[Pdns-users] install version 3.4.5 on Ubuntu 16.04

2017-02-17 Thread Seyed Hossein Mortazavi
I need to install pdns-server and pdns-backend-mysql 3.4.5 on Ubuntu 16.04. If I use the following command: sudo apt-get install pdns-backend-mysql then version 4 will be installed. I need version 3.4.5 Also this also won't work: sudo apt-get install pdns-backend-mysql=3.4.5 (other combinations

Re: [Pdns-users] DiG: Hopefully Final Thoughts..

2017-02-17 Thread stancs3
Many thanks for your comprehensive replies. I have a number of paths to explore now and will head off to do some more careful testing. If I need further advice I will make sure to include a better set of test results. I certainly have more confidence in getting to a solution that works for me, g

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Brian Candler
On 17/02/2017 13:29, Thomas Mieslinger wrote: dig asie4all.com. @192.43.172.30 ; <<>> DiG 9.10.4-P5 <<>> asie4all.com. @192.43.172.30 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4893 ;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 3

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread bert hubert
On Fri, Feb 17, 2017 at 02:33:37PM +0100, Peter van Dijk wrote: > >Call me confused, but it happened every day this week. > > Because OVH put those records in the .net zone. OVH did this. OVH needs to > fix this. There is no ‘security issue’, there is no ‘CVE needed’. There is > just OVH that need

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Peter van Dijk
Hello Thomas, this will be my last email. I am tired of dealing with your stubborn confusion. On 17 Feb 2017, at 14:29, Thomas Mieslinger wrote: I clear the old mx0..5.ovh.net A records from recursor caches, a customer sends an email to bureauxdeventepro.com, the 213.186.33.XX ips get the n

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
Hello Peter, On 17.02.17 14:17, Peter van Dijk wrote: Hello Thomas, On 17 Feb 2017, at 14:15, Thomas Mieslinger wrote: On 17.02.17 13:56, Brian Candler wrote: On 17/02/2017 12:53, Thomas Mieslinger wrote: With crafted glue in the tld zone and mailrelays using pdns_recursor you could redirect

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Peter van Dijk
Hello Thomas, On 17 Feb 2017, at 14:15, Thomas Mieslinger wrote: On 17.02.17 13:56, Brian Candler wrote: On 17/02/2017 12:53, Thomas Mieslinger wrote: With crafted glue in the tld zone and mailrelays using pdns_recursor you could redirect mail traffic. If you have the ability to craft glue i

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
On 17.02.17 13:56, Brian Candler wrote: On 17/02/2017 12:53, Thomas Mieslinger wrote: With crafted glue in the tld zone and mailrelays using pdns_recursor you could redirect mail traffic. If you have the ability to craft glue in the tld zone, surely you could also just change the delegation ou

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Brian Candler
On 17/02/2017 12:53, Thomas Mieslinger wrote: With crafted glue in the tld zone and mailrelays using pdns_recursor you could redirect mail traffic. If you have the ability to craft glue in the tld zone, surely you could also just change the delegation outright?? _

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
Hi Pieter, On 17.02.17 12:34, Pieter Lexis wrote: On Fri, 17 Feb 2017 11:39:51 +0100 Thomas Mieslinger wrote: Why trusts pdns_recursor records from answers without aa bit set? While resolving, this is the only thing we can trust. And this answer is cached as well. This speeds things up tre

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Pieter Lexis
Hi Thoomas, On Fri, 17 Feb 2017 11:39:51 +0100 Thomas Mieslinger wrote: > Why trusts pdns_recursor records from answers without aa bit set? While resolving, this is the only thing we can trust. And this answer is cached as well. This speeds things up tremendously. We could try to be more resil

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
On 17.02.17 10:58, bert hubert wrote: On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: I understand that this must have a performance impact but having the choice between 1000s of customer calls a day "I can't send emails to ovh and it is your fault" and buying some more recurs

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
On 17.02.17 11:14, Aki Tuomi wrote: On 17.02.2017 12:11, Thomas Mieslinger wrote: On 17.02.17 10:58, bert hubert wrote: On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: ovh changed its MX A records and now my employers Mail relays can't > [..] Those additional records are p

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
On 17.02.17 11:01, Nico CARTRON wrote: On 17/02/2017 10:58, bert hubert wrote: On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: ovh changed its MX A records and now my employers Mail relays can't send email to ovh. Have you attempted to talk to OVH about their misconfiguratio

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Aki Tuomi
On 17.02.2017 12:11, Thomas Mieslinger wrote: > On 17.02.17 10:58, bert hubert wrote: >> On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: >>> ovh changed its MX A records and now my employers Mail relays can't >>> send >>> email to ovh. >> >> Have you attempted to talk to OVH ab

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
On 17.02.17 10:58, bert hubert wrote: On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: ovh changed its MX A records and now my employers Mail relays can't send email to ovh. Have you attempted to talk to OVH about their misconfiguration? There is no misconfiguration at ovh.

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Nico CARTRON
On 17/02/2017 10:58, bert hubert wrote: On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: ovh changed its MX A records and now my employers Mail relays can't send email to ovh. Have you attempted to talk to OVH about their misconfiguration? I ask this because the DNS Resolver

Re: [Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread bert hubert
On Fri, Feb 17, 2017 at 10:49:08AM +0100, Thomas Mieslinger wrote: > ovh changed its MX A records and now my employers Mail relays can't send > email to ovh. Have you attempted to talk to OVH about their misconfiguration? I ask this because the DNS Resolver community keeps getting asked to solve

[Pdns-users] pdns_recursors trusts addtional section where it better shouldn't

2017-02-17 Thread Thomas Mieslinger
Hi, ovh changed its MX A records and now my employers Mail relays can't send email to ovh. This may sound unrelated to pdns_recursor but please read on: Many many domains are wrongly delegated with wrong glue records in the tld zone. As of 2017-02-17 10:43:00 CET dig produces the following o

Re: [Pdns-users] DiG: Hopefully Final Thoughts..

2017-02-17 Thread Brian Candler
On 17/02/2017 06:45, stancs3 wrote: Reverse doesn't work in this config, so I figure on giving up on recursor. What do you mean by "reverse doesn't work"? Can you give a specific example of what you did, what you saw, and what you expected to see? Reverse is just another domain (under in-addr.

Re: [Pdns-users] DiG: more success but puzzling

2017-02-17 Thread Brian Candler
On 17/02/2017 06:10, stancs3 wrote: OK, I managed to get DiG to respond with A records, but only by specifying the hostname in from of the domain name. This is OK, but when the servers where reversed, a simple DiG NS would return the NS records,*and* the A records. Again not a showstopper unles