Re: BIND doesn't listen to other loopback addresses

2025-07-06 Thread Michael De Roover
On Monday, July 7, 2025 1:54:41 AM CEST Bagas Sanjaya wrote: > That override won't persist across reboots, though, in my case (I'm using > NetworkManager). > > Thanks. ...-- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this

Re: BIND doesn't listen to other loopback addresses

2025-07-06 Thread Michael De Roover
e proven wrong, but this sure seems like just PEBKAC. If not there, sure maybe here. Prove it. -- Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org Activisme is pas nuttig, wanneer het kan bereiken wat het wenst te bereiken, binnen de limieten van het huidige systeem. De res

Re: BIND doesn't listen to other loopback addresses

2025-07-05 Thread Michael De Roover
On Sunday, July 6, 2025 4:40:37 AM CEST Michael De Roover wrote: > Omit 127.0.0.53, like so: > > options { > listen-on { > 192.168.0.155; > }; > }; > > Works fine for me using IP addresses 192.168.10.{4-6}, on Alpine edge. You > can keep

Re: BIND doesn't listen to other loopback addresses

2025-07-05 Thread Michael De Roover
#x27;s move on. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org Activisme is pas nuttig, wanneer het kan bereiken wat het wenst te bereiken, binnen de limieten van het huidige systeem. De rest is geschiedenis. -- v...@workstation.vm.ideapad.la

Re: BIND doesn't listen to other loopback addresses

2025-07-05 Thread Michael De Roover
}; }; Works fine for me using IP addresses 192.168.10.(4-6}, on Alpine edge. You can keep v6 none. One of the more basic options that's expected to be stable across all distributions regardless. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.e

Re: Dns tunnel detection/prevention

2025-05-23 Thread Michael De Roover
der "chaos engineering". > > Dnstap offers application-level logging (DNS is an application protocol > along with a wire protocol) and you can combine that with e.g. fail2ban > and/or RPZ, or other things if it keeps you up at night and you like > picking the legs of

Re: Dns tunnel detection/prevention

2025-05-22 Thread Michael De Roover
hat software in the first place. Which in itself is a multifaceted policy question. (Apologies if this is to be sent twice, I was working on my mail servers as I wrote this message.) -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visi

Re: Dns tunnel detection/prevention

2025-05-22 Thread Michael De Roover
hat software in the first place. Which in itself is a multifaceted policy question. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the develop

Re: Migration to inline-signing

2025-05-17 Thread Michael Richardson
Crist Clark wrote: > Tired of looking at the log messages warning me that inline-signing > will be the default in 9.20. I want to convert my 9.18 to using > inline-signing. Right now all of the zones use dnssec-policy and are > dynamic. My experience was that it was best to do bu

Re: DNSVIZ errors

2025-05-16 Thread Michael De Roover
Preposterous. PREPOSTEROUS!!! Expect no meaningful response other than that, not from here. Such a high horse mentality, utterly diabolical! Michael De Roover > On 16 May 2025, at 03:53, akritrim® Intelligence™ > wrote: > > i didn’t receive your reply but saw this on list

Re: My Introduction and current issues -

2025-05-09 Thread Michael De Roover
On Saturday, 10 May 2025 01:35:28 CEST Greg Choules via bind-users wrote: > Third, use tcpdump to capture port 53. Do this to a file, then look at it > offline in Wireshark. (Michael just beat me to that tip). Check how queries > are arriving into BIND and what it does with them. Particul

Re: My Introduction and current issues -

2025-05-09 Thread Michael De Roover
On Saturday, 10 May 2025 01:18:17 CEST Michael De Roover wrote: [...] I do remember writing a reply that got lost while drafting my previous email, but I don't remember what exactly it is. I do, however, remember its contents, somewhat. I'll just rewrite it in reply to.. this, I gues

Re: My Introduction and current issues -

2025-05-09 Thread Michael De Roover
e .default-zones file is > commented out. > > If you need other info about my configuration and setup, please feel > free to ask and I'll do my best to provide it. > > Thank you all so much and I look forward to learning from you. > > Regards, > Arnold -- Met vr

Re: Massive increase of SERVFAIL after April 28th 2025.

2025-05-01 Thread Michael Richardson
Ondřej Surý wrote: >> dig +short +nsid version.bind. txt ch @dns4.p08.nsone.net > This needs to be this: ^^^ p> You missed @ and thus you asked your local resolver. Yes, you are right. Bad on me I actually have a script that does this, but I transcribed it for posting. I get: obiwan-

Re: Massive increase of SERVFAIL after April 28th 2025.

2025-05-01 Thread Michael Richardson
Rob McEwen via bind-users wrote: > I strongly suspect that this was caused (even if indirectly?) by the MASSIVE > and many-hours-long power outages in Europe, mainly in Spain and > Portugal. That started on April 28, 2025, at approximately 6:33 a.m. Eastern > Time (ET) - and the

Re: Massive increase of SERVFAIL after April 28th 2025.

2025-05-01 Thread Michael Richardson
_.,-*~'`^`'~*-,._.,-*~'`^`'~*-, > Vincent S. Cojot, Computer Engineering. STEP project. _.,-*~'`^`'~*-,._.,-*~ > Ecole Polytechnique de Montreal, Comite Micro-Informatique. _.,-*~'`^`'~*-,. Bonjour! Elbows Up. -- Michael Richardson. o O ( IPv6 IøT c

Re: DNSVIZ errors

2025-04-21 Thread Michael De Roover
x27;t going to like customers who act like that. Those are paid to help you and to be nice to you, yes, but don't be surprised if it diminishes the quality of the help you are to receive. Do consider it, in any case. N.B.: A trademark office allowed you to get a trademark o

Re: DNS hiccups

2025-04-15 Thread Michael De Roover
Same here, A returns 147.75.40.150 while returns nothing. MX has records to Microsoft, as addressed by Sten. My chain is recursive to Cloudflare from vantage points at Hetzner, and from there follows the usual public chain. *v...@ideapad.lan* [*~*] $ dig vodafone.com ; <<>> DiG 9

Delivery error (Ref: Survey on the impact of software regulation on DNS systems)

2025-04-15 Thread Michael De Roover
xmagic.com (fallback) 168.119.103.78 (/32) AS24940 (Hetzner) Falkenstein, Germany -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org--- Begin Message --- This is the mail system at host nixmagic.com. I'm sorry to have to inform you that your messa

Re: Survey on the impact of software regulation on DNS systems

2025-04-09 Thread Michael De Roover
Hi Peter, I really appreciate this discourse too. With what's happening in the world now and with this particular executive order affecting even something as niche as DNS, I like how it offers a vessel to have this public discussion. On Tuesday, April 8, 2025 7:40:44 PM CEST Peter 'PMc' Much w

Re: Survey on the impact of software regulation on DNS systems

2025-03-27 Thread Michael De Roover
somewhat inaccurate in retrospect, but.. oh well. Benefit of hindsight I guess. It worked at the time, so back then it should've been good enough. Either way, I'm glad that such Expert Groups exist. If they can offer advisory to the politicians themselves and bicker among each other t

Re: Custom DNS Filtering Plugin in BIND 9

2025-03-20 Thread Michael De Roover
On Wednesday, March 19, 2025 4:05:29 PM CET you wrote: > Michael, > > you can hardly create a static list from all of the domains that can > possibly exists. > > I do understand the usefulness of dynamic classification. > > There’s just not a straightforward interface f

Re: Custom DNS Filtering Plugin in BIND 9

2025-03-19 Thread Michael De Roover
in general, the gateway or a forward proxy server may be able to give better results (but encrypted traffic would be a pain to deal with). -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/listinfo/bind-

Re: Custom DNS Filtering Plugin in BIND 9

2025-03-19 Thread Michael De Roover
Negative cache TTL 1 minute IN NS LOCALHOST. ; Examples example.net IN CNAME localhost. Note that the public domain name records to be redirected via RPZ cannot have a trailing dot. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com

Some operational questions about TSIG / XoT

2025-03-07 Thread Michael De Roover
o the operator of this network has decided to add a second DNS server." Your work on the ARM is amazing Suzanne, and indeed we/they are :) -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org [1] https://www.ietf.org/rfc/rfc9103

Re: Where are ISC docs for log file codings?

2025-03-03 Thread Michael Richardson
Brett Delmage via bind-users wrote: > Specifically for me now that's the query log including the flags. But it > could be other log files too at times. I am running DNSSEC and primary, > secondary, and internal resolving servers so many logs are of interest at > different times. I

Re: xfer-in: Transfer status: timed out (selective failures)

2025-02-25 Thread Michael De Roover
ant here, but it's about as much head-scratching as I can partake in right now. Pretty much just shooting in the dark I suppose. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/listinfo/bind-user

Re: IPv6 Geolocation per /64

2025-02-18 Thread Michael Richardson
There is also https://www.rfc-editor.org/info/rfc9632. This document specifies how to augment the Routing Policy Specification Language (RPSL) inetnum: class to refer specifically to geofeed comma-separated values (CSV) data files and describes an optional scheme that uses the Resource Pub

Re: IPv6 Geolocation per /64

2025-02-18 Thread Michael De Roover
deo about that. https://www.youtube.com/watch?v=vh6zanS_epw[1] (Long story short, it's MaxMind's secret sauce and therefore a trade secret) -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org [1] https://www.youtube.com/watch?v=vh

Re: IPv6 Geolocation per /64

2025-02-18 Thread Michael De Roover
regardless, which uh... I don't want to even entertain the idea of for my business, thank you very much! Business here, personal there. Overlap yes, but only up to a point. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https

Re: IPv6 Geolocation per /64

2025-02-18 Thread Michael De Roover
On Tuesday, February 18, 2025 10:06:35 PM CET Peter 'PMc' Much wrote: > On Tue, Feb 18, 2025 at 09:51:51PM +0100, Michael De Roover wrote: > ! On Tuesday, February 18, 2025 9:38:58 PM CET Peter 'PMc' Much wrote: > ! > Then they make a business of selling my own info

Re: IPv6 Geolocation per /64

2025-02-18 Thread Michael De Roover
On Tuesday, February 18, 2025 8:48:15 PM CET Michael De Roover wrote: > I find it a shame that this record is no longer in use. GeoIP is anything > but accurate, and GPS data is not reasonable to request from servers. Not > like you can just hook up a GPS receiver to a VPS. Even from i

Re: IPv6 Geolocation per /64

2025-02-18 Thread Michael De Roover
eir API is. ipinfo.io has been good for a long time, but their commercialization efforts made me look elsewhere. That's how iplist.cc came to be in this guy's operations. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://list

Re: BIND DNS Server on Windows

2025-02-11 Thread Michael De Roover
in your environment and why. Then progressively address them as they happen. Helps to establish rationale for what you build and why. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/listinfo/bind-users t

Re: BIND DNS Server on Windows

2025-02-11 Thread Michael De Roover
heart). As with everything engineering, I suppose it's a variety of compromises. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org [1] https://www.youtube.com/watch?v=6bicunweBAQ -- Visit https://lists.isc.org/mailman/listinfo/

Re: BIND DNS Server on Windows

2025-02-10 Thread Michael De Roover
r option you choose in the end, I wish you good luck :) Best regards, Michael -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/

Re: BIND DNS Server on Windows

2025-02-09 Thread Michael De Roover
be a physical limit. Perhaps it's possible to mitigate this with hostapd voodoo, but I have yet to master that myself. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubs

Re: Primary/Secondary

2025-02-09 Thread Michael De Roover
On Sunday, February 9, 2025 12:54:53 PM CET Michael De Roover wrote: > Perhaps this would be as good of an email as any to express that I once > walked the corridors with this teacher- Not sure to which extent this will be necessary, but by this I meant my own teacher Gitte. I should

Re: Primary/Secondary

2025-02-09 Thread Michael De Roover
any peers leave after the first month because they thought it was little more than LAN parties. That is _not_ what this field is about! It's about network engineering first, entertainment four-hundred-and-fifteenth! Anyway, (forwarded) rants aside.. that's what it&#x

Re: Primary/Secondary

2025-02-08 Thread Michael De Roover
lding, alongside burnt libraries), perhaps we are now in an ideal position to come back to this issue with the benefit of hindsight. I for one look forward to seeing what people from various parts of the world have to say about it. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagi

Re: Primary/Secondary

2025-02-08 Thread Michael De Roover
ondary. How ironic that this is probably the most suitable term here. Long story short, context matters. Paul Vixie made the context pretty clear, as an authoritative figure. Perhaps we were mistaken to tie slavery into this discussion in the first place. Or perhaps the designers at the time were mist

Re: Survey on the impact of software regulation on DNS systems

2025-02-01 Thread Michael De Roover
ve seen a lot in both tablets and laptops, and that kind of hostile engineering is something I strongly object to. Heh, maybe I should just go ahead and do that myself too. Electronics, sysadmin, development... shit never ends, does it. -- Met vriendelijke groet, Michael De Roover Mail: i..

Re: Master/Slave

2025-01-31 Thread Michael De Roover
.##; 192.168.##.##; }; // Masters // Source: https://www.zytrax.com/books/dns/ch7/masters.html masters satellite { 192.168.##.#; }; Hope this helps. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: michael.de.roover.eu.org -- Visit https://lists.isc.org/mailman/li

Re: Master/Slave

2025-01-31 Thread Michael De Roover
r everything else. Additionally, this is separated into 3 servers for the network I'm thinking of.. with 1 master and 2 slaves. It's really just a matter of slicing. Your given server can certainly be a master for one slice, and a slave for another. -- Met vriendelijke gr

Re: Survey on the impact of software regulation on DNS systems

2025-01-29 Thread Michael De Roover
f that is an undesirable status quo, then perhaps the matter of actual collaboration is what deserves foreground attention. For a long time, I've considered the IETF's standards in particular, to be the "laws of the internet". Perhaps it wouldn't be a bad idea to

Re: Executive Order 14144 - encrypted DNS

2025-01-29 Thread Michael De Roover
On Wednesday, 29 January 2025 11:40:50 CET Michael De Roover wrote: > Granted, for my own domains, doing zone transfers in plain TLS over a VPN > connection like WireGuard has never failed me either. TCP, I meant TCP! Goodness gracious, doing an all-nighter was not a good idea. -

Re: Executive Order 14144 - encrypted DNS

2025-01-29 Thread Michael De Roover
On Wednesday, 29 January 2025 11:07:51 CET Stephen Farrell wrote: > Hiya, > > On 29/01/2025 02:58, Michael De Roover wrote: > > > I appreciate the confirmation of this being about DoT/DoH > > > Do we have any opinions as to whether the document (which > I've

Re: Executive Order 14144 - encrypted DNS

2025-01-28 Thread Michael De Roover
the Council) too, but they tend to separate that into their press releases. It's interesting to be able to peek behind the curtains at how each of these world-leading governments approaches this PR matter. -- Met vriendelijke groet, Michael De Roover Mail: i...@nixmagic.com Web: micha

Re: Executive Order 14144 - encrypted DNS

2025-01-28 Thread Michael De Roover
to make? If so, to what extent? And if authenticity is to be enforced from those with authoritative servers, to circumvent that problem if identified as such, wouldn't that just move the ball for ISP's to employ more intrusive methods to comply with the law? -- Met vriendelijke

Re: Docker Compose Setup with ISC/Bind9 Image

2024-12-27 Thread Michael Richardson
If it doesn't work without docker, then it probably won't work with Docker. Probably all the clue you need is in the log files. Did you read them? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works

Re: Undelegating a Signed Subdomain

2024-12-11 Thread Michael Richardson
1. I assume example.com is signed. 2. I don't understand why you can't just remove the NS records and fold the foo.bar.example.com data in. 3. After some interval of TTL, you can delete the DS records. If bar.example.com is served by the same server (I assume not: because if it was, why would

RE: dnnsec ipv6 reverse zone configuration

2024-11-01 Thread Michael Martinell via bind-users
Thanks! This did the trick for me, once I built the missing zone and got the DS records in the correct spots everything is now reporting green. Michael Martinell Network/Broadband Technician Interstate Telecommunications Coop., Inc.-Original Message- From: Mark Andrews Sent: Wednesday

dnnsec ipv6 reverse zone configuration

2024-10-30 Thread Michael Martinell via bind-users
file "reverse/2607.d600.9000.300.rev"; dnssec-policy itc-no-rotate; inline-signing yes; }; Any idea on what I need to do to resolve this issue? Michael Martinell Network/Broadband Technician Interstate Telecommunications Coop., Inc. 312 4th Street West * Clear Lake, SD 57226 P

Re: DNSSEC with views and shared zone files

2024-10-19 Thread Michael Richardson
Bowie Bailey via bind-users wrote: > The first issue is that my server uses a few views to give different IPs > based on which network the request comes from.  I found that if I point the > zones in the different views to the same key directory, there are no errors > and all vie

Re: Updated Docker images (9.18, 9.20, 9.21) - now based on Alpine Linux

2024-08-27 Thread Michael Dahlberg
On Tuesday, August 27th, 2024 at 4:21 AM, Ondřej Surý wrote: > the Docker images have been updated to use Alpine Linux as the base image > and the bind9 binaries are now compiled from the source while building the > Docker images. This is more in-line with the expected Docker (Podman) > workfl

Re: SERVFAIL error during the evening

2024-06-26 Thread Michael Batchelder
ng that you should upgrade). > How can we ensure that this is a network-level issue? Through standard network troubleshooting techniques, such as packet captures and firewall log inspection. Beyond that, you'll need to inquire elsewhere, as I indicated at the top of this message, as this is a list abo

Re: SERVFAIL error during the evening

2024-06-24 Thread Michael Batchelder
>> Hello Michael >> Thank you for your response. Here is a pcap file and some logs. > > Hello Sami, > > Your pcap shows your resolver making thousands of queries that get > no responses (or at least the pcap does not contain them). There's > not much I can say,

Re: SERVFAIL error during the evening

2024-06-24 Thread Michael Batchelder
> Hello Michael > Thank you for your response. Here is a pcap file and some logs. Hello Sami, Your pcap shows your resolver making thousands of queries that get no responses (or at least the pcap does not contain them). There's not much I can say, beyond that this does not app

Re: qname minimization: me too :(

2024-06-21 Thread Michael Batchelder
> Yes, sure. I grabbed three typical cases to analyze further, and > currently trying to understand the proceedings - unsuccessfully, up > to now. :( > > Case 1: > --- > Jun 19 17:42:12 conr named[24481]: lame-servers: >info: success resolving '26.191.165.185.in-addr.arpa/PTR' >

Re: can I provide invalid HTTPS values for testing?

2024-06-19 Thread Michael Richardson
Mark Andrews wrote: > Named and nsupdate validate input for types they know about (both text > and wire). You would have to use versions that are not HTTPS aware and > use unknown type format. So, he could code it in Perl or Python or something which had a dynamic DNS library. Bind

SERVFAIL error during the evening

2024-06-13 Thread Michael Batchelder
along with the BIND log segment which contains the failed queries. Michael Batchelder ISC Support -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.

named -C, ...: Re: dnssec-policy default - where/how to determine what all its settings are?

2024-06-07 Thread Michael Paoli via bind-users
ation to reflect that: > https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/9092/diffs > > Petr Špaček > Internet Systems Consortium > > On 06. 06. 24 21:01, Michael Paoli via bind-users wrote: > > Ah, thanks! > > > > Yeah, that's what I

Re: dnssec-policy default - where/how to determine what all its settings are?

2024-06-06 Thread Michael Paoli via bind-users
isc.org/isc-projects/bind9/-/blob/main/doc/misc/dnssec-policy.default.conf > > On Thu, Jun 6, 2024 at 8:19 AM Michael Paoli via bind-users > wrote: >> >> dnssec-policy default - where/how to determine what all its settings are? >> Documentation >> doc/bind9-do

dnssec-policy default - where/how to determine what all its settings are?

2024-06-06 Thread Michael Paoli via bind-users
dnssec-policy default - where/how to determine what all its settings are? Documentation doc/bind9-doc/arm/reference.html#dnssec-policy-default https://bind9.readthedocs.io/en/v9.18.27/reference.html#dnssec-policy-default says: A verbose copy of this policy may be found in the source tree, in the fi

Problem with a certain domain

2024-06-04 Thread Michael Batchelder
Thomas, I just incorrectly wrote: > So at minimum add "icmp and arp" to your filter expression. I did not mean to use the logical "and". Your minimum filter should be something like: "src port 53 or icmp or arp" Sorry for the confusion, Michael

Problem with a certain domain

2024-06-04 Thread Michael Batchelder
limit the amount of information you provide to those who are trying to help you or make them infer information. It's fine to mention only certain packets in an email, but put the full packet capture on a public resource somewhere accessible. Michael Batchelder ISC Support -- Visit https:

Problem with a certain domain

2024-05-31 Thread Michael Batchelder
(or some level of failure in between all queries and the ones for that one domain)? And at that time, can you successfully query from the same system using a public resolver (e.g. "dig @9.9.9.9 s1._domainkey.mg-esp-prod-eu-eu.mallorcazeitung.es TXT")? And do you have BIND's

Re: Problem upgrading to 9.18 - important feature being removed

2024-02-27 Thread Michael Richardson
Matthijs Mekking wrote: > As the main developer of dnssec-policy, I would like to confirm that > what has been said by Michael and Nick are correct. Cool. > - When migrating to dnssec-policy, make sure the configuration matches > your existing keys. Is there a way

Re: Problem upgrading to 9.18 - important feature being removed

2024-02-26 Thread Michael Sinatra
actices. (It also provides some level of job security :-D.) But in this case, I think the BIND developers did a good job ensuring there was a way to create policies that integrate well with key-management regimes external to BIND. michael -- Visit https://lists.isc.org/mailman/listinfo/b

Re: tsig key not found

2024-01-17 Thread Michael Lipp
https://bind9.readthedocs.io/en/v9.16.42/advanced.html#errors). As it is, I was too focused on finding a problem with defining a key at all. Maybe pointing out this would be an acceptable issue... Thanks again!  - Michael Am 17.01.24 um 18:26 schrieb Anand Buddhdev: On 17/01/2024 18:18, Michael

tsig key not found

2024-01-17 Thread Michael Lipp
6.42/reference.html#key-statement-definition-and-usage>. It is defined globally and should be available in all views (and the output from tsig-list confirms this). As this has been rejected as an error within minutes (https://gitlab.isc.org/isc-projects/bind9/-/issues/4539) it must be a user error.

Re: How should I configure internal and external DNS servers

2023-11-05 Thread Michael Richardson
Greg Choules via bind-users wrote: > What would be better (IMHO) is for you to keep "example.com" as your > external zone in an external (hopefully in a DMZ) primary server, > serving the world with public addresses they need to reach, and > internally create a new zone - "interna

Re: How should I configure internal and external DNS servers

2023-11-04 Thread Michael Richardson
Given VPNs, RemoteAccess and the like, I strongly recommend against split-DNS configurations. They were great ideas in 1993, when all sites were concave, but that's just not the case anymore. Instead, I recommend having a sub-zone, "internal.example.com", or some other convenient name. Put a zo

RE: 9.18 BIND not iterated over all authoritative nameservers

2023-10-30 Thread Michael Martinell via bind-users
, but it will take a large company to push them to do so. Michael Martinell Network/Broadband Technician Interstate Telecommunications Coop., Inc. From: bind-users On Behalf Of Paul Stead Sent: Saturday, October 28, 2023 11:35 AM Cc: bind-users@lists.isc.org Subject: Re: 9.18 BIND not iterated

9.18 BIND not iterated over all authoritative nameservers

2023-10-27 Thread Michael Martinell via bind-users
7#53(2607:d600:9000:330:75:102:160:227) ;; WHEN: Fri Oct 27 09:56:31 CDT 2023 ;; MSG SIZE rcvd: 125 [root@brkr-dns2 bind-9.18.12]# Michael Martinell Network/Broadband Technician Interstate Telecommunications Coop., Inc. 312 4th Street West * Clear Lake, SD 57226 Phone: (605) 874-8313 michael

Re: Bind forgets my changes with nsupdate

2023-10-08 Thread Michael Richardson
lves the problem if interactive. Cron running a week later usually works) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: Bind forgets my changes with nsupdate

2023-10-06 Thread Michael Richardson
In general, you don't want to mix dynamic update zones with ones that you want to edit by hand. I see that you are doing manual DNSSEC signing in your cron job. Your choices are: a) do everything with dynamic update, and turn on automatic DNSSEC management in bind9. b) do your DNSSEC signing

Re: Hyperlocal RFC8806 Root Mirror

2023-09-27 Thread Michael Richardson
Silva Carlos wrote: > On server A I configured HyperLocal. On Server B I did NOT configure > HyperLocal. > I ran the command "dig @localhost EXAMPLES" on both servers. > EXAMPLES: blabla.sdf.dd or teste.com.eroterrter or world.nanana > Problem: Both Servers report that "Quer

Re: BIND 9.18 unable to successfully transfer zone from axfrdns primary

2023-08-31 Thread Michael Sinatra
e Question section empty." There are some older implementations out there that don't do this correctly. I have a vendor supported IPAM implementation, where I have gone back to the vendor and quoted the above, and they have fixed the implementation. michael On 8/31/23 17:34, Ian Bobb

Re: Master file permission denied

2023-06-29 Thread Michael Richardson
Mark Andrews wrote: > where wrong and wouldn’t normally be that way. Something or someone > changed them. It may have happened again. We can’t see what you see And, AppArmor can turn things into permission denied, which are rather mysterious. So, I'd ask for dmesg output too. sign

dnssec not automatically updating on 1 server

2023-06-15 Thread Michael Martinell via bind-users
itctel.com.zone.jbk /var/named/forward/itctel.com.zone.new /var/named/forward/itctel.com.zone.signed.jnl Michael Martinell Network/Broadband Technician Interstate Telecommunications Coop., Inc. 312 4th Street West * Clear Lake, SD 57226 Phone: (605) 874-8313 michael.martin...@itccoop.com www.itc-w

Re: Reverse Policy Zone to make MS Azure stuff work?

2023-04-13 Thread Michael De Roover
}; }; My apologies for not double-checking earlier, but I think this should be everything. -- Met vriendelijke groet / Best regards, Michael De Roover signature.asc Description: This is a digitally signed message part. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from

Re: Reverse Policy Zone to make MS Azure stuff work?

2023-04-13 Thread Michael De Roover
e, not the actual domain on the internet. The only major issue I've been facing with this so far, is that AXFR to secondary and tertiary name servers has some issues, and at least Windows 10 Home will query those when the primary name server does not give a satisfactory answer. -- Met v

Re: Bind listener to an IPv6 from AnyIP subnet

2023-03-13 Thread Michael Richardson
m...@at.encryp.ch wrote: > Regarding the usage of [::] - due to usage of firewall I am able to > block connections to the 53/udp and 53/tcp which are not coming to > specific IP addresses or ranges, I do not need such filtering > functionality within bind itself. Bind doesn't list

Re: Bind listener to an IPv6 from AnyIP subnet

2023-03-13 Thread Michael Richardson
Serg via bind-users wrote: > As an alternative approach I have tried to run with a configuration > "listen-on-v6 { any; }", but it does behave in a way I need - it binds > separate socket for each discovered IP address rather wildcard address > of [::]. Bind needs to bind a new s

Re: Something other than port 53 is blocking the LAN based BIND9 Servers

2023-03-13 Thread Michael Richardson
Mike Lieberman wrote: > The newer router blocks my local BIND servers (ONLY not clients using > downstream servers) from receiving anything from the Internet. OUR BIND > servers still have the local networks, but nothing else. Your explanation is rather obtuse, but I think you mean t

Re: converting from opendnssec/openhsm?

2023-01-27 Thread Michael Richardson
Can you share a bit about why you want to get out of using opendnssec/openhsm? I would regard this as an opportunity to test key rollover with your parent zone :-) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works

Re: Finding dnssec validation failures in the logs

2023-01-24 Thread Michael Richardson
John Thurston wrote: > On a resolver running ISC BIND 9.16.36 with "dnssec-validation auto;" I am > writing "category dnssec" to a log file  at "severity info;"  When I look in > the resulting log file, I'm guessing that lines like this: > validating com/SOA: got insecure respon

Re: DNSSEC With Primary Hidden - Clarifying Question from Documentation

2023-01-17 Thread Michael Richardson
E R wrote: > I am planning on implementing the current version of BIND to replace the > aging, undocumented authoritative servers I inherited. I want to hide the > primary server on our internal network and have two secondary servers be > publicly available. While reading the DN

Re: General DNS / SPF question

2023-01-09 Thread Michael Muller via bind-users
r, president Montague WebWorks 20 River Street, Greenfield, MA 413-320-5336 http://MontagueWebWorks.com Powered by ROCKETFUSION On 1/7/2023 6:24 PM, G.W. Haywood via bind-users wrote: Hi there, On Sat, 7 Jan 2023, Michael Muller wrote: This is my first time posting here, and I'm not sure if i

General DNS / SPF question

2023-01-07 Thread Michael Muller via bind-users
Hello everyone, This is my first time posting here, and I'm not sure if it's the right place or not to ask my question. This is a general DNS question, specifically, I think, SPF. (Btw, I do use Bind in my system, so that's why I'm here.) I host email using SmarterMail, and all 400+ customer

Re: How do subdomains get discovered by adversaries?

2022-12-21 Thread Michael De Roover
On Thu, 2022-12-22 at 05:19 +, Michael De Roover wrote: > Hello, > > I have been running BIND 9 on my external and internal networks for a > few years now -- as such I have a basic understanding of the most > common RR types and activities such as zone transfers. However, I >

How do subdomains get discovered by adversaries?

2022-12-21 Thread Michael De Roover
ed information disclosure, hence my curiosity. If it is at all possible to mitigate, I would of course also appreciate discourse on this matter. Thank you! [1] https://subdomainfinder.c99.nl [2] https://criminalip.io/domain Best regards, Michael -- Visit https://lists.isc.org/mailman/listinfo/bind-users

Re: automatic reverse and forwarding zones

2022-10-27 Thread Michael Richardson
Havard Eidnes via bind-users wrote: >To "fill" an ip6.arpa zone for a /64 requires 18446744073709551616 > records (yes, that's about 18 x 10^18 if my math isn't off). I predict > you do not posess a machine capable of running BIND with that many > records loaded -- I know we

Re: Zone transfer over VPN

2022-09-07 Thread Michael De Roover
ts are set according to algorithm and usage (ZSK or KSK) [1] https://www.cyberciti.biz/faq/unix-linux-bind-named-configuring-tsig/ Thanks again for your time to read this email, and for your insights. -- Met vriendelijke groet / Best regards, Michael De Roover -- Visit https://lis

Zone transfer over VPN

2022-09-06 Thread Michael De Roover
s/ch7/xfer.html Thank you so much for taking your time to read this, and thanks in advance for any insights. -- Met vriendelijke groet / Best regards, Michael De Roover -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this

Re: Stopping ddos

2022-08-02 Thread Michael De Roover
ore complicated. Regarding the legitimate queries, it would be prudent to allow common recursors (Google, Cloudflare, Quad9 etc) to have exceptions to this rule. Just allow their IP addresses to send traffic either unrestricted, or using a more relaxed version of the above. HTH, Michael On Tue, 2

Re: Using nsupdate remotely

2022-07-12 Thread Michael Richardson
Philip Prindeville wrote: > What do I need to do on both ends (remote DHCP server and central DNS > server) to push updates over? Your list is pretty accurate. One thing that bites me regularly is that names of the TSIG keys matters, and that if you have a trailing . in the key name, it

Re: understanding keymgr handling of KSK

2022-05-08 Thread Michael Richardson via bind-users
I found this message: May 8 16:41:18 tilapia named[1268]: zone ox.org/IN: zone_rekey:dns_dnssec_keymgr failed: error occurred writing key to disk It would be great if it could tell me the file name that failed to write, and ideally what the error was (EPERM is my guess, but there could also be

understanding keymgr handling of KSK

2022-05-08 Thread Michael Richardson via bind-users
and I don't have a CDS published. So what happened? I shall troll my logs and see what else I can find out, but there sure is a lot of stuff going on. Maybe lots of flotsam from my previous situation that needs to expunged. -- ] Never tell me the odds!

  1   2   3   4   5   6   >