Re: [Pdns-users] Notify being ignored

2017-05-04 Thread David Jones
From: Pdns-users on behalf of Fabian A. Santiago   >On May 4, 2017 6:15:35 AM EDT, Remi Gacogne wrote: >>On 05/04/2017 12:09 PM, Fabian A. Santiago wrote: 'allow-notify-from' defaults to '0.0.0.0/0,::/0', which allows everything. Of course additional checks are performed afterward

Re: [Pdns-users] Notify being ignored

2017-05-04 Thread Fabian A. Santiago
On May 4, 2017 6:15:35 AM EDT, Remi Gacogne wrote: >On 05/04/2017 12:09 PM, Fabian A. Santiago wrote: >>> 'allow-notify-from' defaults to '0.0.0.0/0,::/0', which allows >>> everything. Of course additional checks are performed afterwards, >>> like checking if the configuration requires a valid TS

Re: [Pdns-users] Notify being ignored

2017-05-04 Thread Remi Gacogne
On 05/04/2017 12:09 PM, Fabian A. Santiago wrote: >> 'allow-notify-from' defaults to '0.0.0.0/0,::/0', which allows >> everything. Of course additional checks are performed afterwards, >> like checking if the configuration requires a valid TSIG signature, >> whether we are authoritative for the do

Re: [Pdns-users] Notify being ignored

2017-05-04 Thread Fabian A. Santiago
On May 4, 2017 3:52:40 AM EDT, Remi Gacogne wrote: >On 05/04/2017 12:10 AM, David Jones wrote: >> I have a PowerDNS server setup as a slave and see this in my logs >> constantly: >> >> Received NOTIFY for example.com from 1.2.3.4 but remote is not >> permitted by TSIG or allow-notify-from >> >>

Re: [Pdns-users] Notify being ignored

2017-05-04 Thread Remi Gacogne
On 05/04/2017 12:10 AM, David Jones wrote: > I have a PowerDNS server setup as a slave and see this in my logs > constantly: > > Received NOTIFY for example.com from 1.2.3.4 but remote is not > permitted by TSIG or allow-notify-from > > I was hoping to not have to maintain a long list of master I

[Pdns-users] Notify being ignored

2017-05-03 Thread David Jones
I have a PowerDNS server setup as a slave and see this in my logs constantly: Received NOTIFY for example.com from 1.2.3.4 but remote is not permitted by TSIG or allow-notify-from I was hoping to not have to maintain a long list of master IPs in the allow-notify-from. One would think that the