Re: DNSSEC and upgrading/restoring

2014-01-30 Thread David Newman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 1/28/14 3:49 AM, Alan Clegg wrote: > > On Jan 27, 2014, at 7:32 PM, David Newman > wrote: > >> Asking again, in a different and more generic form: When >> rebuilding a bind 9.9.4 server running DNSSEC with auto maintain, >> are there any steps I

Re: Bind-9.9.4-S3 RRL

2014-01-30 Thread Evan Hunt
On Thu, Jan 30, 2014 at 04:02:04PM +, Olsen, Richard William (Rick) CTR DISA PEO-MA (US) wrote: > Reading different pages I have seen that you needed to use --enable-rrl > as a configuration option but it is not in the S3 release. So is it the > default or not available in the S3. The public r

Bind-9.9.4-S3 RRL

2014-01-30 Thread Olsen, Richard William (Rick) CTR DISA PEO-MA (US)
Reading different pages I have seen that you needed to use --enable-rrl as a configuration option but it is not in the S3 release. So is it the default or not available in the S3. The public release does have a rrl option. Rick. smime.p7s Description: S/MIME cryptographic signature ___

Re: How to query the "incoming" serial of a zone while inline signing

2014-01-30 Thread Tony Finch
Klaus Darilion wrote: > > named-compilezone -j -f raw -o - example.com \ > /etc/bind/zones/example.com 2>&1| grep SOA|awk '{print $7;}' Another option might be to use named-journalprint and grab the last SOA from the output. I don't know which is faster... actually, let's test... $ time named-

Re: How to query the "incoming" serial of a zone while inline signing

2014-01-30 Thread Klaus Darilion
On 30.01.2014 14:28, Tony Finch wrote: Mark Andrews wrote: In message <52ea4c56.5060...@pernau.at>, Klaus Darilion writes: Are there any tools/ways to query Bind for the incoming serial? rndc zonestatus [class [view]] I think that's a BIND-9.10 feature :-) On 9.9 I think you e

Re: How to query the "incoming" serial of a zone while inline signing

2014-01-30 Thread Tony Finch
Mark Andrews wrote: > In message <52ea4c56.5060...@pernau.at>, Klaus Darilion writes: > > > > Are there any tools/ways to query Bind for the incoming serial? > > rndc zonestatus [class [view]] I think that's a BIND-9.10 feature :-) On 9.9 I think you either have to look at named's logs an

Re: How to query the "incoming" serial of a zone while inline signing

2014-01-30 Thread Klaus Darilion
On 30.01.2014 14:19, Mark Andrews wrote: In message <52ea4c56.5060...@pernau.at>, Klaus Darilion writes: Hi! I use Bind for inline signing between a hidden master and the public slaves. AFAIS Bind maintains 2 serials: one for the incoming unsigned zone (eg. used to match incoming NOTIFYs) and

Re: How to query the "incoming" serial of a zone while inline signing

2014-01-30 Thread Mark Andrews
In message <52ea4c56.5060...@pernau.at>, Klaus Darilion writes: > Hi! > > I use Bind for inline signing between a hidden master and the public > slaves. AFAIS Bind maintains 2 serials: one for the incoming unsigned > zone (eg. used to match incoming NOTIFYs) and one for the outgoing > signed z

How to query the "incoming" serial of a zone while inline signing

2014-01-30 Thread Klaus Darilion
Hi! I use Bind for inline signing between a hidden master and the public slaves. AFAIS Bind maintains 2 serials: one for the incoming unsigned zone (eg. used to match incoming NOTIFYs) and one for the outgoing signed zone. I want to monitor if my name servers are all up2date by monitoring an