Re: [Pdns-users] PDNS Authoritative Server DDOS Protection

2018-07-29 Thread Remi Gacogne
Hi Hamed, On 07/21/2018 08:08 AM, Hamed Haghshenas wrote: > For attacks build by Mausezahn with small Src Address subnet, worked > fine and blocked every /32 subnet that reach the query rate . but > when use big SRC subnet like /20 it can't manage the queries and CPU > rate increase . What is the

Re: [Pdns-users] Migrate from zsk/ksk/rsa to csk/ecdsa

2018-07-29 Thread Nicola Tiling
Hi "Publish the CDS records: pdnsutil set-publish-cds example.com, these records will tell the parent zone to update its DS records. Now wait for the DS records to be updated in the parent zone." If I publish the DS keys for a .net domain, will there be two DS hashes in the .net root zone afte

[Pdns-users] Migrate from zsk/ksk/rsa to csk/ecdsa

2018-07-29 Thread Nicola Tiling
Hi I want to migrate my old original bind generated dnssec zsk/ksk keys to powerdns csk with new ecdsa algorithm. I’ve created a new inactive key pdnsutil add-zone-key example.com ksk inactive 256 ECDSAP256SHA25 and can see the inactive csk with "pdnsutil show-zone“ as expected. But I