Re: [Pdns-users] Disabling DNSSEC on a Domain

2011-06-14 Thread bert hubert
On Tue, Jun 14, 2011 at 09:22:20PM +1200, Craig Whitmore wrote: I have to as far as I can tell.. pdnssec hash-zone-record spam.co.nz test105.spam.co.nz Get the hash and then use insert into records (domain_id,name,content,type,ttl,prio,ordername,auth) values

Re: [Pdns-users] PDNS devel and weird IPv6 log entries

2011-06-14 Thread bert hubert
On Tue, Jun 14, 2011 at 11:21:45AM +0200, Detlef Peeters wrote: Or to any of the slaves of depee.org ? Yes, IPv6 is enabled, and PowerDNS ist listening to it. The mater server for the domain depee.org has the IPv6 address: 2001:4d88:::d0:b723:6daf:2. With PowerDNS 2.9.22 and the

Re: [Pdns-users] DNSSEC/EDIT-SOA interaction

2011-06-12 Thread bert hubert
On Sun, Jun 12, 2011 at 03:06:20PM +0200, Christof Meerwald wrote: guess I have found another bug - this time related to signing of the SOA record when using SOA-EDIT. Again a good catch, fixed in 2215. Thanks! Bert ___ Pdns-users mailing

Re: [Pdns-users] DNSSEC/EDIT-SOA interaction

2011-06-12 Thread bert hubert
On Sun, Jun 12, 2011 at 06:22:27PM +0200, Jan-Piet Mens wrote: Again a good catch I don't know where to begin expressing how ashamed I am that I didn't detect that bug while testing EDIT-SOA ... It is the story of DNSSEC, we sign but almost nobody validates ;-) Bert

Re: [Pdns-users] DNSSEC Slave: RRSIG matching

2011-06-09 Thread bert hubert
On Thu, Jun 09, 2011 at 02:57:44PM +0200, Christof Meerwald wrote: My suspicion is that PowerDNS doesn't just use the RRSIG for the SOA record in the DNS response, but looks for the maximum timestamp in any RRSIG in the DNS response (even if that might be in the additional section)? Very good

Re: [Pdns-users] [HELP REQUEST] Heavy Mass-bombing against PowerDNS

2011-06-09 Thread bert hubert
On Thu, Jun 09, 2011 at 02:54:24PM -0600, kim Doff wrote: Jun 09 15:01:17 domain pdns[28541]: Not authoritative for 'adobe.com', sending servfail to 93.113.174.225 (recursion was desired) iptables on Linux allows filtering on string matches, try: # iptables -A INPUT -m string --string 'adobe'

Re: [Pdns-users] DNSSEC slave: TSIG/RRSIG interaction?

2011-06-09 Thread bert hubert
On Thu, Jun 09, 2011 at 10:37:22PM +0200, Christof Meerwald wrote: Ok, I have done some debugging now and this is why: PowerDNS expects the OPT RR to be the last record in the additional section, but when using TSIG, the TSIG RR is the last record (as this is required by the TSIG spec). This

Re: [Pdns-users] The Lua Backend for PowerDNS

2011-06-05 Thread bert hubert
On Sun, Jun 05, 2011 at 08:15:55PM +0200, fredrik danerklint wrote: Hi everybody! Fun news (I hope for all of you out there)! It is to me ;-) My love affair with Lua is not ending yet! I've merged this contribution in 2208, and added it to the default deb and rpm builds. To be fair, this is

Re: [Pdns-users] New ogslb release (v0.6)

2011-06-02 Thread bert hubert
Thank you very much! I wonder what the best way for PowerDNS would be to draw attention to your project. Since it is so decoupled from the main source, because it is PIPE based, it need not be compiled into the binaries. But we should still find a way to tell people that ogslb exists. Any

Re: [Pdns-users] Custom pipe backend

2011-05-31 Thread bert hubert
On Fri, May 27, 2011 at 04:17:30AM -0700, Ardhan Madras wrote: Okay, what I want to ask is why PowerDNS ask the A record for NS/MX domain name too? in this case bring ADDITIONAL SECTION on dig output that slooowing my backend resolve process. How to work around with this? In general, just

Re: [Pdns-users] zone2sql problem with _domainkey-records

2011-05-31 Thread bert hubert
On Mon, May 30, 2011 at 02:14:58PM +0200, Arsen STASIC wrote: hi, If I convert a valid zone-file to postgres-backend via zone2sql a valid sql-loader-file is generated but unfortunately powerdns is unable to serve this record: Hi Arsen, Can you re-test against a recent snapshot from

Re: [Pdns-users] 3.0-RC2 crash on sending notify

2011-05-29 Thread bert hubert
On Sun, May 29, 2011 at 03:38:39AM -0400, Charles Sprickman wrote: I'll top post since the answer is so simple... Ok - I just committed a fix that turns your mysterious crash into a helpful error message, http://wiki.powerdns.com/trac/changeset/2202 2202 is building on

Re: [Pdns-users] 3.0-RC2 crash on sending notify

2011-05-27 Thread bert hubert
On Thu, May 26, 2011 at 11:06:16PM -0400, Charles Sprickman wrote: various values for loglevel from 5 all the way up to 999 and never saw an increase in verbosity), so I tried launching powerdns from gdb, just to see if I could get more of a hint about what was happening. This is what I see

Re: [Pdns-users] Error message in logfile

2011-05-26 Thread bert hubert
On Thu, May 26, 2011 at 08:42:01AM +0200, Joerg Stephan wrote: May 26 08:31:24 ns1 pdns[4603]: Received question from socket which had no remote address, dropping (Transport endpoint is not connected) which appears every second. So both are just working and i can dig domains on both of

Re: [Pdns-users] Wildcards other than *

2011-05-26 Thread bert hubert
On Thu, May 26, 2011 at 05:29:33PM +0200, Marten Lehmann wrote: Hello, given the example domain whatever.com I just tried to insert the records pop3.* and imap.* for this zone. But trying to resolve Hi Marten, I'm afraid this has little to do with PowerDNS and everything with DNS. records

Re: [Pdns-users] startup fails when master=yes

2011-05-25 Thread bert hubert
On Wed, May 25, 2011 at 01:48:47AM -0400, Charles Sprickman wrote: Hello, I recently started doing some basic testing of pdns and it's been going well. I decided to test the master/slave setup, so I set master=yes on one of my test servers. The server fails to start when this is enabled,

Re: [Pdns-users] dnssec in pdns-recursor

2011-05-21 Thread bert hubert
On Fri, May 20, 2011 at 03:31:35PM -0700, Alfred B. M. Cordero wrote: Does anyone know if the recursor can use dnssec? I don't find any information on that. not yet, but this will come immediately after the release of 3.0 authoritative server. Bert

[Pdns-users] Hack In The Box SIDN presentations

2011-05-17 Thread bert hubert
Hi everybody, There will be two, hopefully interesting, presentations that will touch on PowerDNS, DNSSEC, security and other things. These presentations are at closed venues, but I post about them here anyhow because there is probably quite some overlap between PowerDNS and the

Re: [Pdns-users] Status of the LDAP backend in 3.0 release

2011-05-14 Thread bert hubert
On Fri, May 13, 2011 at 04:35:13PM +0300, Nick Milas wrote: On 30/4/2011 11:00 πμ, Nick Milas wrote: (i) It would not be difficult to include at least the proposed patch for Ticket #313 (http://mailman.powerdns.com/pipermail/pdns-users/2010-September/007004.html) in one v3.0 build

Re: [Pdns-users] Performance of LUABackend

2011-05-12 Thread bert hubert
On Thu, May 12, 2011 at 03:58:15PM +0200, fredrik danerklint wrote: This is just a test to see how fast it can be with only two records in lua: So you have a Lua backend? ;-) Can you share? Queries per second: 23304.748835 qps To validate understand such numbers it is good to do a cached

Re: [Pdns-users] Random (was: When to do a key rollover?)

2011-05-11 Thread bert hubert
On Wed, May 11, 2011 at 08:19:01PM +0200, Posner, Sebastian wrote: Otherwise, create a fresh and immediately active key If the active ZSK will expire soon, create a spare key These last two lines implicate another question: Is there any possibility to influence the source of random

Re: [Pdns-users] another crash

2011-05-09 Thread bert hubert
On Wed, May 04, 2011 at 01:56:41PM +0400, Vasiliy G Tolstov wrote: On Wed, 2011-05-04 at 13:04 +0400, Vasiliy G Tolstov wrote: On Tue, 2011-05-03 at 22:45 +0400, Vasiliy G Tolstov wrote: hello. some new crash, but very minimal debug =( pdns from 64 bit rpm:

Re: [Pdns-users] strange lock after some time after start

2011-05-09 Thread bert hubert
On Thu, Apr 28, 2011 at 11:20:42PM +0400, Vasiliy G Tolstov wrote: On Tue, 2011-04-26 at 19:15 +0400, Vasiliy G Tolstov wrote: Hello =). Any progress about this problem? This reproduced always if i restart master and do notify for all zones in cycle o slave... Vasiliy, Can you confirm

Re: [Pdns-users] Questions on powerdnssec

2011-05-09 Thread bert hubert
On Mon, May 09, 2011 at 02:24:05PM +0100, Chris Russell wrote: Firstly, when using an external server as a recursor; can this be an IPv6 host ? I have the auth server forwarding to bind for any recursive queries, this works when I specify the bind IPv4 address, but not the IPv6

Re: [Pdns-users] Sorting of DNS responses

2011-05-07 Thread bert hubert
On Fri, Apr 29, 2011 at 09:43:29AM +0200, Roland Schwingel wrote: Hi I am using pdns 2.9.22 with ldap backend for many months now. It works very nice and without troubles.Thanks for this... Maybe I am too dump to find this in the docu but I need to sort the responses of dns replies

Re: [Pdns-users] PowerDNS use statistics

2011-05-07 Thread bert hubert
On Mon, May 02, 2011 at 10:13:47PM +0300, Nick Milas wrote: But are there any other surveys about DNS Software use which one would suggest as more reliable? Are there any comparative DNS server software usage trends data for the last 5-6 years ? Correctly or not, for many people, the

Re: [Pdns-users] ogslb a new gslb backend

2011-05-07 Thread bert hubert
On Mon, May 02, 2011 at 07:44:49PM -0400, Mitchell Broome wrote: I have a new backend for PowerDNS callend ogslb (open global server load balancer) I have been playing with to do gslb. You can check it out at: https://github.com/mbroome/ogslb This looks exciting! Thanks. Would you consider

Re: [Pdns-users] pdns/ldap funding, how much?

2011-05-07 Thread bert hubert
On Thu, May 05, 2011 at 05:04:23PM -0400, Christopher Wood wrote: I don't know if anybody has asked how much #2 or #3 cost. How much money are we talking about, as a rounded figure per month or per year? After all, if enough people want this then perhaps it makes sense to spread the cost.

Re: [Pdns-users] another crash

2011-05-04 Thread bert hubert
On Wed, May 04, 2011 at 01:56:41PM +0400, Vasiliy G Tolstov wrote: On Wed, 2011-05-04 at 13:04 +0400, Vasiliy G Tolstov wrote: On Tue, 2011-05-03 at 22:45 +0400, Vasiliy G Tolstov wrote: hello. some new crash, but very minimal debug =( pdns from 64 bit rpm:

Re: [Pdns-users] Authoritative Server 3.0 RC2 Performance?

2011-05-01 Thread bert hubert
On Fri, Apr 29, 2011 at 12:44:44PM -0700, Zane Thomas wrote: I recently rebuilt my backend to work with version 3.0. Previously performance, as measured by respperf, was in the upper 60K per second range. Now it seems to be in the low 7K range running the exact same set of data. CPU usage

Re: [Pdns-users] Status of the LDAP backend in 3.0 release

2011-05-01 Thread bert hubert
On Sun, May 01, 2011 at 08:57:20PM +0100, Chris Russell wrote: However, I was at the UK version of NANOG (UKNOF) meeting a few weeks back, with a lot of people from ISP's and a few fairly senior people from ISC and I asked the same question - not one recomended Power DNS with Well, what can

Re: [Pdns-users] DNSsec DS trouble in single server TLD setup

2011-04-27 Thread bert hubert
On Thu, Apr 21, 2011 at 11:13:00AM +0200, Niek wrote: Couldn't get it to work with the TLD and the child zone on the same server. I was wondering whether this could be a bug in PowerDNS Server or whether I'm maybe trying to do something the wrong way. (And I was wondering if it also affects

Re: [Pdns-users] mysql-tests

2011-04-27 Thread bert hubert
On Sat, Apr 23, 2011 at 01:04:51AM +0200, erkan yanar wrote: As Im missing any good data I created 6*10^6 entries for domains and for every domain some entries in the records-table (about 66*10^6) That is a pretty good test! 6 million domains is around 2 million domains smaller than the largest

Re: [Pdns-users] Delegating a subdomain with DNSsec fails if child and parent zone are on same server

2011-04-26 Thread bert hubert
Hi Niek Jan-Piet, Vasiliy, everybody, Sorry for not being very responsive to issues in the past few days, other things kept us busy. The problems you found are very important, and their fixes will make for a better 3.0 release. Expect fixes tomorrow (Wednesday) and beyond. Bert

Re: [Pdns-users] DNS resolution problem with pdns-recursor-3.3

2011-04-21 Thread bert hubert
Kenneth, Can you reproduce the issue with http://svn.powerdns.com/snapshots/pdns-recursor-3.4-pre.tar.bz2 ? I can resolve cdn4.digitalconcerthall.com reliably with it here. Bert ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com

Re: [Pdns-users] DNS resolution problem with pdns-recursor-3.3

2011-04-21 Thread bert hubert
On Thu, Apr 21, 2011 at 03:33:31PM -0500, Kenneth Marshall wrote: I am sorry, but I think this has been a wild goose chase regarding a bug in the recursor. The existing 3.3 version works just fine with resolving cdn4.digitalconcerthall.com from a system outside our network. I am going to start

Re: [Pdns-users] issues using the recursive-cache-ttl on powerdns 3.0rc2

2011-04-20 Thread bert hubert
On Wed, Apr 20, 2011 at 10:04:04AM +0400, Vasiliy G Tolstov wrote: Sometimes ago i send e-mail about this problem. But not recive any answer. I'm try to... =) Hehe - well, your bug report was a lot more detailed and looked like a lot of work ;-) No good deed goes unpunished it appears.

[Pdns-users] PowerDNS Authoritative Server 3.0 Release Candidate 2 available

2011-04-19 Thread bert hubert
Hi everybody, Release Candidate 2 of the PowerDNS Authoritative Server 3.0 is available from: http://downloads.powerdns.com/releases/pdns-3.0-rc2.tar.gz http://downloads.powerdns.com/releases/deb/pdns-static_3.0-rc2-1_i386.deb

Re: [Pdns-users] PowerDNS Authoritative Server 3.0 Release Candidate 2 available

2011-04-19 Thread bert hubert
On Tue, Apr 19, 2011 at 03:02:20PM +0200, Angel Bosch Mora wrote: is there any news regarding LDAP support on this version? Hi Angel, We are willing to accept patches that fix up the LDAP backend up to the release of 3.0, but nothing has come in yet. So no news yet.. Bert

Re: [Pdns-users] PowerDNS Authoritative Server 3.0 Release Candidate 2 available

2011-04-19 Thread bert hubert
On Tue, Apr 19, 2011 at 03:22:37PM +0200, kalpesh thaker wrote: Do you have an idea if the geo backend will be supported in release 3.0? i am about to start testing the new release using geobackend but need to confirm that its still supported. It is! We've also done testing to see if it

Re: [Pdns-users] DNS resolution problem with pdns-recursor-3.3

2011-04-19 Thread bert hubert
On Tue, Apr 19, 2011 at 01:24:37PM -0500, Kenneth Marshall wrote: Hi PDNS users, I have been trying to figure out why the following site is not resolving: dig cdn4.digitalconcerthall.com This is a known bug in 3.3: Discovered by John J and Robin J, the PowerDNS Recursor did not process

Re: [Pdns-users] issues using the recursive-cache-ttl on powerdns 3.0rc2

2011-04-19 Thread bert hubert
tests: http://powerdnssec.org/downloads/regression-test-results-2176.txt Kind regards, Bert Hubert ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] help with noerror-queries

2011-04-18 Thread bert hubert
On Mon, Apr 18, 2011 at 04:15:33PM -0300, Eduardo Casarero wrote: Well, aparently the issue was with the CNAME of domain.com pointing to www.domain.com that record messed up everything. Maybe i am a dns noob, but can anyone point me why this happened? Any domain that is configured that way is

Re: [Pdns-users] pdns_recursor 3.3-hooks ... possible cache issue

2011-04-14 Thread bert hubert
On Thu, Apr 14, 2011 at 09:40:58AM -0700, Alfred B. M. Cordero wrote: On Wed, 13 Apr 2011 12:11:34 -0700 bert hubert bert.hub...@netherlabs.nl wrote: Try reproducing with 'threads=1'. You may be seeing hits from multiple separate caches. You are telling me that each thread maintains its

[Pdns-users] MongoDB Backend merged Re: Mongo DB and PowerDNS part 3: Now with DNSSEC

2011-04-14 Thread bert hubert
On Tue, Apr 05, 2011 at 10:12:49PM +0200, fredrik danerklint wrote: I've just send the sourcecode of the backend to Bert! Hi Fredrik, I have just merged it with the build system based on your latest version. It is part of build 2163, and will be shipped as 'experimental' with version 3.0. Get

Re: [Pdns-users] pdns_recursor 3.3-hooks ... possible cache issue

2011-04-13 Thread bert hubert
On Wed, Apr 13, 2011 at 11:53:35AM -0700, Alfred B. M. Cordero wrote: Using the postresolve hook in lua to alter TTL that are too low. I log queries that hit the lua code and I see log events for that same host that occur within the same one second period and sometimes within a few or more

Re: [Pdns-users] Recursor v3.2 and v3.3 malformed answer in case of big response from authoritative

2011-04-12 Thread bert hubert
On Mon, Apr 11, 2011 at 05:11:41PM +0200, bert hubert wrote: On Mon, Apr 11, 2011 at 04:53:16PM +0200, Thor Spruyt wrote: Last week I discovered an issue with recursor v3.2. Hi Thor, Thanks! You've uncovered an interesting bug which was quite devious. It has been solved in http

Re: [Pdns-users] Recursor v3.2 and v3.3 malformed answer in case of big response from authoritative

2011-04-11 Thread bert hubert
On Mon, Apr 11, 2011 at 04:53:16PM +0200, Thor Spruyt wrote: Last week I discovered an issue with recursor v3.2. This is probably fixed in 3.3.1: Discovered by John J and Robin J, the PowerDNS Recursor did not process packets that were truncated in mid-record, and also did not act on the

Re: [Pdns-users] General DNS questions...

2011-04-08 Thread bert hubert
On Thu, Apr 07, 2011 at 10:14:31PM -0400, Mohamed Lrhazi wrote: I hope you guys don't mind a couple of non pdns specific questions... For once ;-) - When you declare 2 or 3 NS records for your domain, does the order of those names correlate with their usage? by that I mean can I expect a

Re: [Pdns-users] PowerDNS Authoritative Server 3.0 Release Candidate 1 available

2011-04-05 Thread bert hubert
/ Regards, Kees On 4-4-2011 16:50, bert hubert wrote: Hi everybody, Release Candidate 1 of the PowerDNS Authoritative Server 3.0 is available from: http://powerdnssec.org/downloads/pdns-3.0-rc1.tar.gz http://powerdnssec.org/downloads/packages/pdns-static-3.0rc1-1.i386.rpm http

[Pdns-users] PowerDNS Authoritative Server 3.0 Release Candidate 1 available

2011-04-04 Thread bert hubert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi everybody, Release Candidate 1 of the PowerDNS Authoritative Server 3.0 is available from: http://powerdnssec.org/downloads/pdns-3.0-rc1.tar.gz http://powerdnssec.org/downloads/packages/pdns-static-3.0rc1-1.i386.rpm

Re: [Pdns-users] Status of the LDAP backend in 3.0 release

2011-04-03 Thread bert hubert
On Sun, Apr 03, 2011 at 11:44:56PM +0200, Udo Rader wrote: Before promising something I can't keep: yes, I will give my best to fix the issues above and if things go well, it is not unlikely that either I myself or one of our developers will invest some more time into enhancements, but one

Re: [Pdns-users] release date for pdns 3?

2011-04-03 Thread bert hubert
On Sun, Apr 03, 2011 at 09:57:47PM +0400, Vasiliy G Tolstov wrote: Hello. Where i can find release date for powerdns 3 ? roadmap in wiki says nothing... The open source plan is always to release when ready ;-) Tomorrow (Monday) will see RC1, I expect three subsequent releases (RC2, RC3 and

[Pdns-users] probably fixed Re: current svn crushes...

2011-03-31 Thread bert hubert
On Wed, Mar 30, 2011 at 02:59:34PM +0400, Vasiliy G Tolstov wrote: If it doesn't always start there, can you paste some other traces? Thanks! pdns[31390]: /usr/sbin/pdns_server-instance(_ZN17CommunicatorClass12slaveRefreshEP13PacketHandler+0x1a8b) [0x8169c2b] Mar 30 14:52:25 monitoring

Re: [Pdns-users] error notify master to itself with it's own zone

2011-03-31 Thread bert hubert
On Thu, Mar 31, 2011 at 12:10:00PM +0400, Vasiliy G Tolstov wrote: Another problem (may be not related to current trunk..) Received NOTIFY for clodo.ru from 188.127.236.4 which is not a master But pdns on 188.127.236.4 already master for zone clodo.ru ? Why this happened? This is a master

Re: [Pdns-users] current svn crushes...

2011-03-30 Thread bert hubert
On Wed, Mar 30, 2011 at 02:36:14PM +0400, Vasiliy G Tolstov wrote: I'm build current svn trunk, something work's fine, but sometimes i get this error: Hi Vasiliy, Can you verify that the crash always starts: pdns[28785]: /usr/sbin/pdns_server-instance(_ZN11GSQLBackend8setFreshEj +0x73)

[Pdns-users] SOA serial number editing on re-signing of a zone / RRSIG changes

2011-03-27 Thread bert hubert
On Wed, Mar 23, 2011 at 12:39:42AM +0100, Christof Meerwald wrote: Just wanted to check what the status is on having a PowerDNS master with a non-PowerDNS slave for DNSSEC signed zone - we had briefly discussed this some time ago and I think the slave (if it's not PowerDNS) currently won't do

[Pdns-users] Status of the LDAP backend in 3.0 release

2011-03-23 Thread bert hubert
, Bert Hubert PowerDNS ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] [gmysql] How about add CLIENT_MULTI_RESULTS to smysql.cc ?

2011-03-22 Thread bert hubert
On Mon, Mar 21, 2011 at 08:35:15AM +0100, Sandro Tosi wrote: Anyone has comment on this patch? Is there a better place I can send it for review and (possible) inclusion? Hi Sandro, It has been added to revision 2084, which can be downloaded from http://powerdnssec.org/snapshots/ It will also

[Pdns-users] Heading up to PowerDNS Authoritative Server release 3.0: please check your open tickets

2011-03-22 Thread bert hubert
invalid: --fork is gone in recent versions Ticket #305 (Disable a zone / domain / record) closed by ahu wontfix: To do this, please customize the SQL queries to have an 'active' field. Kind regards, Bert Hubert ___ Pdns-users mailing list Pdns-users

Re: [Pdns-users] pdns-server, DNS-SD and \032 in record labels

2011-03-18 Thread bert hubert
On Fri, Mar 18, 2011 at 09:33:39PM +, Andy Smith wrote: So it seems to me that there are multiple places here that can't handle \032 in a query name or in a record label. Just changing backend is not going to get this working for me, right? Andy, Can you try to reproduce the issue with

Re: [Pdns-users] Mongo DB and Powerdns

2011-03-15 Thread bert hubert
On Mon, Mar 14, 2011 at 07:34:15PM +0100, Jan-Piet Mens wrote: To my knowledge there is no such back-end. What I have done is a PowerDNS pipe back-end to CouchDB. Performance is lousy of course, but I did it as a proof of concept, and it works ok. I've written about it at If the performance is

Re: [Pdns-users] Malformed messages when not in cache

2011-03-05 Thread bert hubert
On Fri, Mar 04, 2011 at 07:38:36PM -0500, Kevin O'Connor wrote: We have a record set up with the BIND backend as follows: testing IN CNAME gci-prod-lb-0.us-east-1.elb.amazonaws.com. When you query it right after a service restart, you get: Wow, that is weird.

Re: [Pdns-users] Format of private keys in PowerDNSSEC (gmysql) doesn't correspond to BIND's

2011-03-03 Thread bert hubert
On Thu, Feb 24, 2011 at 05:44:01PM +0100, Maik Zumstrull wrote: As noted in the comment, I'm not sure whether this small error is on PDNS' part or in ldns, but an example in RFC 5702 suggests BIND's format is correct. As far as I can tell, this private key format has no formal

Re: [Pdns-users] authoritative server freezes while processing NOTIFYs

2011-03-03 Thread bert hubert
On Wed, Feb 16, 2011 at 10:53:05AM +, Richard Poole wrote: We have a setup with a non-public master and two publicly visible slaves. All three servers are using the bind backend. Sometimes we need to change many zones, say about 2000, at the same time, causing the master to send out 2000

Re: [Pdns-users] stuck tcp sessions on recursor

2011-02-24 Thread bert hubert
On Thu, Feb 24, 2011 at 01:33:24PM -0500, Charles Sprickman wrote: Simon Bedford, Brad Dameron and Laurient Papier discovered relatively high TCP/IP loads could cause TCP/IP service to shut down over time. Addressed in commits 1546, 1640, 1652, 1685, 1698. Additional information provided by

Re: [Pdns-users] stuck tcp sessions on recursor

2011-02-24 Thread bert hubert
On Thu, Feb 24, 2011 at 03:06:12PM -0500, Charles Sprickman wrote: this definitely sounds like 3.3 material! So far so good, nearly 500,000 tcp queries without any lingering sockets. Good! Totally unrelated, but I see a stat that's not mentioned in the docs: no-packet-error 492682. What

Re: [Pdns-users] Zone transfer MX record issue

2011-02-20 Thread bert hubert
On Mon, Feb 21, 2011 at 02:15:26PM +0800, p8x wrote: zone transfer from the primary PowerDNS seems to mangle the records slightly replacing occurrences of the domain with an @ in some cases. This seems to work for all of the records except for the MX record. As an example, here is a copy of

[Pdns-users] PowerDNS Tickets are being processed, please check the status of yours

2011-02-14 Thread bert hubert
Dear PowerDNS users, As of yesterday, 103 tickets were open in the PowerDNS bugtracker, available on http://wiki.powerdns.com/trac/report/1 Today, 87 are left. As most tickets have been filed anonymously, if you ever created one, please check our timeline on

Re: [Pdns-users] PowerDNS and pgbouncer

2011-02-14 Thread bert hubert
On Mon, Feb 14, 2011 at 02:45:43PM -0600, Mark Felder wrote: Is there any connection pooling work done by PowerDNS that would negate any possible performance benefits of pgbouncer? Hi Mark, During typical PowerDNS operation, you will see a number over very longlived database connections, plus

Re: [Pdns-users] query on --out-of-zone-additional-processing

2011-02-11 Thread bert hubert
On Fri, Feb 11, 2011 at 10:32:45AM +, Tom Boland wrote: Do out of zone additional processing. This means that if a malicious user adds a '.com' zone to your server, it is not used for other domains and will not contaminate answers. Do not enable this setting if you run a public

Re: [Pdns-users] PDNS Recursor on Debian / Low performance !!!URGENT!!!!

2011-02-07 Thread bert hubert
On Mon, Feb 07, 2011 at 09:17:29AM +, Maroon Ibrahim wrote: As for the file descriptors, I already added the following: - in sysctl.conf : fs.file-max = 65535 - in /etc/init.d/pdns-recursor #!/bin/sh # chkconfig: - 80 75 # description: pdns_recursor is a versatile high

Re: [Pdns-users] AXFR problem with pdns snapshots

2011-02-07 Thread bert hubert
On Mon, Feb 07, 2011 at 10:24:53PM +0100, Christof Meerwald wrote: Ok, think I have found it - Microsoft DNS doesn't seem to like the EDNS options in the AXFR packets. Guess that's why it says WRONG in tcpreceiver.cc, line 410... Our EDNS-in-AXFR has been brought in line with RFC 5936 now. I

Re: [Pdns-users] DNSSEC and Master/Slave setup

2011-02-03 Thread bert hubert
On Thu, Feb 03, 2011 at 08:44:08AM +0100, Christof Meerwald wrote: I kind of expected this to happen today - the master (ns.cmeerw.net) with the keying material has now updated the RRSIG records, but the slave (ns2.cmeerw.net, no keying material) still returns the old RRSIG records: Indeed,

Re: [Pdns-users] signingpipe.hh not in snapshot 1964

2011-02-03 Thread bert hubert
On Thu, Feb 03, 2011 at 09:25:04PM +0100, M Techter wrote: being interested in DNSSEC support of pdns, I tried to build from the pdns-3.0-pre.20110202.1964 Good catch - we fixed the issue in SVN already. Meanwhile,

Re: [Pdns-users] New PowerDNS Authoritative Server snapshot with DNSSEC + Release Notes

2011-01-29 Thread bert hubert
On Sat, Jan 29, 2011 at 10:30:47AM +0100, Christof Meerwald wrote: On Sat, 29 Jan 2011 00:38:12 +0100, Christof Meerwald wrote: That's really excellent news - I have just migrated my 2 nameservers to SVN revision 1928 and signed one of the zones (btw, the setup is: master using bind backend

Re: [Pdns-users] New PowerDNS Authoritative Server snapshot with DNSSEC + Release Notes

2011-01-28 Thread bert hubert
On Fri, Jan 28, 2011 at 12:27:13AM +0100, Detlef Peeters wrote: On 27.01.2011 23:37, bert hubert wrote: (the short version, there is a snapshot worth looking at, packages on http://powerdnssec.org/downloads - documentation on http://powerdnssec.org ) I have upgraded to the snapshot

Re: [Pdns-users] Recursor: Different answers for the same query

2011-01-26 Thread bert hubert
On Wed, Jan 26, 2011 at 10:32:19AM +0100, Christian Kuehn wrote: any idea why the pdns-recursor 3.3 gives different answers to the same query?? Hello!! ;-) You probably run with threads=2, and one of the threads has had problems resolving cecilmen.se, and the other hasn't. 3.3.1 which will be

Re: [Pdns-users] problem with one specific dns name

2011-01-18 Thread bert hubert
On Tue, Jan 18, 2011 at 11:12:19AM -0800, dialsc wrote: www.vggr.ch has been registered as a cname record pointing to vggr.ch which is an A type record. randomly one or more powerdns servers are unable to resolve www.vggr.ch. once i restart the recursor of the server having this problem,

Re: [Pdns-users] Changing replies from PowerDNS

2011-01-10 Thread bert hubert
Hi 'abcdef ghijkl' with your newsubdomain.domain.com on dns.comain.com, I'm afraid I can't help you this way. Please provide real domain names and IP addresses. You might want to consider upgrading to 2.9.22. Bert On Mon, Jan 10, 2011 at 01:00:46PM +0100, abcdef ghijkl wrote: Hello

[Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-06 Thread bert hubert
Dear PowerDNS Community, With the help of many of you, we've now brought 'PowerDNSSEC' to the point where it might make sense for you to trial it on test domains. We expect to make move some of our own important domains over to PowerDNSSEC early next week. PowerDNS.COM underlies the commercial

Re: [Pdns-users] DNS Requirements - Packet Type Allowance/Responses/Settings

2011-01-03 Thread bert hubert
On Mon, Jan 03, 2011 at 02:27:22PM -0500, Morgan Osborne wrote: Does anyone have a specific list of the required packet types (and response settings) needed for DNS servers to fully operate on the net? I know UDP is a must, but more to the point, are ICMP (ping, tracert) responses

Re: [Pdns-users] pdns recursor do not always use records in /etc/hosts

2010-12-28 Thread bert hubert
On Wed, Dec 29, 2010 at 03:20:13PM +0800, Conan wrote: We know the option export-etc-hosts=on will export records from /etc/hosts to pdns recursor. But I found the records are not always available. Hi Conan, The export-etc-hosts feature is not meant to override the internet, but to supplement

Re: [Pdns-users] redirect a search for one site to another site

2010-12-25 Thread bert hubert
On Sat, Dec 25, 2010 at 05:13:47PM -0500, Morgan Osborne wrote: The first is 'red.com' with a record type of 'CNAME' and content of 'blue.com' , then the second record is 'blue.com' with a record type of 'A' and the correct IP address of '150.145.15.1' So now when I do a http search for

Re: [Pdns-users] Pramod Bodla wants to stay in touch on LinkedIn

2010-12-22 Thread bert hubert
Please everybody do not respond ;-) On Wed, Dec 22, 2010 at 04:49:11AM +, Pramod Bodla wrote: LinkedIn I'd like to add you to my professional network on LinkedIn. - Pramod Bodla Pramod Bodla Senior Soft ware Engineer at Kodiak Networks Bengaluru Area, India

Re: [Pdns-users] pdns-recursor doesnt connect to dns root servers

2010-12-21 Thread bert hubert
On Tue, Dec 21, 2010 at 06:24:56PM +0100, Florian Krolikowski wrote: Hi Bert! Here the requested tcpdump. I hope it is meaningful for you. Thanks a lot for your help. Hi Florian, It appears that there is no PowerDNS issue - PowerDNS is sending correct root priming queries, but getting no

Re: [Pdns-users] [Recursor] Resolving large RRsets

2010-12-13 Thread bert hubert
On Mon, Dec 13, 2010 at 09:35:47AM +0100, Stephane Bortzmeyer wrote: On Mon, Dec 13, 2010 at 09:30:18AM +0100, bert hubert bert.hub...@netherlabs.nl wrote a message of 286 lines which said: Dec 13 09:23:54 [1] all-wikileaks.bortzmeyer.fr.: truncated bit set, retrying via TCP

[Pdns-users] PowerDNS Recursor: McAfee-related errors in your log files

2010-12-08 Thread bert hubert
; dr.d_label=label; dr.d_clen=ah.d_clen; Kind regards, Bert Hubert ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] PowerDNS Recursor: McAfee-related errors in your log files

2010-12-08 Thread bert hubert
McAfee responded within minutes, and they are on the case. Thanks for the hint! Bert On Wed, Dec 08, 2010 at 09:05:24AM -0500, Curtis Maurand wrote: You might try posting a message to the nanog list. --Curtis On 12/8/2010 7:43 AM, bert hubert wrote: Dear PowerDNS Recursor users

Re: [Pdns-users] Cache Problems with upgrade to Recursor 3.3

2010-12-02 Thread bert hubert
On Wed, Dec 01, 2010 at 12:40:40PM -0600, Jeremy Utley wrote: load balancer which handles sharing the load between them. This implementation has been in place for about a year with no issues. We also use Cacti graphs for collecting performance data, by extending SNMP with output from the

Re: [Pdns-users] tcp listener issue - hopefully fixed

2010-12-02 Thread bert hubert
:04 To: bert hubert Cc: Mike; pdns-users@mailman.powerdns.com Subject: Re: [Pdns-users] tcp listener issue - hopefully fixed Bert, I re-downloaded the src and rebuilt my RPM. It appears to be up and running now. Unknown why the first compiles had this issue. I have been testing the last

Re: [Pdns-users] PowerDNS Recursor additional Lua hooks for IPv6 DNS64 and Renumbering

2010-11-15 Thread bert hubert
On Sun, Nov 14, 2010 at 10:32:31PM +0100, bert hubert wrote: The PowerDNS Recursor is currently being extended with additional Lua hooks and extra infrastructure to support flexible DNS64 operations, plus perform on-the-fly IPv4 or IPv6 renumbering. (...) Known defects are: postresolve

Re: [Pdns-users] is it nessary to add soa record? I don't use axfr.

2010-11-10 Thread bert hubert
On Thu, Nov 11, 2010 at 12:05:26PM +0800, Xscape wrote: hi, I will manage one dns zone(or one domain) with pdns authoritative server (mysql backend). Is there any problems without soa record. SOA means 'start of authority'. Without SOA, there is no authority and no zone. So yes, it is

Re: [Pdns-users] Announcing JPower Admin

2010-10-12 Thread bert hubert
! Bert Hubert PowerDNS On Mon, Oct 11, 2010 at 03:36:35PM -0600, Jivko Sabev wrote: Greetings, I have released yet another control panel for Power DNS. Some of the key features include: - support for all Power DNS features - support for fancy records - built on an enterprise platform

Re: [Pdns-users] Pdns 2.9.22 stopped treating NOTIFY or manual retrieves when acting as slave

2010-10-04 Thread bert hubert
On Mon, Oct 04, 2010 at 02:09:16PM +0200, Florent Lerat wrote: We slave about 20 domains for most of which one of our 5 servers is the master. We are slave for 90 different masters. Some of those masters are indeed generating timeout or different types of error such as : - Query to

Re: [Pdns-users] PowerDNS recursor rrd change ?

2010-09-28 Thread bert hubert
Indeed. And for this purpose we have: http://doc.powerdns.com/recursor-stats.html ;-) This states: It should be noted that answers0-1 + answers1-10 + answers10-100 + answers100-1000 + packetcache-hits + over-capacity-drops = questions. You are currently missing the 'packetcache-hits'. The

Re: [Pdns-users] pdns recursor 3.2 cname resolution phenomenon

2010-09-22 Thread bert hubert
Thomas, Please provide real domain names, otherwise I can't test. Kind regards, Bert Hubert On Wed, Sep 22, 2010 at 04:53:22PM +0200, Thomas Mieslinger wrote: On 09/20/10 07:53 AM, bert hubert wrote: On Mon, Sep 20, 2010 at 07:32:51AM +0200, Thomas Mieslinger wrote: we're using pdns

Re: [Pdns-users] pdns recursor 3.2 cname resolution phenomenon

2010-09-22 Thread bert hubert
you will get NXDomain and AUTHORTIY = 1, but internally db686.YYY.de is known. Would you add an option to try recursing cnames even if an answer has the authority bit set? Regards Thomas On 09/22/10 04:54 PM, bert hubert wrote: Thomas, Please provide real domain names, otherwise I

[Pdns-users] PowerDNS Recursor 3.3 released!

2010-09-22 Thread bert hubert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi everybody, We're proud to announce the release of the PowerDNS Recursor 3.3! It can be downloaded from http://www.powerdns.com/ or via the following direct links: http://downloads.powerdns.com/releases/pdns-recursor-3.3.tar.bz2

Re: [Pdns-users] PowerDNS Recursor 3.3-RC3 released

2010-09-21 Thread bert hubert
On Tue, Sep 21, 2010 at 11:08:33AM +0200, Detlef Peeters wrote: On Mon, 20 Sep 2010 20:22:40 +0200, bert hubert bert.hub...@netherlabs.nl wrote: PowerDNS Recursor 3.3 Release Candidate 3 is now available! It is in wide production use already, but we'd like everyone to take a good look

<    1   2   3   4   5   6   7   8   9   >