Re: [Pdns-users] Systemctl Daemon Problem After each pdns upgrade

2023-09-29 Thread Michael Loftis via Pdns-users
On Thu, Sep 28, 2023 at 14:30 IHI IHI via Pdns-users < pdns-users@mailman.powerdns.com> wrote: > Hello > When upgrading to a new version(PowerDNS Recursor v4.7-->4.8-->4.9-->5), > despite choosing to keep the current configuration file,but its tuning > parameters at > pdns-recursor.service(/lib/sy

Re: [Pdns-users] DNSLink or IPFS Support in PowerDNS

2023-01-20 Thread Michael Loftis via Pdns-users
On Fri, Jan 20, 2023 at 12:28 Tom Barrett via Pdns-users < pdns-users@mailman.powerdns.com> wrote: > I would be interested in speaking with anyone who has experimented with > customizing PowerDNS to support IPFS or the DNSLink TXT record type. > There’s not anything for PowerDNS to do here. They’

Re: [Pdns-users] Pdns master notify lag

2022-11-30 Thread Michael Loftis via Pdns-users
On Wed, Nov 30, 2022 at 10:47 lovi via Pdns-users < pdns-users@mailman.powerdns.com> wrote: > Hello, > > Ive setup a pdns lab with 1 pdn/pgsql/master and a slave/named config. > > When I update a record pdns logs show that it takes about 40s before Ive > this message : > 1 domain for which we are

Re: [Pdns-users] Select default type for new zones

2022-11-28 Thread Michael Hallager via Pdns-users
On 2022-11-29 07:13, Andrea Biancalani via Pdns-users wrote: Is there a way to select default zone type for a server instead specify it everytime I enter a new zone in my master? I'd like to pre-select type:master everytime instead asking for native/master/slave options (with native pre-selected)

Re: [Pdns-users] What are the differences between PowerDNS Authoritative Server and Recursor?

2022-11-25 Thread Michael Hallager (personal) via Pdns-users
ed: https://www.powerdns.com/mailing-lists.html Michael ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] What are the differences between PowerDNS Authoritative Server and Recursor?

2022-11-22 Thread Michael Hallager (personal) via Pdns-users
On 2022-11-23 01:18, Raghvendra Choudhary wrote: I am aware of basic networking. But I am not aware of the powerDNS tool. So I want to explore this tool . So anyone can help me how to use this tool after installing the server and admin UI both. I add the domain and the record through the admin

Re: [Pdns-users] What are the differences between PowerDNS Authoritative Server and Recursor?

2022-11-22 Thread Michael Hallager (personal) via Pdns-users
On 2022-11-23 00:46, Raghvendra Choudhary wrote: Hi Team, I installed the powerDNS server and PowerDNS admin in container and it works fine. I also added the domain through the UI. Now i want to know how to resolve the DNS that present in the backend of the powerDNS. This makes no sense. You

Re: [Pdns-users] What are the differences between PowerDNS Authoritative Server and Recursor?

2022-11-18 Thread Michael Hallager via Pdns-users
ne. In the 1990's there was more of a hacker culture on the internet but these days clients and employers expect competency. This does not mean we all have to know everything (none of us do) but having the fundamentals in place is a prerequisite. Michael ___

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-18 Thread Michael Hallager via Pdns-users
On 2022-11-18 23:11, Raghvendra Choudhary wrote: can you please help me out the step. As I checked the articles and I found the step to install recursive server but it was totally indepedence. PDNS Authoritative and Recursor are 2 separate pieces of software. ___

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-18 Thread Michael Hallager via Pdns-users
On 2022-11-18 23:05, Raghvendra Choudhary wrote: Hi Thank for your valauble response. Can we install authorative server and recursive server both in a same machine. Yes you can though you will need to bind them to different IP addresses with the 'local-address' option. __

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-18 Thread Michael Hallager via Pdns-users
On Fri, Nov 18, 2022 at 3:07 PM Michael Hallager via Pdns-users wrote: Add your domain into table 'domains' with type MASTER or SLAVE as appropriate. In the instance of SLAVE you will also need to specify a master IP address. Then add records with the relevant 'domain_id'

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-18 Thread Michael Hallager via Pdns-users
@digivalet.com On Thu, Nov 17, 2022 at 2:38 PM Raghvendra Choudhary wrote: Thank for the help. Raghvendra Choudhary DevOps Engineer | www.digivalet.com [2] T: +91.731.6667891 M: +91.96307.90947 E: raghvendra.choudh...@digivalet.com On Thu, Nov 17, 2022 at 1:36 PM Michael Hallager wrote

Re: [Pdns-users] SNAT and notify messages

2022-11-17 Thread Michael Hallager via Pdns-users
Are you using double NAT? If so then its likely to double your issues. I recommend you fix your underlying issues now by getting all your servers onto the same net block or net blocks which can route between each other without NAT. On 2022-11-18 11:37, ch via Pdns-users wrote: Hi PDNS users,

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-17 Thread Michael Hallager via Pdns-users
en its the wrong product for you. On 2022-11-17 21:01, Raghvendra Choudhary wrote: Hi Michael, Can you let me know the uses of PowerDNS . Why Power DNS is used. can we achieved whatever I said in the mail trail. Raghvendra Choudhary DevOps Engineer | www.digiva

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-16 Thread Michael Hallager via Pdns-users
By default Linux will use hosts file first and then DNS servers listed in /etc/resolv.conf (If the specific application uses Glibc functions for name resolution) but dig is a DNS specific command. So maybe you want to use the ping command? At this time your question sounds more like a Linux us

Re: [Pdns-users] Configure Powerdns and check if the domain which is not present in Powerdns is tranferring the traffic to 8.8.8.8 .

2022-11-16 Thread Michael Hallager via Pdns-users
Your request is very vague. When posting to a free forum like a mailing list you are far more likely to get a useful response by giving tangible information on what you are doing, what you wish to achieve and what you have done so far to diagnose the issue. On 2022-11-17 18:54, Raghvendra Chou

Re: [Pdns-users] DNS-over-TLS option

2022-11-14 Thread Michael Hallager via Pdns-users
ntion in the documents. Michael ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] DNS-over-TLS option

2022-11-13 Thread Michael Hallager via Pdns-users
lease? Kind regards, Michael Hallager___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] [LdapBackend] avoid writing PdnsDomainNotifiedSerial

2022-01-21 Thread Michael Ströder via Pdns-users
operations. Which configuration setting can I tweak to suppress writing PdnsDomainNotifiedSerial? Many thanks in advance. Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] BIND-mode vs. Hybrid BIND-mode

2021-12-02 Thread Fox, Michael E. via Pdns-users
ND files and an sqlite3 database is required for the keys and other DNSSEC related data. Hybrid BIND-mode says the zone records and keying material are stored in different backends. Isn't that the same thing? If there's a distinction here, I don't know what it is. Can someone explain

Re: [Pdns-users] How to configure TSIG with BIND backend

2021-11-18 Thread Fox, Michael E. via Pdns-users
time to figure out what’s wrong. Right now, I don’t even know the proper way to set it up. Michael E Fox Sr. Assoc. Director, ITEC Texas A&M University 979-862-4036 (Office) michael@tamu.edu<mailto:michael@tamu.edu> https://itec.tamu.edu<https://itec.tamu.edu/> Join us for

Re: [Pdns-users] How to configure TSIG with BIND backend

2021-11-17 Thread Fox, Michael E. via Pdns-users
config snipit, using example IPs and domain name, is what I’m looking for. Specifically, what should go in named.conf and pdns.conf for the master and the slave? Can someone help with that? Thanks much. Michael E Fox Sr. Assoc. Director, ITEC Texas A&M University 979-862-4036 (Office) mic

Re: [Pdns-users] How to configure TSIG with BIND backend

2021-11-15 Thread Fox, Michael E. via Pdns-users
? Michael From: frank+p...@tembo.be Sent: Monday, November 15, 2021 5:27 AM To: Fox, Michael E. Cc: pdns-users-ml Subject: Re: [Pdns-users] How to configure TSIG with BIND backend Hi Michael, Can you provide full (unedited) config files please? A lot of info is missing to be able to help you

[Pdns-users] How to configure TSIG with BIND backend

2021-11-13 Thread Fox, Michael E. via Pdns-users
; (resolver): AXFR chunk error: Server Not Authoritative for zone / Not Authorized (This was the first time. Excluding zone from slave-checks until 1636827466) Any help would be greatly appreciated! Michael ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Server Hostname not visible

2021-09-02 Thread SOLIT | Michael via Pdns-users
I fixed it myself. Thank you. The key was to add a PTR record on the PowerDNS locally. Windows checks the PTR record on the local server itself instead of the authorative server. [cid:image001.png@01D79FDE.A265DDE0] [SOLIT Network Solutions B.V]<https://Solit.nl> Michael v

[Pdns-users] Server Hostname not visible

2021-09-01 Thread SOLIT | Michael via Pdns-users
@01D79FD2.3D5FDC40] With the application “bind” its a matter of adding “hostname” to the configuration file. Perhaps anyone can help me, thanks in advance. Best regards, Michael van der Worp [SOLIT Network Solutions B.V]<https://Solit.nl> Michael van der Worp SOLIT Network Solutions B.V | Zu

Re: [Pdns-users] Upgrading Auth Server directly from 4.1.14 to 4.4.1

2021-05-20 Thread Michael Ströder via Pdns-users
t; launch=ldap:bkend1,bind:bkend2 This just works: launch=ldap:bkend1,bind Do you really need the launch suffix 'bkend2' for the bindbackend parameters? Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.pow

Re: [Pdns-users] Building for 32-bit platforms (was: PowerDNS Recursor 4.5.1 Released)

2021-05-11 Thread Michael Ströder via Pdns-users
On 5/11/21 7:22 PM, Otto Moerbeek wrote: > On Tue, May 11, 2021 at 07:01:08PM +0200, Michael Ströder via Pdns-users > wrote: >> Was support for running on 32-bit platforms dropped? > > Yes, as you can read further down below in the announcement. Arrgh! Missed that. Sorry fo

[Pdns-users] Building for 32-bit platforms (was: PowerDNS Recursor 4.5.1 Released)

2021-05-11 Thread Michael Ströder via Pdns-users
HI! Was support for running on 32-bit platforms dropped? configure fails with: configure: error: size of time_t is 4, which is not large enough to fix the y2k38 bug See build system: https://build.opensuse.org/package/show/home:stroeder:network/pdns-recursor Ciao, Michael. On 5/11/21 11:49

Re: [Pdns-users] RV: Fatal Error: Trying to set unknown parameter 'ldap-authmethod'

2021-02-19 Thread Michael Ströder via Pdns-users
7;t have a kerberized setup so all of the above is just from memory. Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Dnstap and kafka

2021-01-14 Thread Michael Chisina via Pdns-users
OK. Thanks for clarification. On Thu, Jan 14, 2021, 4:00 PM Brian Candler wrote: > On 14/01/2021 13:11, Michael Chisina wrote: > > Thanks for the info > > > > # is there any need for middleware software if I use dtap (dnstap > > favoured) following from github

Re: [Pdns-users] Dnstap and kafka

2021-01-14 Thread Michael Chisina via Pdns-users
= ["kafka.example.jp:9092"] Topic = "dnstap_message" # the dataflow will be as follows: DNS message --->dnstap--->middleware--->Kafka producer connector ---> Kafka streaming---> Kafka consumer connector---> debezium connector --->timescaledb(postgresql favoured) Rega

[Pdns-users] Dnstap and kafka

2021-01-13 Thread Michael Chisina via Pdns-users
: Hello, I want to frame stream powerdns recursor DNS query and response using dnstap to an apache kafka remote server (202.20.20.1). # what are the configurations needed on recursor? # what is dns message schema(s) format for the database creation? Regards Michael Chisina

Re: [Pdns-users] gmysql: Is latin1 really necessary? What are the consequences of using UTF-8?

2020-10-30 Thread Michael Loftis via Pdns-users
On Fri, Oct 30, 2020 at 8:17 AM Michael Loftis wrote: > > On Fri, Oct 30, 2020 at 8:15 AM Nicholas Williams via Pdns-users > wrote: > > > > I thought domain names have supported unicode characters for several years > > now. > > Not at the protocol level they&

Re: [Pdns-users] gmysql: Is latin1 really necessary? What are the consequences of using UTF-8?

2020-10-30 Thread Michael Loftis via Pdns-users
On Fri, Oct 30, 2020 at 8:15 AM Nicholas Williams via Pdns-users wrote: > > I thought domain names have supported unicode characters for several years > now. Not at the protocol level they're not. They're punycode. > > On Oct 30, 2020, at 7:53 AM, Frank Louwers wrote: > > Hi Nick, > > I gue

Re: [Pdns-users] gmysql: Is latin1 really necessary? What are the consequences of using UTF-8?

2020-10-30 Thread Michael Loftis via Pdns-users
I was hoping someone who knew more about PDNS authoritative server itself would chime in For MySQL server+client, if the character set in the libmysqlclient and server side tables/etc match, it doesn't matter except for server side sorts (collations). If it is latin1 all the way through then

Re: [Pdns-users] Pdns master-slave replication issue

2020-10-16 Thread Michael Rommel via Pdns-users
Hi, you could look at the config whether you have whitelisted the ip of the slave on the master for zone transfers (AXFR). Secondly, if you have configured, that only signed transfers are allowed, look whether the correct TSIG keys are configured on master and slave. HTH, Michael

Re: [Pdns-users] PowerDNS Recursor build fails on openSUSE Tumbleweed/Factory (gcc 10)

2020-09-09 Thread Michael Ströder via Pdns-users
x27;s tracked downstream here: https://bugzilla.opensuse.org/show_bug.cgi?id=1176312 Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] PowerDNS Recursor build fails on openSUSE Tumbleweed/Factory (gcc 10)

2020-09-09 Thread Michael Ströder via Pdns-users
On 9/8/20 11:49 AM, Remi Gacogne via Pdns-users wrote: > On 9/8/20 11:39 AM, Michael Ströder via Pdns-users wrote: > >> Currently building PowerDNS Recursor fails building on openSUSE >> Tumbleweed/Factory: > > It's an issue caused by Boost >= 1.73, see [1]. We

[Pdns-users] PowerDNS Recursor build fails on openSUSE Tumbleweed/Factory (gcc 10)

2020-09-08 Thread Michael Ströder via Pdns-users
c0746a1beb1ba073c7981eb09f55b3d993b32e5c] (SUSE Linux) As you can see it builds on openSUSE Leap: https://build.opensuse.org/package/show/home:stroeder:branches:server:dns/pdns-recursor Is this an issue with newer gcc? Ciao, Michael. ___ Pdns-users

Re: [Pdns-users] "HTTP/1.1 422 Unprocessable Entity" when creating a zone

2020-06-30 Thread Michael Loftis via Pdns-users
On Tue, Jun 30, 2020 at 08:52 Tomasz Chmielewski via Pdns-users < pdns-users@mailman.powerdns.com> wrote: > Unfortunately I'm not able to find what I'm doing wrong. > > The error is returned no matter if I have "master=yes" set in pdns.conf > or not, and no matter if I use "masters": [] or not.

Re: [Pdns-users] LUA createForward() records and improvement suggestions

2020-06-22 Thread Michael Rommel via Pdns-users
Hi Otto, thanks for the pointer! AFAICT it covers my patches as well, looks a lot more complicated, though. I'll take a closer look at it. Is there any reason, why it hasn't been merged yet? Any cases that would break that needed to be avoided? Thanks, Michael. -- Mich

[Pdns-users] LUA createForward() records and improvement suggestions

2020-06-22 Thread Michael Rommel via Pdns-users
resolving of entries like 192-168-3-4.-3003.example.com. These additional lines below the hex portion would allow this: if(sscanf(parts[0].c_str(), "%u-%u-%u-%u", &x1, &x2, &x3, &x4)==4) { if(x1<=0xff && x2<=0xff && x3&l

Re: [Pdns-users] why CAP_CHOWN?

2020-05-16 Thread Michael Ströder via Pdns-users
On 5/16/20 10:25 PM, bert hubert wrote: > On Sat, May 16, 2020 at 08:42:21PM +0200, Michael Ströder via Pdns-users > wrote: >> But I wonder why CAP_CHOWN is set in CapabilityBoundingSet= and >> AmbientCapabilities= and I could not find a reason in the git history of >>

[Pdns-users] why CAP_CHOWN?

2020-05-16 Thread Michael Ströder via Pdns-users
that capability. Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Best way to setup pdns for ACME challenges and "virtual" entries

2020-03-01 Thread Michael Rommel via Pdns-users
this is an oversight in the code, or the comment is wrong. It > looks like it would be a pretty straightforward feature to add. > > If there's no way round this, then you can use the full LUA backend instead: > https://doc.powerdns.com/authoritative/backends/lua2.html > <https://doc.powerdns.com/authoritative/backends/lua2.html> Nice! thanks for the pointer, Brian! Michael. -- Michael Rommel, Erlangen, Germany___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] Best way to setup pdns for ACME challenges and "virtual" entries

2020-03-01 Thread Michael Rommel via Pdns-users
Thank you in advance for your insights! Michael. -- Michael Rommel, Erlangen, Germany___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] pdns-recursor Permissions Error

2020-01-07 Thread Michael Ströder
ot; happens while running an action as root I'd check whether SELinux or AppArmor blocks some access. => check your audit log (assuming you're running auditd) Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Contents of Pdns-users digest

2019-11-13 Thread Michael Chisina
I think load balancer is the best option and configure the policy(ies) on it. Michael Chisina On Wed, Nov 13, 2019, 2:00 PM wrote: > Send Pdns-users mailing list submissions to > pdns-users@mailman.powerdns.com > > To subscribe or unsubscribe via the World Wid

Re: [Pdns-users] Log all zone changes

2019-09-27 Thread Michael Ströder
er you're looking for: I'm using PowerDNS with LDAP backend and write operations to OpenLDAP server(s) are logged with accesslog overlay. My personal setup is very small but the components should easily scale up. Ciao, Michael. smime.p7s Description: S/MIME Cryp

Re: [Pdns-users] BIND-Zonefiles: @ vs blank

2019-08-08 Thread Michael Loftis
On Thu, Aug 8, 2019 at 07:01 Bjoern Franke wrote: > Hi, > > we have a zonefile which got recently added TXT entries for SPF and DMARC: > > _dmarc IN TXT "v=DMARC1; p=none; rua=mailto:foo"; > IN MX 10 mx.domain.tld. > IN TXT "v=s

[Pdns-users] Question about PDNS SOA presentation.

2019-03-07 Thread Michael Van Der Beek
--+ 2 rows in set (0.00 sec) Didn't setup the fields. Either it was when I signed the domain. No matter.. Setting the SOA-EDIT to "" I get back the correct values. Thanks Peter! Been scratching my head about this for a while. Regards, Michael __

[Pdns-users] Question about PDNS SOA presentation.

2019-03-07 Thread Michael Van Der Beek
reasing it sequentially. But nobody replied to him. His version was 4.1.x. I presume that in his case the first setup was correct. Maybe it was partially fixed from 4.0.6 to 4.1.x Regards, Michael ___ Pdns-users mailing list Pdns-users@mailman.power

[Pdns-users] Question about PDNS SOA presentation.

2019-03-06 Thread Michael Van Der Beek
why I installed dnsdist as an eventual progression. Regards, Michael ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] Question about PDNS SOA presentation.

2019-03-05 Thread Michael Van Der Beek
Forgot to mention I am running. rpm -qa | grep pdns pdns-4.0.6-1pdns.el7.x86_64 dnsdist-1.1.0-1pdns.el7.x86_64 pdns-recursor-4.0.9-1pdns.el7.x86_64 pdns-backend-mysql-4.0.6-1pdns.el7.x86_64 And MariaDB-server-10.1.38-1.el7.centos.x86_64 ___ Pdns-users

[Pdns-users] Question about PDNS SOA presentation.

2019-03-05 Thread Michael Van Der Beek
Opps wrong thread. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] MariaDB-server-10.1.38-1.el7.centos.x86_64

2019-03-05 Thread Michael Van Der Beek
Opps wrong thread. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] PDNS recursor dnssec settings

2019-03-05 Thread Michael Van Der Beek
Forgot to mention I am running. rpm -qa | grep pdns pdns-4.0.6-1pdns.el7.x86_64 dnsdist-1.1.0-1pdns.el7.x86_64 pdns-recursor-4.0.9-1pdns.el7.x86_64 pdns-backend-mysql-4.0.6-1pdns.el7.x86_64 And MariaDB-server-10.1.38-1.el7.centos.x86_64 Thanks Regards, Michael

[Pdns-users] Question about PDNS SOA presentation.

2019-03-05 Thread Michael Van Der Beek
2 | 187.14.72.in-addr.arpa | NULL | NULL | MASTER | 2019022501 | NULL| ++++++-+-+ How come the values are different? What am I doing wrong? Regards, Michael ___ Pdns

Re: [Pdns-users] Spoof MX records

2018-12-15 Thread Bit World Computing - Michael Mertel
> Am 15.12.2018 um 09:50 schrieb bert hubert : > > On Sat, Dec 15, 2018 at 09:42:21AM +0100, Bit World Computing - Michael > Mertel wrote: >> Hi Aleksandr, >> >> I’am somewhat lost, I’am able to set a rule to have the Lua function called >> for MX requ

Re: [Pdns-users] Spoof MX records

2018-12-15 Thread Bit World Computing - Michael Mertel
dq::addAnswer(), which I have found in the recursor documentation, is this valid for dnsdist too? Best regards. > Am 14.12.2018 um 17:16 schrieb Aleksandr Rogozin : > > Hi Michael, > > You should be able to load the file (if the list of zones is large enough and > w

Re: [Pdns-users] Spoof MX records

2018-12-14 Thread Bit World Computing - Michael Mertel
good used mail gateway would be sent to this resolver. I think I’ll give it a try with dnsdist and see what happens. Best regards. > Am 14.12.2018 um 12:55 schrieb Aleksandr Rogozin : > > Hi Michael, > > I recommend using Lua to intercept the DNS queries. Both dnsdist and recurs

[Pdns-users] Spoof MX records

2018-12-13 Thread Bit World Computing - Michael Mertel
dns therefore. The number of zones to spoof is currently not defined, could be dozens if not hundreds. I would usually do this kind of stuff with dnsdist (which I love), but would the recursor a better choice here? Thanks for any advice. —Michael

[Pdns-users] RRSet

2018-04-23 Thread Michael Van Der Beek
something similar to this with pdns-server? Thanks for your time. I've research the mailing list way back 8+ years ago. There was a discussion on this. But the links to the solution no longer exists. Can anyway tell me if there is a new solution? Regards, Mi

Re: [Pdns-users] Meltdown impact on PowerDNS/dnsdist

2018-01-06 Thread Michael Ströder
ve server and move DNSSEC signing to isolated systems? Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Question about logging changes

2017-11-28 Thread Michael Ströder
case you could also let the database backend enforce access control even for API requests. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Question about logging changes

2017-11-28 Thread Michael Ströder
n how to audit write operations on the LDAP server. And this depends on the features of the LDAP server you're planning to use. Personally I love accesslog overlay (originally implemented for delta-replication) in OpenLDAP because it automatigally gives you a perfect audit trail in a separate dat

Re: [Pdns-users] GUI with LDAP backend ?

2017-05-15 Thread Michael Ströder
ility of DNS RRs which put so much burden on the UI. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] pdns-ldap <-> Rudder-ldap

2016-11-15 Thread Michael Ströder
s.net/2015/11/03/powerdns-with-the-remote-back-end-and-dnssec/ Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] PowerDNS Recursor does not provide correct answer to Postfix

2016-08-18 Thread Michael
Quoting Pieter Lexis : Hi Michael, On Thu, 18 Aug 2016 14:20:25 + Michael wrote: Last week I updated to Ubuntu 16.04. So I have a new Postfix version (3.1.0) as well as a new pdns_recursor version (4.0.0-alpha2). Since this update Postfix does not receive correct answers for a

Re: [Pdns-users] PowerDNS Recursor does not provide correct answer to Postfix

2016-08-18 Thread Michael
(5) file for glibc resolver(3) generated by resolvconf(8) # DO NOT EDIT THIS FILE BY HAND -- YOUR CHANGES WILL BE OVERWRITTEN nameserver 127.0.0.1 Thanks, Michael Quoting Leen Besselink : Hi, Sounds like a strange problem. Just to make sure it's set up correctly. Could you check

[Pdns-users] PowerDNS Recursor does not provide correct answer to Postfix

2016-08-18 Thread Michael
I have to change? Thanks, Michael Postfix log = Aug 15 18:21:07 mx0 postfix/qmgr[2715]: 39EF2A40EA2: from=, size=865, nrcpt=1 (queue active) Aug 15 18:21:08 mx0 postfix/smtp[2907]: warning: no MX host for

Re: [Pdns-users] [Pdns-announce] PowerDNS Authoritative Server 4.0.0 released

2016-07-11 Thread Michael Ströder
Pieter Lexis wrote: > * A revived and supported LDAP backend (ldap). Thanks! :-) CIao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mail

[Pdns-users] pdns 4.0 - domain notifcation (master which is not a master)

2016-06-12 Thread Bit World Computing - Michael Mertel
as type=master in the domains table. Any idea what I’am doing wrong here. After writing these lines I had a deja vu: https://mailman.powerdns.com/pipermail/pdns-users/2007-May/004568.html Can’t recall if this ever got figured out. Thanks and best regards. —Michael

Re: [Pdns-users] pdns-recursor 4.0.0~alpha3-1 - no DNSSEC answer?

2016-05-19 Thread Bit World Computing - Michael Mertel
feedback. —Michael > Am 19.05.2016 um 17:36 schrieb Leen Besselink : > > On Thu, May 19, 2016 at 03:00:12PM +0200, Bit World Computing - Michael > Mertel wrote: >> Hi, >> > > Hi, > >> I’am currently trying to get a better unterstanding of DNSSEC. But ev

[Pdns-users] pdns-recursor 4.0.0~alpha3-1 - no DNSSEC answer?

2016-05-19 Thread Bit World Computing - Michael Mertel
. —Michael ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] pdns-recursor 0.0.759g02abb90-1 (4.0 master) vs. getent?

2016-03-09 Thread Bit World Computing - Michael Mertel
Hi Pieter, dnssec=off did the trick indeed. Hope you can fix this, because dnssec was the reason I went to 4.x in the first place :) If I can be of any help here, just let me know. Best regards. > Am 09.03.2016 um 10:05 schrieb Pieter Lexis : > > Hi Michael, > > Please keep

[Pdns-users] pdns-recursor 0.0.759g02abb90-1 (4.0 master) vs. getent?

2016-03-08 Thread Bit World Computing - Michael Mertel
, exit code is 2 (One or more supplied key could not be found in the database) -with 8.8.8.8 as nameserver 188.166.116.224 STREAM repo1.powerdns.com 188.166.116.224 DGRAM 188.166.116.224 RAW Is this a known bug? Never had any trouble with the 3.7.3 release. —Michael

[Pdns-users] Re: pdns-recursor 4.0.0alpha1 crashes at startup

2016-01-30 Thread Bit World Computing - Michael Mertel
s.com' returns successfully. I changed my dns from local recursor to 8.8.8.8 in /etc/resolv.conf and the problem with wget went away. Meanwhile I returned to 3.7.3, but I will give it another shot later because of the DNSSEC functionality. —Michael smime.p7s Description: S/MIME cryptographic

[Pdns-users] pdns-recursor 4.0.0alpha1 crashes at startup

2016-01-29 Thread Bit World Computing - Michael Mertel
working for ages: forward-zones-file=/etc/powerdns/forward-zones forward-zones-recurse=.=8.8.8.8 No matter if I enable both, either the first or the second the recursor crashes if a zone is served following these forward rules. Is this a known bug? —Michael smime.p7s Description: S/MIME

Re: [Pdns-users] Setting up intentionally invalid DNSSEC record in auto-secure environment

2016-01-06 Thread Michael Loftis
(inline) On Wed, Jan 6, 2016 at 11:42 AM, Nicholas Williams wrote: > I'll look into that other script. Thanks, Bert. > >> How about a creating a separate sub-zone with a broken presigned DNSSEC > >> You can set presigned for just that single zone using the PRESIGNED domain >> metadata[1] int your

Re: [Pdns-users] PDNS to answer as NON-authoritative?

2016-01-03 Thread Michael Loftis
, when you turn off recursive resolution it resolves. I > can't figure out the missing part to have the same behavior. > Le 3 janv. 2016 2:39 PM, "Michael Loftis" > a écrit : > >> Again not a resolver. Sorry but you're the one misunderstanding. If you >>

Re: [Pdns-users] PDNS to answer as NON-authoritative?

2016-01-03 Thread Michael Loftis
sample output > Le 3 janv. 2016 2:00 PM, "Aki Tuomi" > a écrit : > >> That is because dig is not a resolver. >> >> >> >> --- >> Aki Tuomi >> >> >> Original message ---- >> From: Luis Daniel Luci

Re: [Pdns-users] PDNS to answer as NON-authoritative?

2016-01-03 Thread Michael Loftis
the way u don't want to use. I know how. > > I need to make it work in non recursive mode. > Le 3 janv. 2016 9:29 AM, "Aki Tuomi" > a écrit : > >> If you want to use auth as recursor, you need to configure >> >> recursor= >> allow-r

Re: [Pdns-users] PDNS to answer as NON-authoritative?

2016-01-02 Thread Michael Loftis
PowerDNS is not the same as PowerDNS Recursor. The former only does authoritative which is your problem here. On Saturday, January 2, 2016, Luis Daniel Lucio Quiroz < luis.daniel.lu...@gmail.com> wrote: > Hello > > Wat am I missing? I have this: > launch=pipe,bind > pipe-command=/usr/local/libexe

Re: [Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-25 Thread Michael Ströder
l...@consolejunkie.net wrote: On 2015-04-24 21:35, Michael Ströder wrote: Michael Ströder wrote: We're currently testing DNSSEC validation with libunbound 1.5.3 with all the RRs retrieved through a pdns-recursor (also tested 3.7.2). It seems that 1. libunbound does not explicitly ret

Re: [Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-24 Thread Michael Ströder
Michael Ströder wrote: We're currently testing DNSSEC validation with libunbound 1.5.3 with all the RRs retrieved through a pdns-recursor (also tested 3.7.2). It seems that 1. libunbound does not explicitly retrieve the RRSIG RRs and 2. pdns-recursor does not return them when not expli

[Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-24 Thread Michael Ströder
tion in this infrastructure. Any hint is appreciated. Thanks in advance. Ciao, Michael. ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] LargeScaleDNSSECBCP / versions

2015-04-16 Thread Michael Ströder
HI! It seems this wiki page mentions rather old pdns versions: http://wiki.powerdns.com/trac/wiki/LargeScaleDNSSECBCP Are there more recent insight to consider regarding versions? Especially when thinking about pdns upgrade 3.3.x -> 3.4.1 for DNSSEC? Ciao, Michael. -- Michael Ströder E-M

Re: [Pdns-users] Configure private subdomain

2015-03-28 Thread Michael Ströder
ime constraints. And a nicer schema for not (ab)using attribute 'seeAlso' would be better. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Configure private subdomain

2015-03-04 Thread Michael Ströder
s for two years now. I'm using stock pdns 3.4.3 and not external code. Give it a try. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Configure private subdomain

2015-03-04 Thread Michael Ströder
come here and ask whether I managed to get it working in time: https://chemnitzer.linux-tage.de/2015/en/programm/beitrag/134 Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Slave DNSKeys

2015-03-02 Thread Michael Ströder
why the LDAP backend is not improved to support DNSSEC. It's so much easier to setup a LDAP server with multi-master and two-tier replication than a mySQL server. And attributes are of variable length by default. Ciao, Michael. smime.p7s Description: S/MIME Crypto

Re: [Pdns-users] ANY+Reflection Attacks?

2015-02-25 Thread Michael Ströder
ter all, those are legitimate clients and there seems > to be a firewall with connection tracking issues. What's unexpected to me > is having TCP requests, I was expecting only UDP traffic from end users. DNSSEC used? Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signa

[Pdns-users] DNS names and strings (was: PowerDNS development plans: 4.x DNSSEC, C++ 2011!)

2015-02-23 Thread Michael Ströder
elated to us treating them like strings. Unfortunately the term string is used in many different ways. Could you please elaborate on what that means exactly? E.g. will this affect the way NON-ASCII DNS names are stored in backend files? Ciao, Michael. smime.p7s Description: S/MIME Cryptograph

Re: [Pdns-users] Why was content length increased?

2015-02-19 Thread Michael Loftis
DNSSEC and DKIM. On Thursday, February 19, 2015, Nick Williams wrote: > I'm upgrading to authoritative 3.4 and noticed that the records.content > column has been increased from 255 characters to 64000 characters. Because > my table is UTF-8, I get the following error: > > mysql> ALTER TABLE reco

Re: [Pdns-users] Currently using distro packages, want to update

2015-02-12 Thread Michael Ströder
the direct download links to zypper repo for your openSUSE version. In my OBS home project I'm also building openSUSE Factory_ARM for running the packages on rasperry pi. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature __

Re: [Pdns-users] DNSSEC with LDAP backend

2015-01-17 Thread Michael Ströder
27;t need auto-signing or support by other PowerDNS tools. I'd implement generating DNSSEC related RRs with own custom scripts writing LDAP entries. All I need is that powerdns delivers the RRs needed for DNSSEC read from LDAP entries. Is that possible? Ciao, Michael. smime.p7s Descr

[Pdns-users] DNSSEC with LDAP backend

2015-01-16 Thread Michael Ströder
not from content of ldap_attrany if qtype is set. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] RFE LDAP backend: Filter template

2014-10-18 Thread Michael Ströder
ly used as example. Of course I can use the pipe-backend to implement whatever is needed for LDAP integration. Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com http://mailman.powerdns.com/mailman/listinfo/pdns-users

  1   2   >