[Pdns-users] PowerDNS DNSdist 2.0.0 released

2025-07-21 Thread Remi Gacogne via Pdns-users
able from our repository [7]. [1]: https://dnsdist.org [2]: https://dnsdist.org/changelog.html#change-2.0.0 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https://downloads.powerdns.com/releases/dnsdist-2.0.0.tar.xz [6]: https:/

[Pdns-users] PowerDNS Security Advisory 2025-04: A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts

2025-07-21 Thread Otto Moerbeek via Pdns-users
l#change-5.0.12 5. https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.6 6. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.4 7. https://mailman.powerdns.com/mailman/listinfo/pdns-users 8. https://github.com/PowerDNS/pdns/issues/new/choose

[Pdns-users] Second release candidate of PowerDNS DNSdist 2.0.0

2025-07-17 Thread Remi Gacogne via Pdns-users
downloads website, and packages for several distributions are available from our repository [7]. [1]: https://dnsdist.org [2]: https://dnsdist.org/changelog.html#change-2.0.0-rc2 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https

[Pdns-users] Second alpha release of PowerDNS Recursor 5.3.0

2025-07-09 Thread Otto Moerbeek via Pdns-users
/changelog/5.3.html#change-5.3.0-alpha2 3. https://docs.powerdns.com/recursor/upgrade.html 4. https://mailman.powerdns.com/mailman/listinfo/pdns-users 5. https://github.com/PowerDNS/pdns/issues/new/choose 6. https://downloads.powerdns.com/releases/pdns-recursor-5.3.0-alpha2.tar.xz 7

[Pdns-users] First release candidate of PowerDNS DNSdist 2.0.0

2025-07-08 Thread Remi Gacogne via Pdns-users
://dnsdist.org/changelog.html#change-2.0.0-rc1 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https://downloads.powerdns.com/releases/dnsdist-2.0.0-rc1.tar.xz [6]: https://downloads.powerdns.com/releases/dnsdist-2.0.0-rc1.tar.xz.sig [7]: https

[Pdns-users] PowerDNS Authoritative Server 4.9.7 released

2025-07-07 Thread Miod Vallat via Pdns-users
ative/upgrading.html 3. https://downloads.powerdns.com/releases/pdns-4.9.7.tar.bz2 4. https://downloads.powerdns.com/releases/pdns-4.9.7.tar.bz2.sig 5. https://downloads.powerdns.com/releases/ 6. https://repo.powerdns.com/ 7. https://mailman.powerdns.com/mailman/listinfo/pdns-users 8. https://github.com/Pow

[Pdns-users] minimum ttl

2025-07-02 Thread Andrey Sedletsky via Pdns-users
Good afternoon, powerdns team! We use pdns recursor with a five-minute value set in the settings for the minimum_ttl_override field. However, recently there have been problems with Content Delivery Network providers using dns balancing, so it became necessary to redefine the value of the

[Pdns-users] First alpha release of PowerDNS Recursor 5.3.0

2025-06-25 Thread Otto Moerbeek via Pdns-users
://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.0-alpha1 3. https://docs.powerdns.com/recursor/upgrade.html 4. https://mailman.powerdns.com/mailman/listinfo/pdns-users 5. https://github.com/PowerDNS/pdns/issues/new/choose 6. https://downloads.powerdns.com/releases/pdns-recursor-5.3.0

[Pdns-users] pdns / BIND backend: Better "rediscover" documentation?

2025-06-20 Thread Steinar Haug via Pdns-users
" or something along those lines? Steinar Haug, AS2116 ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] First beta release of PowerDNS DNSdist 2.0.0 released

2025-06-20 Thread Remi Gacogne via Pdns-users
]: https://dnsdist.org [2]: https://dnsdist.org/changelog.html#change-2.0.0-beta1 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https://downloads.powerdns.com/releases/dnsdist-2.0.0-beta1.tar.xz [6]: https://downloads.powerdns.com/releases

Re: [Pdns-users] DNSSEC Validations and max-cache-bogus-ttl

2025-06-11 Thread Otto Moerbeek via Pdns-users
On Wed, Jun 11, 2025 at 04:56:14PM +0200, Jan-Piet Mens via Pdns-users wrote: > > rec_control add-nta domain.example botched keyroll > > > > would set dnssec validations for domain.example. to "off"? > > Correct, though the multple arguments as rea

Re: [Pdns-users] DNSSEC Validations and max-cache-bogus-ttl

2025-06-11 Thread Jan-Piet Mens via Pdns-users
uments. -JP ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] DNSSEC Validations and max-cache-bogus-ttl

2025-06-11 Thread rob777 via Pdns-users
. Juni 2025 um 16:21 Uhr schrieb Jan-Piet Mens via Pdns-users < pdns-users@mailman.powerdns.com>: > I think the safest in this situation would be to add a Negative Trust > Anchor > (NTA) [1] in order to temporarily disable DNSSEC validation in your > Recursor > for that particular

Re: [Pdns-users] DNSSEC Validations and max-cache-bogus-ttl

2025-06-11 Thread Jan-Piet Mens via Pdns-users
authoritative server and get them to fix the zone. -JP [1] https://doc.powerdns.com/recursor/lua-config/dnssec.html#addNTA [2] https://doc.powerdns.com/recursor/dnssec.html#ntas ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https

[Pdns-users] DNSSEC Validations and max-cache-bogus-ttl

2025-06-11 Thread rob777 via Pdns-users
Hi I had a case where a customer who is using my pdns recursor for external domain resolution had an application error due to failed dnssec validation for the external Domain which his application depends on. I have dnssec=validate configured in pdns recursor The external domain had 4 Auth. DNS

Re: [Pdns-users] Migrating pdns auth backend to new database server - DNSSEC considerations ?

2025-06-05 Thread Smith via Pdns-users
On Wednesday, 4 June 2025 at 23:42, Ken Marshall wrote: > On Wed, Jun 04, 2025 at 06:11:02PM +, Smith via Pdns-users wrote: > > > Subject says it all really. > > > > I've got a pdns-auth server currently talking to a postgres backend. > > > > I

[Pdns-users] We're looking for a C++ Developer

2025-06-05 Thread Otto Moerbeek via Pdns-users
___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Migrating pdns auth backend to new database server - DNSSEC considerations ?

2025-06-04 Thread Ken Marshall via Pdns-users
On Wed, Jun 04, 2025 at 06:11:02PM +, Smith via Pdns-users wrote: > Subject says it all really. > > I've got a pdns-auth server currently talking to a postgres backend. > > I want to migrate the postgres backend to a different server (new version of > postgres). >

[Pdns-users] Migrating pdns auth backend to new database server - DNSSEC considerations ?

2025-06-04 Thread Smith via Pdns-users
Subject says it all really. I've got a pdns-auth server currently talking to a postgres backend. I want to migrate the postgres backend to a different server (new version of postgres). Are there any special steps / considerations required to avoid breaking DNSSEC along the way ? I gue

[Pdns-users] How to set up multiple domains with exactly the same data (domain aliasing)

2025-06-03 Thread Frank Altpeter via Pdns-users
ame with the gmysql backend? Or is there a backend that could do that for me (like some kind of alias backend where one can configure a list of domains and a target domain to fetch records from)? I can't get rid of the bind backend if it results in having to edit 5k domains on a single record cha

Re: [Pdns-users] Lau2 backend, and query refused errors

2025-05-28 Thread Eric via Pdns-users
Thanks, was able to get a working configuration to get started with. I did not see that previously May 23, 2025 7:46:42 AM Otto Moerbeek : > On Thu, May 22, 2025 at 10:38:07AM -0400, Eric via Pdns-users wrote: > >> Having some trouble finding documentation and examples of u

Re: [Pdns-users] public DoH/DoT dnsdist 1.9.8 exited on signal 11

2025-05-27 Thread Remi Gacogne via Pdns-users
Hi Christoph, On 5/27/25 11:33, Christoph via Pdns-users wrote: These crashes continued on an almost daily basis until we updated to 1.9.9 in early May, since then we have never seen a dnsdist crash. So maybe it was related to CVE-2025-30194 or some other changes in 1.9.9 after all, not sure

Re: [Pdns-users] public DoH/DoT dnsdist 1.9.8 exited on signal 11

2025-05-27 Thread Christoph via Pdns-users
___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

[Pdns-users] First Alpha Release for PowerDNS Authoritative Server 5.0.0

2025-05-27 Thread Peter van Dijk via Pdns-users
horitative/upgrading.html 3. https://downloads.powerdns.com/releases/pdns-5.0.0-alpha1.tar.bz2 4. https://downloads.powerdns.com/releases/pdns-5.0.0-alpha1.tar.bz2.sig 5. https://downloads.powerdns.com/releases/ 6. https://repo.powerdns.com/ 7. https://mailman.powerdns.com/mailman/lis

Re: [Pdns-users] Lau2 backend, and query refused errors

2025-05-23 Thread Otto Moerbeek via Pdns-users
On Thu, May 22, 2025 at 10:38:07AM -0400, Eric via Pdns-users wrote: > Having some trouble finding documentation and examples of using lau2 to > answer dns requests. > > Was able to use bind and gsqlite3 as backends for powerdns and they answer > queries but have not had any

[Pdns-users] Second alpha release of PowerDNS DNSdist 2.0.0 released

2025-05-23 Thread Remi Gacogne via Pdns-users
/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https://downloads.powerdns.com/releases/dnsdist-2.0.0-alpha2.tar.xz [6]: https://downloads.powerdns.com/releases/dnsdist-2.0.0-alpha2.tar.xz.sig [7]: https://repo.powerdns.com Best regards, -- Remi Gacogne PowerDNS.COM BV - https

[Pdns-users] Lau2 backend, and query refused errors

2025-05-22 Thread Eric via Pdns-users
nt to have it answer a single query of any kind with lau2 as the backend. Does anyone have examples of minimal configs for pdns.conf and an associated lau2-filename script? Documentation or tutorial examples? Thanks ___ Pdns-users mailing list

[Pdns-users] PowerDNS DNSdist 1.9.10 released, fixing CVE-2025-30193

2025-05-20 Thread Remi Gacogne via Pdns-users
://dnsdist.org [2]: https://dnsdist.org/changelog.html#change-1.9.10 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https://downloads.powerdns.com/releases/dnsdist-1.9.10.tar.bz2 [6]: https://downloads.powerdns.com/releases/dnsdist-1.9.10.tar.bz2.sig

Re: [Pdns-users] Pdns-users Digest, Vol 268, Issue 6

2025-05-12 Thread Djerk Geurts via Pdns-users
Geurts > On 12 May 2025, at 15:28, pdns-users-requ...@mailman.powerdns.com wrote: > > Send Pdns-users mailing list submissions to > pdns-users@mailman.powerdns.com > > To subscribe or unsubscribe via the World Wide Web, visit > https://mailman.powerdns.com/mailma

Re: [Pdns-users] No response from pdns-recursor for some clients

2025-05-12 Thread Robby Pedrica via Pdns-users
hanks for your help and assume this request is closed. Regards Robby On Thu, May 08, 2025 at 03:00:37PM +0100, Robby Pedrica wrote: On 2025/04/30 12:41, Otto Moerbeek wrote: On Tue, Apr 29, 2025 at 03:18:44PM +0100, Robby Pedrica via Pdns-users wrote: Hi pdns community I've got an

Re: [Pdns-users] Recursor too fast?

2025-05-12 Thread Robby Pedrica via Pdns-users
Question Djerk: why are you running your firewalls in active/active? This is an unusual configuration that has many challenges, including the one you've just mentioned. Regards Robby On 2025/05/12 15:04, Djerk Geurts via Pdns-users wrote: An odd statement possibly, but I’m looking for

[Pdns-users] Recursor too fast?

2025-05-12 Thread Djerk Geurts via Pdns-users
___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Migration to a single 10.in-addr.arpa Reverse Zone

2025-05-09 Thread rob777 via Pdns-users
Hi On 30/04/2025 09:19, Alessandro Lota via Pdns-users wrote: > > If a specific reverse zone like a /24 exists, it could have precedence > > over a /8 during resolution (NOT TESTED!!!). > > On the auth server: this will be fine. Many servers host a domain and > its sub-do

Re: [Pdns-users] No response from pdns-recursor for some clients

2025-05-08 Thread Otto Moerbeek via Pdns-users
eek wrote: > > On Tue, Apr 29, 2025 at 03:18:44PM +0100, Robby Pedrica via Pdns-users > > wrote: > > > > > Hi pdns community > > > > > > I've got an odd issue where some clients do not get a response from either > > > of my 2 recursor

Re: [Pdns-users] No response from pdns-recursor for some clients

2025-05-08 Thread Robby Pedrica via Pdns-users
On 2025/04/30 12:41, Otto Moerbeek wrote: On Tue, Apr 29, 2025 at 03:18:44PM +0100, Robby Pedrica via Pdns-users wrote: Hi pdns community I've got an odd issue where some clients do not get a response from either of my 2 recursors. Both are v5.1.4 deployed via docker with fairly std co

Re: [Pdns-users] pdns-recursor metrics review and tuning advice request

2025-05-07 Thread Scott Crace via Pdns-users
configuration forwards to > the > > private AD servers and I believe the lua script drops queries that have > no > > match in that zone. The public zone is being slowly phased out. > > > > I noted while reviewing the previous server configs and found a comment > >

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread frank--- via Pdns-users
is why this configuration worked perfectly for > me with one old version of PDNS- pdns-4.1.14-1 (only put two namesever > in resolv.conf 127.0.0.1 and 8.8.8.8) ? Please see https://doc.powerdns.com/authoritative/appendices/EOL.html?highlight=end%20life. Pdns 4.1 went End Of Life before

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread Brian Candler via Pdns-users
"How do I do this really bad thing with PowerDNS, in order to achieve Y?" when we don't know what Y actually is.___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread frank--- via Pdns-users
ts to > servidor1.dominio.com <http://servidor1.dominio.com/>, it must resolve to a > different IP: diripservidor1-serverB. > Yes, Pdns-auth with LUA records (in MySQL or other) are a good solution for this. That's not the issue. > So, depending on the source of the DNS query, th

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread frank--- via Pdns-users
Hi Nacho, How "static" is the list of domains which need to resolve locally? Updated sub-second? Once every minute? Once every hour? I would not use pdns-recursor at all. I would let dnsdist be the first point of entry, with 2 pools: a "auth" pool and a resolver pool. Add

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread Nacho Oppo via Pdns-users
, and I don't really understand how it did it. 4. Should a Computer Science assignment really be this high-level? They proposed it to me and I thought it wouldn't be as complicated as it's turning out to be. Nacho. El mié, 7 may 2025 a las 10:27, William Edwards via Pdns

[Pdns-users] PowerDNS Authoritative Server 4.9.5

2025-05-07 Thread Miod Vallat via Pdns-users
.html#change-4.9.5 2. https://doc.powerdns.com/authoritative/upgrading.html 3. https://downloads.powerdns.com/releases/pdns-4.9.5.tar.bz2 4. https://downloads.powerdns.com/releases/pdns-4.9.5.tar.bz2.sig 5. https://downloads.powerdns.com/releases/ 6. https://repo.powerdns.com/ 7

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread Brian Candler via Pdns-users
On 07/05/2025 09:04, Nacho Oppo via Pdns-users wrote: The goal is to configure PowerDNS so that it first checks an A record in a MySQL backend, and if the record is not found o if database does´not respond, it should forward the query to an external DNS server, such as Google’s (8.8.8.8

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread William Edwards via Pdns-users
10:04 heeft Nacho Oppo via Pdns-users > het volgende geschreven: > >  > Dear "PowerDNS MailGroup", > > My name is Nacho, and I am a university student currently studying Computer > Science. I’m working on my final-year project, which involves setting up a

Re: [Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread frank--- via Pdns-users
> On 7 May 2025, at 10:04, Nacho Oppo via Pdns-users > wrote: > > The goal is to configure PowerDNS so that it first checks an A record in a > MySQL backend, and if the record is not found o if database does´not respond, > it should forward the query to an external D

[Pdns-users] Request for Help with PowerDNS + Recursor Configuration for Final Year Project

2025-05-07 Thread Nacho Oppo via Pdns-users
to a complete example, I would be truly grateful. Thank you in advance for your time and help. Best regards, Nacho ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] No response from pdns-recursor for some clients

2025-04-30 Thread Otto Moerbeek via Pdns-users
On Tue, Apr 29, 2025 at 03:18:44PM +0100, Robby Pedrica via Pdns-users wrote: > Hi pdns community > > I've got an odd issue where some clients do not get a response from either > of my 2 recursors. Both are v5.1.4 deployed via docker with fairly std > configs. Generally the l

Re: [Pdns-users] Migration to a single 10.in-addr.arpa Reverse Zone

2025-04-30 Thread Brian Candler via Pdns-users
On 30/04/2025 09:19, Alessandro Lota via Pdns-users wrote: If a specific reverse zone like a /24 exists, it could have precedence over a /8 during resolution (NOT TESTED!!!). On the auth server: this will be fine. Many servers host a domain and its sub-domains: this is normal practice. On

Re: [Pdns-users] Migration to a single 10.in-addr.arpa Reverse Zone

2025-04-30 Thread rob777 via Pdns-users
instead of a /8, for more > precise control. > Thank you for the input - seems no way around of testing it with regards to overlapping domains.. Yes - maybe a /16 zone is better than /8, have to think about that Best Regards ___ Pdn

Re: [Pdns-users] Migration to a single 10.in-addr.arpa Reverse Zone

2025-04-30 Thread Alessandro Lota via Pdns-users
On 25/04/25 10:30, rob777 via Pdns-users wrote: Would this work or will this generate a conflict with the existing 10.0.10.in-addr.arpa, 10.0.20.in-addr.arpa, 10.0.25.in-addr.arpa Reverse zones? Or will Powerdns Auth. not be able to load this new reverse zone 10.in-addr.arpa because it

[Pdns-users] No response from pdns-recursor for some clients

2025-04-29 Thread Robby Pedrica via Pdns-users
Hi pdns community I've got an odd issue where some clients do not get a response from either of my 2 recursors. Both are v5.1.4 deployed via docker with fairly std configs. Generally the logs will indicate if something is not in the allowed-from list but these clients don't show

[Pdns-users] PowerDNS DNSdist 1.9.9 released, fixing CVE-2025-30194

2025-04-29 Thread Remi Gacogne via Pdns-users
downloads website, and packages for several distributions are available from our repository [7]. [1]: https://dnsdist.org [2]: https://dnsdist.org/changelog.html#change-1.9.9 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https

[Pdns-users] Migration to a single 10.in-addr.arpa Reverse Zone

2025-04-25 Thread rob777 via Pdns-users
Hi List I use Powerdns Authoritative with Powerdns Recursor for Internal Zones. Currently i have 300-400 Subnets in the 10.0.0.0/8 Range. Currently i have only for 3 Subnets in this Range a Reverse zone configured in my Pdns Auth. and PDNS Recursor. So i have... 10.0.10.in-addr.arpa 10.0.20.in

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Fabian Santiago via Pdns-users
smime.p7s Description: S/MIME cryptographic signature ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Miod Vallat via Pdns-users
add a mention to the documentation, that this feature is not compatible with group replication. Miod ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Fabian Santiago via Pdns-users
p-replication and it is in fact ok to use then? -- Thank you. Fabian S. OpenPGP: 0x643082042DC83E6D94B86C405E3DAA18A1C22D8F OpenPGP_0x5E3DAA18A1C22D8F.asc Description: OpenPGP public key OpenPGP_signature.asc Description: OpenPGP digital signature __

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Fabian Santiago via Pdns-users
hello, On 4/24/25 2:57 AM, Miod Vallat via Pdns-users wrote: You are not using zone2sql correctly ahh, understood. i re-read the docs and yep, i see that now. misread it. thank you. i'll come back to this if needed later. unless this turns out to be the only way possible somehow. --

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Miod Vallat via Pdns-users
"enable foreign keys" script. HTH, Miod ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Fabian Santiago via Pdns-users
On 4/24/25 1:52 AM, Miod Vallat via Pdns-users wrote: There should be a more detailed error in the group replication plugin logs, can you check what error gets reported there? there is an error: 2025-04-24T15:27:41.272419Z 1861 [ERROR] [MY-011543] [Repl] Plugin group_replication reported

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Fabian Santiago via Pdns-users
it was the sanitization of the records as they came over as we had a bunch of really old records in zones (from the 90s). In brief the method we used was: * Create all zones as secondaries in pdns, with your bind as primary: pdnsutil create-secondary-zone * convert to native when ready

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-24 Thread Chris Wopat via Pdns-users
they came over as we had a bunch of really old records in zones (from the 90s). In brief the method we used was: * Create all zones as secondaries in pdns, with your bind as primary: pdnsutil create-secondary-zone * convert to native when ready: pdnsutil set-kind native You could also do this in

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-23 Thread Miod Vallat via Pdns-users
Re, 2.> zone2sql --named-conf= --gmysql | mysql -u powerdns -p powerdns You are not using zone2sql correctly. You should not pass it a bind zone file, but rather the named.conf bind configuration which references your zone file. HTH, Miod ___ P

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-23 Thread Miod Vallat via Pdns-users
you didn't literally mean to attach the file itself and instead wanted something else. please advise. That's fine. I will have a look at it shortly. Thanks, Miod ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powe

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-23 Thread Fabian Santiago via Pdns-users
hello, On 4/24/25 12:44 AM, Miod Vallat via Pdns-users wrote: The PowerDNS mysql database schema is currently not compatible with mysql group replication. You will need to disable this feature for PowerDNS to work. that's a bummer. may i ask, what you you then recommend for syncin

Re: [Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-23 Thread Miod Vallat via Pdns-users
Hello, [...] > mysql wise, the 2 servers are replicating their data using mysql group replication. pdns itself is NOT doing anything primary -vs- secondary; they're just going to host native zones. error from attempt 1: Apr 23 20:48:38 [bindbackend] Done parsing domains, 0 rejected,

[Pdns-users] need help with pdns authoritative + gmysql backend with mysql group replication-based servers

2025-04-23 Thread fsantiago--- via Pdns-users
hello pdns world, i've been here before but it's been many years, and i certainly did it differently back then and now i'm stuck again; i have 2 servers, intended to be a pair of authoritative dns servers. they both match these general specs: Ubuntu 24.04.2 LTS pdns-server 4.

Re: [Pdns-users] Rectify QNAME issues

2025-04-22 Thread Jacob Bunk Nielsen via Pdns-users
Jason Tremblett via Pdns-users writes: > We are having issues with the way that QNAME minimization works and would > like to know if there is a way to improve our process to resolve > the issue. > > Backend: postgresql DB > Frontend: authoritative server > DNSSEC Enabled w

[Pdns-users] Rectify QNAME issues

2025-04-22 Thread Jason Tremblett via Pdns-users
of a smaller zone with less records the potential to get a NXDOMAIN for a non-cached entry could occur between the load-zone and rectify-zone (although obviously the window would be smaller). Thanks for your input! Jason Tremblett ___ Pdns-users mailing li

Re: [Pdns-users] pdns-recursor metrics review and tuning advice request

2025-04-19 Thread Otto Moerbeek via Pdns-users
ervers and I believe the lua script drops queries that have no > match in that zone. The public zone is being slowly phased out. > > I noted while reviewing the previous server configs and found a comment > about this value but no context for the specific reasoning. This may > exp

Re: [Pdns-users] pdns-recursor metrics review and tuning advice request

2025-04-18 Thread Scott Crace via Pdns-users
/github.com/PowerDNS/pdns/issues/6186 max-negative-ttl=0 /etc/pdns-recursor/recursor.conf --- dnssec: validation: validate incoming: allow_from: - 127.0.0.1/8 - 10.0.0.0/8 - 172.16.0.0/12 - 192.168.0.0/16 - 'fd00::/8' - '2607:B600::/32' l

Re: [Pdns-users] pdns-recursor metrics review and tuning advice request

2025-04-18 Thread Otto Moerbeek via Pdns-users
On Fri, Apr 18, 2025 at 08:28:48AM -0400, Scott Crace via Pdns-users wrote: Hi, Please include your config. That said: You seem to have pretty low cache hit ratio, a high number of outgoing queries. How is your cache configged? Also some throttling is going on. I suspect rec has trouble

[Pdns-users] pdns-recursor metrics review and tuning advice request

2025-04-18 Thread Scott Crace via Pdns-users
Hello all, Long time lurker on the message list and would like some performance and/or tuning advice. We've been using pdns-recursor as internal recursive nameservers for quite some time now. The original implementer of pdns departed and I was recently tasked with replacing or upgrading a

Re: [Pdns-users] successful installation of recursor 5.2 on non-systemd

2025-04-11 Thread Brian Candler via Pdns-users
On 11/04/2025 15:38, Curtis Maurand wrote: https://doc.powerdns.com/authoritative/running.html That documentation is for PDNS Authoritative. I believe you were talking about PDNS Recursor, which is a different piece of software. Source release tarballs for both can be found here: https

Re: [Pdns-users] successful installation of recursor 5.2 on non-systemd

2025-04-11 Thread Otto Moerbeek via Pdns-users
On Thu, Apr 10, 2025 at 12:44:57PM -0400, Curtis Maurand via Pdns-users wrote: > the sysv script is not in the current debian packages and hasn’t been for the > last few versions and the pdns-recursor installation script will delete the > existing sysv script. this has been true

[Pdns-users] PowerDNS Recursor 5.0.10, 5.1.4 and 5.2.2 Released

2025-04-10 Thread Otto Moerbeek via Pdns-users
/YFDVVY3JNYRGSS5ZBDPTPZLFY4E4FNMO/ 2. https://doc.powerdns.com/recursor/changelog/5.0.html#change-5.0.10 3. https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.4 4. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.2 5. https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] successful installation of recursor 5.2 on non-systemd

2025-04-10 Thread Curtis Maurand via Pdns-users
the sysv script is not in the current debian packages and hasn’t been for the last few versions and the pdns-recursor installation script will delete the existing sysv script. this has been true since 4.9. The docs say that the sysv script is in the source tarball, but it’s not there. It

Re: [Pdns-users] successful installation of recursor 5.2 on non-systemd

2025-04-10 Thread Brian Candler via Pdns-users
On 10/04/2025 14:16, Curtis Maurand via Pdns-users wrote: I know that powerdns has dropped support for systems that don't run systemd Citation Needed™.  There is optional systemd integration, but AFAICS it is not required: https://doc.powerdns.com/recursor/appendices/compiling

[Pdns-users] successful installation of recursor 5.2 on non-systemd

2025-04-10 Thread Curtis Maurand via Pdns-users
Hello, I have successfully installed pdns-recursor on a non-systemd equipped system. I know that powerdns has dropped support for systems that don't run systemd, but I wanted to get this on record for others that like powerdns, but don't use systemd. By default the new ve

[Pdns-users] PowerDNS Recursor Security Advisory 2025-01 regarding PowerDNS Recusor 5.2.0

2025-04-07 Thread Otto Moerbeek via Pdns-users
AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&version=3.1 3. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.1 4. https://docs.powerdns.com/recursor/upgrade.html 5. https://mailman.powerdns.com/mailman/listinfo/pdns-users 6. https://github.com/PowerDNS/pdns/issues/new/choose

Re: [Pdns-users] Recursor 5.2.0 with RD=0 forwarded queries

2025-04-05 Thread Olli Attila via Pdns-users
Hi, Perfect. Thanks. OA la 5.4.2025 klo 8.36 Otto Moerbeek (o...@drijf.net) kirjoitti: > On Fri, Apr 04, 2025 at 09:25:04PM +0300, Olli Attila via Pdns-users wrote: > > Hi, > > I think setting the RD flag in dnsdist using > https://www.dnsdist.org/reference/dq.html?highlight=

Re: [Pdns-users] Recursor 5.2.0 with RD=0 forwarded queries

2025-04-05 Thread Otto Moerbeek via Pdns-users
RD(dq) dq.dh:setRD(true) return DNSAction.None -- process further rules end addAction(NotRule(RDRule()), LuaAction(setRD)) -Otto > > Cheers, > OA > > la 5. huhtik. 2025 klo 8.36 Otto Moerbeek kirjoitti: > > > On Fri, Apr 04, 2025 at 09:25:04PM +0300, Olli Attila

Re: [Pdns-users] Recursor 5.2.0 with RD=0 forwarded queries

2025-04-05 Thread Olli Attila via Pdns-users
at 09:25:04PM +0300, Olli Attila via Pdns-users wrote: > > Hi, > > I think setting the RD flag in dnsdist using > https://www.dnsdist.org/reference/dq.html?highlight=rd#DNSHeader:setRD > on the requests forwarded to the recursor should work and get you the > old behaviour back.

Re: [Pdns-users] Recursor 5.2.0 with RD=0 forwarded queries

2025-04-04 Thread Otto Moerbeek via Pdns-users
On Fri, Apr 04, 2025 at 09:25:04PM +0300, Olli Attila via Pdns-users wrote: Hi, I think setting the RD flag in dnsdist using https://www.dnsdist.org/reference/dq.html?highlight=rd#DNSHeader:setRD on the requests forwarded to the recursor should work and get you the old behaviour back. I don&#

[Pdns-users] Recursor 5.2.0 with RD=0 forwarded queries

2025-04-04 Thread Olli Attila via Pdns-users
Hello all, After upgrading from dns-recursor 4.8.x -> 5.2.0 I noticed this happened: Recursor 4.9.x changelog (4.9.0-alpha1 Improvements): "Change the way RD=0 forwarded queries are handled. References: pull request 12425 <https://github.com/PowerDNS/pdns/pull/12425> "

[Pdns-users] First alpha release of PowerDNS DNSdist 2.0.0 released

2025-03-18 Thread Remi Gacogne via Pdns-users
are available from our repository [7]. [1]: https://dnsdist.org [2]: https://dnsdist.org/changelog.html#change-2.0.0-alpha1 [3]: https://dnsdist.org/upgrade_guide.html [4]: https://github.com/PowerDNS/pdns/issues/new/choose [5]: https://downloads.powerdns.com/releases/dnsdist-2.0.0-alpha1.tar.xz [6]: http

Re: [Pdns-users] Problem with Linode NS Servers

2025-03-13 Thread rob777 via Pdns-users
elp ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Problem with Linode NS Servers

2025-03-13 Thread Doug Freed via Pdns-users
This was posted a half hour ago, and is probably related: https://status.linode.com/incidents/m2l4nhd0zyvv -Doug On Thu, Mar 13, 2025 at 9:59 AM rob777 via Pdns-users < pdns-users@mailman.powerdns.com> wrote: > Hi > > I have posted this on /r/dns too - maybe someone here kn

Re: [Pdns-users] Problem with Linode NS Servers

2025-03-13 Thread Brian Candler via Pdns-users
On 13/03/2025 14:59, rob777 via Pdns-users wrote: # My Powerdns Recursor cant resolve stuff from the NS Servers ns1.linode.com <http://ns1.linode.com/> , ns2.linode.com <http://ns2.linode.com/>, ns3.linode.com <http://ns3.linode.com/> # You starting point should b

[Pdns-users] Problem with Linode NS Servers

2025-03-13 Thread rob777 via Pdns-users
Debug Log of my recursor says Server Failure for alpinelinux.org (the same for others domain NS hosted at these linode NS Servers: 2025-03-13T12:38:17.346381+01:00 top-dnsslave-01 pdns-recursor[1048606]: [816] QM alpinelinux.org: Step3 Final resolve: Server Failure/0 I cant open an Support Ti

Re: [Pdns-users] How to force recursions to TCP only

2025-02-28 Thread Otto Moerbeek via Pdns-users
uthoritative servers. Better fix your UDP connectivity. -Otto On Fri, Feb 28, 2025 at 09:10:59AM -0500, Kevin P. Fleming via Pdns-users wrote: > I don't think there are any configuration options in the recursor do to this, > so you'll have to do it in a firewall system

Re: [Pdns-users] How to force recursions to TCP only

2025-02-28 Thread Kevin P. Fleming via Pdns-users
I don't think there are any configuration options in the recursor do to this, so you'll have to do it in a firewall system outside of the recursor. Blocking all outbound traffic to UDP port 53 would take care of it. On Fri, Feb 28, 2025, at 06:45, Carlos N via Pdns-users wrote: &

[Pdns-users] How to force recursions to TCP only

2025-02-28 Thread Carlos N via Pdns-users
to do this or if it is even possible. Documentation doesn't give any clue. Kind regards and thanks in advance. Carlos ___ Pdns-users mailing list Pdns-users@mailman.powerdns.com https://mailman.powerdns.com/mailman/listinfo/pdns-users

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread Peter Zoltan Keresztes (zozo) via Pdns-users
ozo) > wrote: > > 8bit-dns=yes > api=yes > api-key=changeme > cache-ttl=20 > config-dir=/etc/pdns > daemon=yes > default-api-rectify=yes > default-ksk-algorithm=ecdsa256 > default-ksk-size=0 > default-ttl=3600 > direct-dnskey=yes > disable-axfr=yes > distr

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread Peter Zoltan Keresztes (zozo) via Pdns-users
8bit-dns=yes api=yes api-key=changeme cache-ttl=20 config-dir=/etc/pdns daemon=yes default-api-rectify=yes default-ksk-algorithm=ecdsa256 default-ksk-size=0 default-ttl=3600 direct-dnskey=yes disable-axfr=yes distributor-threads=3 dname-processing=yes dnssec-key-cache-ttl=30 dnsupdate=yes domain

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread Curtis Maurand via Pdns-users
sorry for the bandwidth: pdnsutil rectify-zone On 2/27/25 09:47, Curtis Maurand via Pdns-users wrote: I can't type: pdnsutil rectify Cheers, Curtis On 2/27/25 09:46, Curtis Maurand via Pdns-users wrote: Is the domain signed? Did you run pdnsutil rectivy ? On 2/27/25 06:58,

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread Curtis Maurand via Pdns-users
I can't type: pdnsutil rectify Cheers, Curtis On 2/27/25 09:46, Curtis Maurand via Pdns-users wrote: Is the domain signed? Did you run pdnsutil rectivy ? On 2/27/25 06:58, Peter Zoltan Keresztes (zozo) via Pdns-users wrote: I have reinstalled the pdns exported the zones to csv

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread Curtis Maurand via Pdns-users
Is the domain signed? Did you run pdnsutil rectivy ? On 2/27/25 06:58, Peter Zoltan Keresztes (zozo) via Pdns-users wrote: I have reinstalled the pdns exported the zones to csv files and readied the used one using pdnsutil however when I try to save sometimes I am getting the same errors

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread frank--- via Pdns-users
e: >> >> Try increasing max_allowed_packet in your mysqld config, see if that helps... >> >> >> Frank >> >>> On 27 Feb 2025, at 15:10, Peter Zoltan Keresztes (zozo) via Pdns-users >>> wrote: >>> >>> This is really strange

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread Peter Zoltan Keresztes (zozo) via Pdns-users
Just did that increased it to 128M no change whatsoever. Peter > On 27 Feb 2025, at 16:22, fr...@kiwazo.be wrote: > > Try increasing max_allowed_packet in your mysqld config, see if that helps... > > > Frank > >> On 27 Feb 2025, at 15:10, Peter Zoltan Kere

Re: [Pdns-users] Need help after the upgrade

2025-02-27 Thread frank--- via Pdns-users
Try increasing max_allowed_packet in your mysqld config, see if that helps... Frank > On 27 Feb 2025, at 15:10, Peter Zoltan Keresztes (zozo) via Pdns-users > wrote: > > This is really strange situation. > I have the list of records added to the domain. I can check pdnsuti

  1   2   3   4   5   6   7   8   9   10   >