DNSSEC: validation with "dnssec-must-be-secure" AND "dnssec-lookaside" fails

2015-02-26 Thread Robert Senger
Hi all, I am struggling with weird behaviour of bind9 acting as authenticating resolver, when querying DNSSEC enabled domains that are using DLV. My registrar is still unable to sign DS records. Everything works fine if only "dnssec-lookaside auto" option is set in the resolver's named.conf.optio

Re: Have question using bind9 for local dns proxy

2015-02-26 Thread Tony Finch
Junyoung Park wrote: > > but i want to send query to clients original dns server instead of root ns. > (if client pc DNS server set 8.8.8.8, i want to send 8.8.8.8 instead > of root dns servers) > (i can't use forward / forwarders options because clinets PC DNS > server setting is different each o

Re: order of masters IP addresses in slave/stub zone?

2015-02-26 Thread Barry Margolin
In article , Hillary Nelson wrote: > I was asked to add some backup master IP addresses to a slave zone file for > some HCP system, but those IPs not active and can't do zone transfer until > system failover. > > My question is, does the order of the master ip list matters, so named > always tr