Re: Obfuscating SOA information in RPZ

2019-12-02 Thread Mark Andrews
You need BIND 9.14.0 or later. 5177. [func] Add the ability to specify in named.conf whether a response-policy zone's SOA record should be added to the additional section (add-soa yes/no). [GL #865] That said the rpz SOA is “unrelated”

Re: Obfuscating SOA information in RPZ

2019-11-29 Thread John W. Blue
What does the complaint look like? Is it preventing this industrial machine from doing its job? John Sent from Nine<http://www.9folders.com/> From: Ict Security Sent: Nov 29, 2019 7:18 AM To: bind-users@lists.isc.org Subject: Obfuscating SOA information

Obfuscating SOA information in RPZ

2019-11-29 Thread Ict Security
Dear guys, we use RPZ zone in Bind 9 to protect some users against possible malwares and to force Google safe search changing resolution to Google's safe IP address server. We have an industrial machine which, for some reason, if "complaining" about the SOA information, visible in the additional