Re: Problem with 9.6.2-p1

2010-04-07 Thread Chris Thompson
On Apr 6 2010, Daniel Ryslink wrote: By the way, similar problem occurs in 9.6.2-p1. According to changelog, support for RSA/SHA-256 (algorithm number 8 in dnssec-related records) was backported into 9.6.2 from 9.7 (and indeed, 9.6.2 has no problems with the TLDs recently signed with keys us

Re: "dig dnskey int." different responses from recent BIND versions

2010-04-07 Thread Chris Thompson
On Apr 7 2010, I wrote: A peculiarity: dig dnskey int. @... to nameservers with validation via dlv.isc.org gives SERVFAIL if they are running BIND 9.6.2-P1 or 9.7.0-P1. but gives a normal "NODATA" from BIND 9.6.2. Any ideas? The same thing happens for any zone without DNSKEY records replaci

"dig dnskey int." different responses from recent BIND versions

2010-04-07 Thread Chris Thompson
A peculiarity: dig dnskey int. @... to nameservers with validation via dlv.isc.org gives SERVFAIL if they are running BIND 9.6.2-P1 or 9.7.0-P1. but gives a normal "NODATA" from BIND 9.6.2. Any ideas? [Why was I messing around with "int"? It arose (not very directly) from a mention of the old