Re: [Pdns-users] Zone transfert rejected in Powerdns Letsencrypt challenge

2021-06-23 Thread Martijn Grendelman via Pdns-users
Hi, Op 22/06/2021 om 13:46 schreef Brian Candler via Pdns-users: On 22/06/2021 12:33, Jan-Piet Mens via Pdns-users wrote: For Letsencrypt protocol to generate certificate I have to enable zone transfer in my powerdns. I think you mean "DNS Updates" for Let's Encrypt dns-01, but I don't believ

Re: [Pdns-users] Zone transfert rejected in Powerdns Letsencrypt challenge

2021-06-23 Thread Brian Candler via Pdns-users
On 23/06/2021 08:54, Cheikh Dieng wrote: Very Thanks, It's clear for me. For dnsdist i  need HA pour my Powerdns. And how are you achieving HA of your dnsdist? The normal, recommended approach for authoritative DNS resilience is to have multiple nameservers, listed as separate NS records. dn

Re: [Pdns-users] Zone transfert rejected in Powerdns Letsencrypt challenge

2021-06-23 Thread Cheikh Dieng via Pdns-users
Very Thanks, It's clear for me. For dnsdist i need HA pour my Powerdns. >>The delegation is done at the parent level, yes. However the delegated domain still needs to contain NS records and a SOA record for its own zone: Yes, this is some details [pduser@hyp03 ~]$ podman exec pdns pdnsutil li

Re: [Pdns-users] Zone transfert rejected in Powerdns Letsencrypt challenge

2021-06-23 Thread Brian Candler via Pdns-users
On 22/06/2021 23:30, Cheikh Dieng wrote: Hi, excuse for delay.. For context: My powerdns listen in port 2053 My dnsdist listen in port 1053 We are an translating port through 53 (from external request) to 1053 . That's why from external we use port 53 and in internal we can use port 1053 or 20