com A -y test:TpCdBiXZ successful query: 17:25:25 Query:

  1   2   >