Re: Insecure response BIND 9.7.0b2

2009-11-20 Thread Stephane Bortzmeyer
On Fri, Nov 20, 2009 at 09:27:35AM +1100, Mark Andrews wrote a message of 34 lines which said: > There are also firewalls that block DNS/UDP responses bigger 512 > bytes or block EDNS queries/responses 10 years after the > introduction of EDNS. There are also middleware that blocks/drops > DN

Re: Insecure response BIND 9.7.0b2

2009-11-19 Thread Mark Andrews
In message , David Forrest w rites: > Logged: > Nov 19 12:13:45 maplepark named[23329]: validating @0x17b7980: > dlv.isc.org SOA: got insecure response; parent indicates it should be > secure > > What does this mean? It means named fellback to making a plain DNS query due to multiple timeou

Re: Insecure response BIND 9.7.0b2

2009-11-19 Thread Evan Hunt
> So what are you suggesting? That a dlv.isc.org server went ape and > returned an insecure response for (IN,SOA,dlv.isc.org)? Or that the > user is under attack with faked responses? I don't think anyone was suggesting anything, just explaining what the message means. Which is that isc.org has a

Re: Insecure response BIND 9.7.0b2

2009-11-19 Thread Chris Thompson
On Nov 19 2009, Jeremy C. Reed wrote: On Thu, 19 Nov 2009, David Forrest wrote: Logged: Nov 19 12:13:45 maplepark named[23329]: validating @0x17b7980: dlv.isc.org SOA: got insecure response; parent indicates it should be secure What does this mean? This is documented in the ARM. The paren

Re: Insecure response BIND 9.7.0b2

2009-11-19 Thread David Forrest
On Thu, 19 Nov 2009, Jeremy C. Reed wrote: On Thu, 19 Nov 2009, David Forrest wrote: Logged: Nov 19 12:13:45 maplepark named[23329]: validating @0x17b7980: dlv.isc.org SOA: got insecure response; parent indicates it should be secure What does this mean? This is documented in the ARM. The

Re: Insecure response BIND 9.7.0b2

2009-11-19 Thread Jeremy C. Reed
On Thu, 19 Nov 2009, David Forrest wrote: > Logged: Nov 19 12:13:45 maplepark named[23329]: validating @0x17b7980: > dlv.isc.org SOA: got insecure response; parent indicates it should be secure > > What does this mean? This is documented in the ARM. The parent zone says (published DS) that it

Insecure response BIND 9.7.0b2

2009-11-19 Thread David Forrest
Logged: Nov 19 12:13:45 maplepark named[23329]: validating @0x17b7980: dlv.isc.org SOA: got insecure response; parent indicates it should be secure What does this mean? -- David Forrest St. Louis, Missouri ___ bind-users mailing list bind-users@