I have this and poked around monitoring everything while it happened repeatedly. I stumbled onto a reliable means of reproduction:
dig -t AAAA ocsp.verisign.net. Happens with dnssec enable and disabled, so its not that. I tried it with a pretty stripped down to the original bind config and it still happened. https://www.cloudshark.org/captures/56802b91286a Its presumably the reply from verisign that kills it, but I'm not sure why. -- Jon Kernel Archaeologist X(7): A program for managing terminal windows. See also screen(1). -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org