RE: forwarding non-domain queries

2025-02-06 Thread Cuttler, Brian R (HEALTH) via bind-users
tanza from both servers, restarted both primary and secondary and since I made those changes almost 6 hours ago have not observed those messages. Sorry, my bad. Thank you for your continued support, Brian From: Greg Choules Sent: Thursday, February 6, 2025 3:18 AM To: Cuttler, Brian R (HEALTH)

RE: forwarding non-domain queries

2025-02-06 Thread Cuttler, Brian R (HEALTH) via bind-users
Greg, Yes, I did remove that stanza and restart the daemon, clean shutdown and restart, not just a reload. Get the messages about the extra NS "." And unable to find root files, restored the stanza, same error. Thanks, Brian From: Greg Choules Sent: Thursday, February 6, 2025

RE: forwarding non-domain queries

2025-02-05 Thread Cuttler, Brian R (HEALTH) via bind-users
warding files for some NYS specific zones. I have yet to tackle my lame delegation issues, a matter of removing obsolete references to another site. That is a completely separate matter though, as the hints issues are on my internal servers and my delegation is for my external/public server. T

RE: cname for apex record

2024-12-24 Thread Cuttler, Brian R (HEALTH) via bind-users
Thanks Jan, Per discussion not supported by all dns servers nor clients. Ultimate solution is a non-DNS based fix to the websites anchors or a url wr-write function to correct for the missing www. Prefix. Thanks, Brian -Original Message- From: bind-users On Behalf Of Jan Schaumann

RE: cname for apex record

2024-12-24 Thread Cuttler, Brian R (HEALTH) via bind-users
:54 AM To: bind-users@lists.isc.org Subject: RE: cname for apex record ATTENTION: This email came from an external source. Do not open attachments or click on links from unknown senders or unexpected emails. Hello again, On Tue, 24 Dec 2024, Cuttler, Brian R (HEALTH) wrote: > ... I think its t

RE: cname for apex record

2024-12-24 Thread Cuttler, Brian R (HEALTH) via bind-users
Apologies, meant to write Stephane and not Stefane. From: bind-users On Behalf Of Cuttler, Brian R (HEALTH) via bind-users Sent: Tuesday, December 24, 2024 10:23 AM To: Greg Choules Cc: bind-users Subject: RE: cname for apex record ATTENTION: This email came from an external source. Do not

RE: cname for apex record

2024-12-24 Thread Cuttler, Brian R (HEALTH) via bind-users
efix, anchors do not. Ged - I just put up the server in the spring, will check and update if we are somehow running an older version. Thanks to all and happy holidays, Brian From: Greg Choules Sent: Tuesday, December 24, 2024 10:00 AM To: Cuttler, Brian R (HEALTH) Cc: bind-users Subject: Re: cna

cname for apex record

2024-12-24 Thread Cuttler, Brian R (HEALTH) via bind-users
dify the source code. I'm looking for guidance on how to point the named domain name, the apex record at the IP addresses provided by the cname name we are using for our webserver. Thanks in advance, Brian Brian Cuttler, System and Network Administration Wadsworth Center, NYS Department of

RE: forwarding non-domain queries

2024-12-19 Thread Cuttler, Brian R (HEALTH) via bind-users
Greg, From: Greg Choules Sent: Wednesday, December 18, 2024 5:04 PM To: Cuttler, Brian R (HEALTH) Cc: bind-users Subject: Re: forwarding non-domain queries ATTENTION: This email came from an external source. Do not open attachments or click on links from unknown senders or unexpected emails

RE: forwarding non-domain queries

2024-12-18 Thread Cuttler, Brian R (HEALTH) via bind-users
his case I queried a .edu address. Is there a way to prevent these errors, or was my query ill thought out or have I simply misconfigured my server? thanks, Brian Dig without trace root@intest:/etc/bind# dig @intest ns1.albany.edu 18-Dec-2024 14:45:04.452 queries: info: client @0x7f

RE: forwarding non-domain queries

2024-12-10 Thread Cuttler, Brian R (HEALTH) via bind-users
Greg, I have a test server I will enable the changes on before I roll them out to my primary and secondary servers. The test server is where we make all tests and updates to zone files. As I configure the forwarders stanza, I will remove the zone for db.cache and test it out. Thanks, Brian

RE: forwarding non-domain queries

2024-12-10 Thread Cuttler, Brian R (HEALTH) via bind-users
Greg, Yes, I do have that but it looks like this (/etc/dns-root is a link to /etc/bind/zones carry over from an older platform) These are the servers I want to use as the forwards for all queries that aren't either local zones or more specific zones in the internal corp network. brian@

RE: forwarding non-domain queries

2024-12-10 Thread Cuttler, Brian R (HEALTH) via bind-users
Nick, Greg, Thank you both, don't deal with that level of detail very often but I love having a clue as to the underpinnings of things. The root priming process is exactly the sort of thing you'd hope a service like this did, and it does! Thanks, Brian From: bind-users On Beha

RE: forwarding non-domain queries

2024-12-10 Thread Cuttler, Brian R (HEALTH) via bind-users
health.ny.gov and ny.gov and its.ny.gov, those will continue to word when I add a forwarders statement for the servers that ny.gov servers for all more generic queries. Many thanks, Brian From: Greg Choules Sent: Monday, December 9, 2024 6:26 PM To: Cuttler, Brian R (HEALTH) Cc: bind-users Subject: Re

forwarding non-domain queries

2024-12-09 Thread Cuttler, Brian R (HEALTH) via bind-users
've missed something. Thanks in advance, Brian Brian Cuttler, System and Network Administration Wadsworth Center, NYS Department of Health Albany, NY 12201 POB 509 brian.cutt...@health.ny.gov<mailto:brian.cutt...@health.ny.gov> 518 486-1697 -- Visit https://lists.isc.org/mailman/l

named hangs when trying to sign a large zone after upgrading to 9.18.28

2024-07-25 Thread Sebby, Brian A. via bind-users
ough it doesn’t have as many clients. I don’t think the new max-records-per-type or max-types-per-name options are involved as we don’t have any cases where we have that many records with the same name. Thanks, Brian -- Brian Sebby (he/him/his) | Lead Systems Engineer E

Re: New BIND releases are available: 9.18.28, 9.20.0

2024-07-23 Thread Sebby, Brian A. via bind-users
at that? We’re on RHEL 8 and 9 for our BIND servers and it looks like the EPEL 8 and 9 versions build successfully, but I want to make sure that I’m not missing something. Thanks! Brian -- Brian Sebby (he/him/his) | Lead Systems Engineer Email: se...@anl.gov<mailto:se...@anl.

RE: rolling my own hints file

2024-07-01 Thread Cuttler, Brian R (HEALTH) via bind-users
A xx.yy.zz..8 . 518400IN NS @ Thank you. Brian From: bind-users On Behalf Of Cuttler, Brian R (HEALTH) via bind-users Sent: Wednesday, June 26, 2024 12:56 PM To: Greg Choules ; David Farje Cc: bind-users ; Hefner, Joseph (HEALTH) Subject: RE: rolling my own hints file ATTENTION

RE: rolling my own hints file

2024-06-26 Thread Cuttler, Brian R (HEALTH) via bind-users
ven me exactly what was needed. Brian From: Greg Choules Sent: Wednesday, June 26, 2024 12:29 PM To: Cuttler, Brian R (HEALTH) Cc: bind-users Subject: Re: rolling my own hints file You don't often get email from gregchoules+bindus...@googlemail.com<mailto:gregchoules+bindus...@googlem

rolling my own hints file

2024-06-26 Thread Cuttler, Brian R (HEALTH) via bind-users
8400 IN A 170.247.170.2 c.root-servers.net. 518400 IN A 192.33.4.12 Thanks for your help and suggestions, Brian Brian Cuttler, System and Network Administration Wadsworth Center, NYS Department of Health Albany, NY 12201 POB 509 brian.cutt...@health.ny.gov<mailto:brian.cutt...@

Re: Question about ISC BIND COPR repositories for 9.16->9.18 ESV transition

2024-06-14 Thread Sebby, Brian A. via bind-users
packages rather than building from source. Brian -- Brian Sebby (he/him/his) | Lead Systems Engineer Email: se...@anl.gov<mailto:se...@anl.gov> | Information Technology Infrastructure Phone: +1 630.252.9935| Business Information Services Cell: +1 630.92

Question about ISC BIND COPR repositories for 9.16->9.18 ESV transition

2024-06-13 Thread Sebby, Brian A. via bind-users
compile BIND myself on Solaris, and it’s so much nicer to just install it from packages on Linux. 😊 ) Thanks, Brian -- Brian Sebby (he/him/his) | Lead Systems Engineer Email: se...@anl.gov<mailto:se...@anl.gov> | Information Technology Infrastructure Phone: +1 630.25

issue with forwarder zones

2024-05-29 Thread Cuttler, Brian R (HEALTH) via bind-users
hing the failed response for some period of time? If so, disable caching for the problematic forwarder zone? Some other issue? If so what might it be, how can I test for it and how do I resolve/work-around it? Thanks in advance, Brian Brian R Cuttler System and Network Administrator Wadsworth C

RE: named fails to start with bind-9.18.0

2024-05-21 Thread Cuttler, Brian R (HEALTH) via bind-users
No idea what OS or product. This is a compile, as in build the binary, or a daemon run issue? For myself I have an Ubuntu base and am running IND 9.18.x. Not locally compiled. I have found journalctl, systemctl, bind logs and /usr/bin/named-checkconf and named-checkzone to be very useful. Fr

Re: HTTP API for bind

2023-05-26 Thread Brian J. Murrell
On Fri, 2023-05-26 at 16:51 +0530, Shailendra Gautam wrote: > Does bind provide any way to manage(add,update,delete) resource > records > with HTTP API, like powerdns? Not TTBOMK. It does have an API for managing RRs but that is using RFC 2136 and not HTTP. > I currently use zonefiles to store D

RE: Reverse lookups not working when Internet connection failed.

2022-11-04 Thread Cuttler, Brian R (HEALTH) via bind-users
bind-users On Behalf Of Cuttler, Brian R (HEALTH) via bind-users Sent: Friday, November 4, 2022 2:09 PM To: Grant Taylor ; bind-users@lists.isc.org Subject: RE: Reverse lookups not working when Internet connection failed. ATTENTION: This email came from an external source. Do not open attachment

RE: Reverse lookups not working when Internet connection failed.

2022-11-04 Thread Cuttler, Brian R (HEALTH) via bind-users
My pointer zones are more like Zone "28.66.136.193.in-addr.arpa.", I've never had that leading "0-" Is that typical? What does it do? -Original Message- From: bind-users On Behalf Of Grant Taylor via bind-users Sent: Friday, November 4, 2022 1:07 PM To: bind-users@lists.isc.org Subjec

filter queries for A records from some clients

2022-03-10 Thread Brian J. Murrell
I am trying to do some testing of an IPv6-only network here using some nat64 to reach the "legacy" :-) IPv4 Internet. My network is currently dual-stack. I have dns64 query mapping working, but I am still seeing some clients that I am trying to test with (that still have IPv4 addresses until the

Re: copy EDNS options to resolver response

2022-02-19 Thread Brian J. Murrell
On Sun, 2022-02-20 at 08:16 +1100, Mark Andrews wrote: > > EDNS is hop by hop. There is no copying by any compliant server. Fair enough. I thought it was a long shot. Cheers, b. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the developme

Re: copy EDNS options to resolver response

2022-02-19 Thread Brian J. Murrell
On Sat, 2022-02-19 at 19:02 +0100, Matus UHLAR - fantomas wrote: > > what's the point of this setup? > BIND can resolve by itself perfectly and you wouldn't rely on 3rd > party > service Except that it cannot do EDE, as I already said in my original message. Cheers, b. signature.asc Descri

copy EDNS options to resolver response

2022-02-19 Thread Brian J. Murrell
I have a BIND9 server configured as a resolver for the local network to forward all requests to 1.1.1.1. Given that that 1.1.1.1 includes (RFC8914) EDE EDNS options in it's responses, can I configure the BIND resolver to forward those EDNS options in it's response to the client? While I know BIND

RE: Add DNS records automatically for static IP's

2021-08-05 Thread Cuttler, Brian R (HEALTH) via bind-users
of my site wiki article if you'd like to see it. Brian -Original Message- From: bind-users On Behalf Of Roberto Carna Sent: Thursday, August 5, 2021 12:19 PM To: ML BIND Users Subject: Add DNS records automatically for static IP's ATTENTION: This email came from an external

RE: configure notify for ixfer?

2021-06-02 Thread Cuttler, Brian R (HEALTH) via bind-users
e made the secondary authoritative and as a result was not notifying for dynamic changes. Thank you very much, Brian -Original Message- From: Mark Andrews Sent: Tuesday, June 1, 2021 9:24 PM To: Cuttler, Brian R (HEALTH) Cc: bind-users@lists.isc.org Subject: Re: configure notify

configure notify for ixfer?

2021-06-01 Thread Cuttler, Brian R (HEALTH) via bind-users
50.156.70#39230 (dai.wadsworth.org): transfer of 'dai.wadsworth.org/IN': IXFR ended Thanks in advance, Brian Brian Cuttler ITG - Information Technology Group, Network and System Administrator Wadsworth Center, NYS Department of Health Empire Stat

Re: forwarding zone setup from a BIND slave (without recursion?)

2021-04-13 Thread Sebby, Brian A. via bind-users
that I’m not aware of. Thanks, Brian -- Brian Sebby (he/him/his) | Lead Systems Engineer Email: se...@anl.gov<mailto:se...@anl.gov> | Information Technology Infrastructure Phone: +1 630.252.9935| Business Information Services Cell: +1 630.921.4305| A

RE: replication time for dynamic records from primary to secondary servers

2021-04-01 Thread Cuttler, Brian R (HEALTH) via bind-users
he incremental update from the DHCP server cause DNS to update the SN and send a notify message? Is there some other mechanism to update the secondary? Thanks, Brian -Original Message- From: Tony Finch On Behalf Of Tony Finch Sent: Wednesday, March 31, 2021 11:43 AM To: Cuttler, Brian R (HE

RE: replication time for dynamic records from primary to secondary servers

2021-03-31 Thread Cuttler, Brian R (HEALTH) via bind-users
w where to find it, but looks to me like the button I want to press. Is that where I should be looking? Thanks, Brian -Original Message- From: bind-users On Behalf Of John Thurston Sent: Tuesday, March 30, 2021 5:00 PM To: bind-users@lists.isc.org Subject: Re: replication time for dynam

replication time for dynamic records from primary to secondary servers

2021-03-30 Thread Cuttler, Brian R (HEALTH) via bind-users
t interval. If someone would help me find the right switch I'd love to update my config. Currently running bind 9.9.4 on Centos 7 (I see an Ubuntu platform in my future). Thanks in advance, Brian ___ Please visit https://lists.isc.org/mailma

unsubscribe

2021-01-06 Thread Michalewicz, Brian R (THIP)
** This communication, including attachments, is for the exclusive use of addressee and may contain proprietary, confidential and/or privileged information. If you are not the intended recipient

"overlay" views

2020-01-20 Thread Brian J. Murrell
I'm really not sure about what the name of this feature I am going to describe would be. I would probably call it an "overlay view". But I am sure there are better names. Imagine I have a BIND 9 server for the following network topology: Network 1 192.168.1.0/24 -

Re: Enforcing minimum TTL...

2018-10-26 Thread Brian Greer
You could setup a DNSMASQ / Unbound service as a front end, which then queried bind. Both of those allow the setting of a minimum TTL (max of 3600 seconds in DNSMASQ). It cannot be done with bind by itself. > On Oct 26, 2018, at 11:41, Grant Taylor via bind-users > wrote: > > On 10/26/2018 01

RE: Question about forwarder zones

2018-10-17 Thread Cuttler, Brian R (HEALTH)
a postmortem should be done to find out why BIND had to be restarted unless you already know. Good hunting! John -Original Message- From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Cuttler, Brian R (HEALTH) Sent: Monday, October 15, 2018 10:27 AM To: bind-users@lists

Question about forwarder zones

2018-10-15 Thread Cuttler, Brian R (HEALTH)
y zones or should employ some other mechanism to help assure I'm hitting the best-forwarders/most productive forwarder zone selection I can. Thank you, Brian Brian Cuttler Network and System Administrator, ITG - Information Technology Group Wadsworth Center, NYS Department of Health Biggs L

Logging ECS information for RPZ rewrites

2018-05-15 Thread Brian Keifer
ing in the query log (or is there?) that indicates that a query was rewritten. Is there any way to get the ECS information in the RPZ log? Failing that, suggestions on how to accomplish this would be greatly appreciated. Thanks! -Brian ___ Please visit htt

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-25 Thread Brian J. Murrell
On Wed, 2018-01-17 at 10:45 -0500, Brian J. Murrell wrote: > I have a BIND (9.9.4)[1] server that runs well most of the time, but > periodically it will start returning SERVFAIL for very high-level > domains such as *.google.com, *.gstatic.com, *.github.com, etc. It > seems to

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-23 Thread Brian J. Murrell
On Tue, 2018-01-23 at 09:53 -0700, Grant Taylor via bind-users wrote: > > Could you try disabling DDNS updates for a little while? That's effectively what I have done. I set up a second server configuration running new zone on a different IP address and pointed the DHCP server at it so that the

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-23 Thread Brian J. Murrell
On Tue, 2018-01-23 at 13:38 +0100, Reindl Harald wrote: > > pretty sure it's possible and likely not much different than the > unbound-sample below which asks a rbldnsd on port 1043 on the same > machine > > stub-zone: > name: "zone-name." > stub-addr: 127.0.0.1@1053 This all falls apart be

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-23 Thread Brian J. Murrell
On Tue, 2018-01-23 at 13:38 +0100, Reindl Harald wrote: > > pretty sure it's possible and likely not much different than the > unbound-sample below which asks a rbldnsd on port 1043 on the same > machine > > stub-zone: > name: "zone-name." > stub-addr: 127.0.0.1@1053 That's the sort of path

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-23 Thread Brian J. Murrell
Here's a new most interesting data point. All of these outages happen right after a DHCP client connect and sends a DDNS update to BIND. It would be an interesting experiment to isolate the zone that receives DDNS updates for the DHCP clients onto a separate server to see if that makes this probl

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-23 Thread Brian J. Murrell
On Mon, 2018-01-22 at 12:45 +, Tony Finch wrote: > > lame-servers is also a log category, and tends to be quite noisy > about > various problems :-) Turns out I do already have lame server logging enabled. I.e.: 20-Jan-2018 12:01:37.053 lame server resolving 'backup-ns.yn.cninfo.net' (in '

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-22 Thread Brian J. Murrell
On Mon, 2018-01-22 at 16:10 +, Tony Finch wrote: > > You should make sure it is enabled, because there are vital clues in > those > log lines :-) But they will only occur if there is some lameness with the ns[1- 4].google.com records and that will already be reported with lame:n in the "fetch

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-22 Thread Brian J. Murrell
On Mon, 2018-01-22 at 12:04 +, Tony Finch wrote: > > The thing to look out for is the minutes before the outage starts - > see > what kind of failures you get. So, taking this approach, looking for the first occurrence of just any one of the names ns[1-4].google.com prior to the A/ querie

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-22 Thread Brian J. Murrell
On Mon, 2018-01-22 at 12:45 +, Tony Finch wrote: > > They'll have a log category of edns-disabled. But if the problem were EDNS, would it be so intermittent and always fixable by rndc reload? > But, looking through the > code, if this is leading to lameness you will also get lame-servers > l

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-22 Thread Brian J. Murrell
On Mon, 2018-01-22 at 12:04 +, Tony Finch wrote: > > That indicates that it has already marked the servers as lame, so the > packet trace isn't going to tell you what caused the lameness. OK. > The thing to look out for is the minutes before the outage starts - > see > what kind of failures

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-20 Thread Brian J. Murrell
OK. I now have named trace logging http://brian.interlinx.bc.ca/named.run.log and a packet dump: http://brian.interlinx.bc.ca/dns-packets.txt that demonstrates how BIND is getting .com referrals from the root servers when doing a query for www.google.com and then doing nothing with those refer

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-19 Thread Brian J. Murrell
On Fri, 2018-01-19 at 15:22 +, Tony Finch wrote: > > You don't have any weird middleboxes between your resolver and the > Internet, do you? I don't believe so. Not entirely sure what "weird middleboxes" refers to in this context though. And by resolver are you referring to my BIND9 server o

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-19 Thread Brian J. Murrell
On Fri, 2018-01-19 at 14:54 +, Tony Finch wrote: > > Those responses look like referrals from the root servers to the .com > servers; Ahhh. Right. That makes sense. > I would expect you to see `named` repeating the queries as it > follows the iterative resolution algorithm. Indeed. I wil

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-19 Thread Brian J. Murrell
On Thu, 2018-01-18 at 17:46 +, Tony Finch wrote: > Brian J. Murrell wrote: > > On Thu, 2018-01-18 at 15:41 +, Tony Finch wrote: > > > > > > The default is 10 minutes - try reducing it and see if the outage > > > becomes shorter. > > > &

Re: intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-18 Thread Brian J. Murrell
On Thu, 2018-01-18 at 15:41 +, Tony Finch wrote: > > Does the time to recovery correspond to the lame-ttl setting? I am not sure. I'm not always aware of when it starts. I guess if I am running a trace level permanently the log would tell me though. > The default > is 10 minutes - try redu

intermittent SERVFAIL for high visible domains such as *.google.com

2018-01-17 Thread Brian J. Murrell
I have a BIND (9.9.4)[1] server that runs well most of the time, but periodically it will start returning SERVFAIL for very high-level domains such as *.google.com, *.gstatic.com, *.github.com, etc. It seems to happen most frequently with Google domains, but I wonder if that is just a reflection o

RE: Clean up dynamic names

2017-02-08 Thread Cuttler, Brian R (HEALTH)
Bob, Thank you, the assurance that I'd understood the defaults and that nsupdate was the correct tool was all that was missing. I executed the update commands and they worked like a charm. Thank you, Brian === The forward table looks like this hr16038             

RE: Clean up dynamic names

2017-02-08 Thread Cuttler, Brian R (HEALTH)
ed forward and reverse records, but text records are different, I just don't know how different. The forward table looks like this hr16038 A 10.57.48.209 TXT "00f8e5793e94da14990f27763448c54a00" Thank you, Brian > -Origin

Clean up dynamic names

2017-02-08 Thread Cuttler, Brian R (HEALTH)
the A, TXT and PTR records is the way to go, but hope for a quicker, less error prone method. Thanks in advance, Brian ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-

CVE-2016-2776 possibly

2016-10-04 Thread Brian Conry
attention of the larger security community. We believe that in the long run this increased scrutiny will help us further increase the security and stability of BIND, but in the near term it does increase the risk of operating an unpatched server. Thanks, Brian Conry ISC Support

DNS views setup help

2016-08-18 Thread Brian Pugh
I am running bind 9.8.2 on a pair of RHEL 6 DNS servers.. One server is the master, one is the slave. My goal is to setup 2 views so that our internal folks can resolve hostnames to internal IP's while still allowing our external customers to resolve from the outside. Both of these servers are exte

RE: Forward record for WWW

2016-05-05 Thread Cuttler, Brian R. (HEALTH)
Stanley, > Are you running DNSSEC? Negative, we are not running dnssec. Brian ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org ht

RE: Forward record for WWW

2016-05-05 Thread Cuttler, Brian R. (HEALTH)
r and I've no idea what. If anyone has any suggestions I'd love to hear them, but with your help the issue I was having has been resolved by restarting the server, rather than reloading the zones files. Many thanks, Brian > -Original Message- > From: Bischof, Ralph F. (MSFC

RE: Forward record for WWW

2016-05-05 Thread Cuttler, Brian R. (HEALTH)
s. wadsworth.org. 300 IN A 199.184.16.22 ; simply not being served, removed until I can figure out why ; 2012-12-10 per ivan wadsworth.org. IN TXT "v=spf1 ptr:wadsworth.org ip4:199.184.28.0/22 ?all" --removing dig output and other already posted information-- Thank you, Brian

RE: Forward record for WWW

2016-05-05 Thread Cuttler, Brian R. (HEALTH)
05 13:30:49 EDT 2016 ;; MSG SIZE rcvd: 369 [euclid] ~ 214> > -Original Message----- > From: Stephane Bortzmeyer [mailto:bortzme...@nic.fr] > Sent: Thursday, May 05, 2016 12:12 PM > To: Cuttler, Brian R. (HEALTH) > Cc: Stephane Bortzmeyer ; bind-users@lists.isc.org > S

RE: Forward record for WWW

2016-05-05 Thread Cuttler, Brian R. (HEALTH)
. > -Original Message- > From: Stephane Bortzmeyer [mailto:bortzme...@nic.fr] > Sent: Thursday, May 05, 2016 11:55 AM > To: Cuttler, Brian R. (HEALTH) > Cc: bind-users@lists.isc.org > Subject: Re: Forward record for WWW > > ATTENTION: This email came from an external source. Do n

Forward record for WWW

2016-05-05 Thread Cuttler, Brian R. (HEALTH)
as to why this isn't resolving for me and how to correct would be appreciated. I checked for resolution using both nslookup and dig. Thank you, Brian ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

RE: dns_update_log shows dynamic entries deleted

2015-06-09 Thread Cuttler, Brian (HEALTH)
the named.conf, though I could have overlooked it, certainly I did nothing to enable such a switch. It's a mystery to me. Thanks, Brian -Original Message- From: dhcp-users-boun...@lists.isc.org [mailto:dhcp-users-boun...@lists.isc.org] On Behalf Of dave c Sent: Tuesday, June 09, 20

RE: bind-users Digest, Vol 2086, Issue 1

2015-04-08 Thread Brian Alaimo
sounds good. thanks -Original Message- From: bind-users-boun...@lists.isc.org [mailto:bind-users-boun...@lists.isc.org] On Behalf Of bind-users-requ...@lists.isc.org Sent: Wednesday, April 08, 2015 10:39 AM To: bind-users@lists.isc.org Subject: bind-users Digest, Vol 2086, Issue 1 Send

RE: problem with static range in dynamic table

2015-04-02 Thread Cuttler, Brian (HEALTH)
Of Simon Hobson Sent: Thursday, April 02, 2015 11:27 AM To: Users of ISC DHCP; bind-users@lists.isc.org Subject: Re: problem with static range in dynamic table "Cuttler, Brian (HEALTH)" wrote: > Except-I set my available address range to 10.57.36.10 - 10.57.39.150, as I > have so

problem with static range in dynamic table

2015-04-02 Thread Cuttler, Brian (HEALTH)
pull the tables, even after the table expiration date. The work-around, which is really not supportable, has been to remove the tables from the slave servers and restart named on them. I am aware that I'm the cause of the problem, just not sure of the solution. Thanks in

error (insecurity proof failed) resolving './DS/IN'

2015-03-23 Thread Brian J. Murrell
Trying to follow an example I found of manually verifying a name's DNSSEC records I did the following: # dig . DNSKEY | grep -Ev '^($|;)' > root.keys # dig +sigchase +trusted-key=./root.keys www.eurid.eu. A That resulted in some errors but more importantly the following in my syslog: Mar 23 08:1

RE: problem loading dynamic zone

2015-01-30 Thread Cuttler, Brian (HEALTH)
Tony, Thank you, I had no idea... I also had no luck moving to the more common directory structure. the security switch named_write_master_zones proved ineffective until I set security to "permissive". Thank you, the link contained the key I needed. Now its DHCP time. Many tha

RE: problem loading dynamic zone

2015-01-29 Thread Cuttler, Brian (HEALTH)
[mailto:fa...@hermes.cam.ac.uk] On Behalf Of Tony Finch Sent: Thursday, January 29, 2015 11:57 AM To: Cuttler, Brian (HEALTH) Cc: Alan Clegg; bind-users@lists.isc.org Subject: RE: problem loading dynamic zone Cuttler, Brian (HEALTH) wrote: > Error: db.dynamic.jnl: create: permission denied

RE: problem loading dynamic zone

2015-01-29 Thread Cuttler, Brian (HEALTH)
t not resolved. Will talk with my manager about the query-source address issue, don't recall if he'd mandated this, or it's a holdover from an earlier config. It is not a setting in the example config that installed with the package. Thank you, Brian -Original Message- F

problem loading dynamic zone

2015-01-29 Thread Cuttler, Brian (HEALTH)
ther people are successfully doing this for it to be a bug (right??). thank you, Brian Cuttler Wadsworth Center Albany, NY # uname -a Linux znix.wadsworth.org 3.10.0-123.6.3.el7.x86_64 #1 SMP Wed Aug 6 21:12:36 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux Installed Packages Name: bind Arch

Re: Metazones or Something Else?

2014-08-06 Thread Brian Cuttler
er [default any; if > missing] > allow-update is a EDNS acl option of subtype update [default none; if missing] > conf is a EDNS which contains other configuration data for a zone > > Mark > > In message <20140805164053.ga11...@fantomas.sk>, Matus UHLAR - fantomas >

Re: Metazones or Something Else?

2014-08-05 Thread Brian Cuttler
On Tue, Aug 05, 2014 at 09:41:14AM -0500, /dev/rob0 wrote: > On Tue, Aug 05, 2014 at 09:31:31AM -0400, Brian Cuttler wrote: > > On Tue, Aug 05, 2014 at 09:21:07AM -0400, Brian Cuttler wrote: > > > rndc addzone sounds like a very interesting tool, but > > > if you w

Re: Metazones or Something Else?

2014-08-05 Thread Brian Cuttler
On Tue, Aug 05, 2014 at 09:21:07AM -0400, Brian Cuttler wrote: > > rndc addzone sounds like a very interesting tool, but > if you want an automated sync, will require something to > read the source config of the master and then write the > requisit slave zone information for the d

Re: Metazones or Something Else?

2014-08-05 Thread Brian Cuttler
o unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users --- Brian R Cuttler brian.cutt...@wadsworth.org Computer Systems Support(v) 518 486-1697 Wadsworth Center

Re: test bind before moving to production

2014-07-03 Thread brian
on't get any output If I run named-checkzone tst.com /var/named/tst.com.zone I get: zone tst.com/IN: loaded serial 1 OK I checked the apache error log and it is empty. Brian On 07/03/2014 10:39 AM, Jeremy C. Reed wrote: On Thu, 3 Jul 2014, brian wrote: I'm new to bind. I want to be ab

test bind before moving to production

2014-07-03 Thread brian
ction. At the domain register I'll either point to this dns server or host the dns at the domain register and point the A record to the IP.* *Brian* ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bin

Re: Clients Matching Multiple Views

2014-04-10 Thread Brian Cuttler
ostmaster, Security, and Timelord! > > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.i

Re: script - automatic change A record

2013-11-26 Thread Brian Cuttler
; fi > sleep 60 > done > > > > -- > Mark Andrews, ISC > 1 Seymour St., Dundas Valley, NSW 2117, Australia > PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org > _______ > Please visit https://lists.isc.org/mailman/listin

Re: script - automatic change A record

2013-11-25 Thread Brian Cuttler
scribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users --- Brian R Cuttler brian.cutt...@wadsworth.org Computer Systems Support(v) 518 486-1697 Wadsworth Center

Re: Bind logging

2013-10-11 Thread Brian Cuttler
rg/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users --- Brian R Cuttler brian.cutt...@wadsworth.org Computer Systems Support(v) 518 486-1697

Re: weird perfmonce BIND version 9.6

2013-09-25 Thread Brian Cuttler
records or explicitely allowing recursive queries on our internal and private network. On Wed, Sep 25, 2013 at 04:23:57PM -0400, Alan Clegg wrote: > > On Sep 25, 2013, at 3:23 PM, Brian Cuttler wrote: > > > In our switch from BIND 8.3.3 to 9.8.2 we failed to add the now > >

Re: weird perfmonce BIND version 9.6

2013-09-25 Thread Brian Cuttler
t https://lists.isc.org/mailman/listinfo/bind-users to > unsubscribe from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users --- Brian R Cuttler brian.cutt...@wadsworth.org Com

Re: BIND 9.9.4 is now available. Do we still need RRL & RPZ patches?

2013-09-19 Thread Brian Conry
ory in our knowledge base... I can confirm that those patches do include several minor functionality differences in addition to potentially significant performance improvements. I apologize for the confusion. Thanks, Brian ___ Please visit https://lists.isc.org/m

Re: BIND 9.9.4 is now available. Do we still need RRL & RPZ patches?

2013-09-19 Thread Brian Conry
ame syntax. Thanks, Brian Conry ISC Support ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users

Re: Can anyone help me resolve this named failure report

2013-09-17 Thread Brian Cuttler
m this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users > ___ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-u

Re: Problem with "authoritative answer"

2013-09-13 Thread Brian Cuttler
new mount name, remains to be seen... Thank you, Brian On Fri, Sep 13, 2013 at 12:02:13PM -0700, Chris Buxton wrote: > On Sep 11, 2013, at 8:11 AM, Brian Cuttler wrote: > > We have remapped some of our DNS clients to point to another > > DNS resolver, one that we do not co

Problem with "authoritative answer"

2013-09-11 Thread Brian Cuttler
thanks in advance, Brian --- Brian R Cuttler brian.cutt...@wadsworth.org Computer Systems Support(v) 518 486-1697 Wadsworth Center(f) 518 473-6384 NYS Department of Health

Re: bind 2.1a3 on centos 6.4

2013-06-24 Thread Brian Cuttler
Chris, Looks like 3.0a2-1 understands views statement. Not sure if there is a newer version, but this will do the deed. thank you, Brian On Mon, Jun 24, 2013 at 10:21:17AM -0700, Chris Buxton

Re: bind 2.1a3 on centos 6.4

2013-06-24 Thread Brian Cuttler
ferences. But this also does not check A/PTR pairs, check for illegal characters "_" etc. Oh - the purpose of having a test server for the database is because we've accidently dropped zones by causing syntax errors, by the time we've run our checks we know we are passing val

Re: bind 2.1a3 on centos 6.4

2013-06-24 Thread Brian Cuttler
Thank you, that explains a lot. Had assumed that the one nslint # yum found would be at least somewhat current. Will see if I can't find a newer one to install. thank you, Brian On Sat, J

  1   2   >