[prev in list] [next in list] [prev in thread] [next in thread]
List: bind-workers
Subject: Possible issue with BIND 9.9.0/9.9.1
From: "Luther, Dan" <Dan.Luther () Level3 ! com>
Date: 2012-05-31 17:46:05
Message-ID: 37812A94EF532146AE52D13A98302ABD0F1BA444 () VIDCEMBX0002 ! corp ! global ! level3 ! com
[Download RAW message or body]
Hello,
When running the BIND 9.9.1 with auto-dnssec set to maintain and inline signing, I've \
run into several instances where non-standard record types become corrupted. This is \
on a Sun T2000 server, running Solaris 10. I've tested with both BIND 9.9.1 and 9.9.0 \
with the same results.
Using this zone file:
[root@dns1] /usr/local/dns/dnssec1/zones> cat m.202.216.in-addr.arpa
; m.202.216.in-addr.arpa
$TTL 86400
@ IN SOA dnssec1.Level3.net. dns.level3.net. (
2012052201 ; serial
3600 ; refresh
900 ; retry
2592000 ; expire
86400 ) ; min ttl
; Authoritative Name Servers
@ IN NS dnssec1.Level3.net.
@ IN NS dnssec2.Level3.net.
; Deny all route announcements except those authorized. (RLOCK)
@ IN TYPE65400 \# 0
; 216.202.0.0/16 SRO 3356 (SRO = "Secure Route Origin")
@ IN TYPE65401 \# 4 00000d1c
; 216.202.124.0/23 SRO 21889 (SRO = "Secure Route Origin")
I'm specifically looking at the "TYPE65400" record above.
The configuration file looks as follows:
options {
# General BIND control options
notify yes;
recursion no;
auth-nxdomain no;
zone-statistics yes;
transfer-format many-answers;
# BIND accessibility options
allow-transfer { 209.244.127.174; localhost; };
allow-query { any; };
allow-query-on { any; };
allow-query-cache { any; };
allow-query-cache-on { any; };
# Server identification options
version "hostmaster@Level3.net";
server-id "dns2.newyork1.Level3.net";
hostname "dns2.newyork1.Level3.net";
# Network and interface configuration options
use-v4-udp-ports { range 8192 65535; };
listen-on { 209.244.7.57; };
notify-source 209.244.7.57;
transfer-source 209.244.7.57;
query-source address 209.244.7.57 port *;
interface-interval 5;
use-alt-transfer-source no;
# File system options
directory "/usr/local/dns/dnssec1";
dump-file "dump";
pid-file "pid";
statistics-file "logs/stats";
# DNSSEC options
dnssec-enable yes;
key-directory "keys";
inline-signing yes;
dnssec-loadkeys-interval 60;
# Performance options
minimal-responses yes;
transfers-in 512;
transfers-out 512;
transfers-per-ns 48;
tcp-clients 500;
max-transfer-time-in 10;
max-transfer-time-out 10;
max-refresh-time 43200;
max-retry-time 900;
serial-query-rate 200;
cleaning-interval 2;
min-retry-time 15;
max-cache-ttl 43200;
max-cache-size 256000000;
min-refresh-time 120;
max-ncache-ttl 900;
};
include "/usr/local/dns/etc/bad-clients.conf";
acl query-clients {
192.168.53.0/24;
!bad-clients;
any;
include "/usr/local/dns/dnssec1/conf/named.rndc";
include "/usr/local/dns/etc/named.logging.9.x";
zone "." in {
type hint;
file "/usr/local/dns/etc/root.cache";
};
/* ID zone */
zone "nameserver" in {
type master;
file "/usr/local/dns/etc/nameserver";
};
. . .
zone "m.202.216.in-addr.arpa" in {
type master;
file "zones/m.202.216.in-addr.arpa";
allow-update { localhost; };
auto-dnssec maintain;
inline-signing yes;
key-directory "keys";
check-names ignore;
};
Queries for this record show an obvious corruption:
[root@dns1] /usr/local/dns/dnssec1/zones> dig @dnssec1 m.202.216.in-addr.arpa \
TYPE65400 +dnssec +multi ;; Truncated, retrying in TCP mode.
; <<>> DiG 9.9.1 <<>> @dnssec1 m.202.216.in-addr.arpa TYPE65400 +dnssec +multi
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18188
;; flags: qr aa rd; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;m.202.216.in-addr.arpa. IN TYPE65400
;; ANSWER SECTION:
m.202.216.in-addr.arpa. 86400 IN TYPE65400 \# 48830 ( \
00000001000151800000FF7800000009000000000000
0000002A4D90000000000000003E0000000000000000
002A51A000000000FFFFFFFFFFFFFFFF000000000000
00000001000000000001000151800000FF7800000009
0000000000000000002A4C00000000000000005A0000
000000000000002A4F7000000000FFFFFFFFFFFFFFFF
000000000000000000010000002A51A0000000000000
00000000000000000000FFFFFFFFFFFFFFFFC00E070E
03124AEE002A4B100060000001300131013101310131
013101300700020406080A0CBEBEBEBEBEBE00000001
000151800000FF780000000900000000000000000036
2FB00000000000000091000000000000000000362E20
. . .
000000000000000000010029DB6000000001BEBEBEBE
0004000000004D580000000000000000000000000000
00000000000000000000000000000000000000000000
00000000000000000000000000000000000000000000
000000BE000000000000000000000000000000000000
00000000000000000000000000000000000000000000
00000000000000000000000000000000000000000000
00000000000000000000000000000000000000000000
000000000000000000000000 )
m.202.216.in-addr.arpa. 86400 IN RRSIG TYPE65400 5 5 86400 (
20120630132728 20120531122728 60792 \
m.202.216.in-addr.arpa.
kwvclR3r1j24reESiD1oYcQ9026xjflfHrfO0/gt4beG
PTWssGfpT7vDnqYX3xjUgLrYaE3hxzr6wonBHwmrifyQ
nkgnoywE7CE+XVajB9834LCwRzbNT8UAIhL1xsDqsJlr
/7j4f5IiNuAnxj3kFJTFQ0dKsIBKwk64dc6DZIg= )
;; Query time: 275 msec
;; SERVER: 209.244.7.57#53(209.244.7.57)
;; WHEN: Thu May 31 17:35:20 2012
;; MSG SIZE rcvd: 49075
The "MSG SIZE rcvd" status says it all. Additionally, I'm getting sporadic messages \
where my inline-signed zones have "No signing records found", including this one, and \
experiencing crashes when trying to transfer these zones to my secondary.
I've experienced this on several other zones, forcing me to revert to the "old \
school" method of signing zones. Has anyone experienced such an issue, and can I \
supply more information to help identify what is causing this error, and more \
importantly, how to fix it?
Dan Luther
Operations Engineer
Systems Operation Engineering
Level 3 Communications
One Technology Center, Tulsa OK 74103
p: 918-547-4370
e: dan.luther@level3.com<mailto:name.name@level3.com>
[Attachment #3 (text/html)]
<html xmlns:v="urn:schemas-microsoft-com:vml" \
xmlns:o="urn:schemas-microsoft-com:office:office" \
xmlns:w="urn:schemas-microsoft-com:office:word" \
xmlns:x="urn:schemas-microsoft-com:office:excel" \
xmlns:dt="uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" \
xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" \
xmlns="http://www.w3.org/TR/REC-html40"> <head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style>
<!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page Section1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
{page:Section1;}
-->
</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="Section1">
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Hello, <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">When running the BIND 9.9.1 with auto-dnssec set to maintain and \
inline signing, I’ve run into several instances where non-standard record types \
become corrupted. This is on a Sun T2000 server, running Solaris 10<span \
style="color:black">. I’ve tested with both BIND 9.9.1 and 9.9.0 with the same \
results.</span><span style="color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Using this zone file:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">[root@dns1] /usr/local/dns/dnssec1/zones> cat \
m.202.216.in-addr.arpa &nbs \
p; \
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">; m.202.216.in-addr.arpa<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">$TTL 86400<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier \
New"">@ \
IN SOA dnssec1.Level3.net. \
dns.level3.net. (<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> &nb \
sp; \
2012052201 ; serial<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> &nb \
sp; \
3600 ; refresh<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
900 ; retry<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
2592000 ; expire<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> &nb \
sp; \
86400 ) ; min ttl<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">; Authoritative Name Servers<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">@ \
IN NS \
dnssec1.Level3.net.<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">@ \
IN NS \
dnssec2.Level3.net.<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">; Deny all route announcements except those \
authorized. (RLOCK)<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">@ \
IN TYPE65400 \# 0<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""><o:p> </o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""><o:p> </o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">; \
216.202.0.0/16 \
SRO 3356 (SRO = "Secure Route \
Origin")<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">@ \
IN TYPE65401 \# 4 00000d1c<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""><o:p> </o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">; \
216.202.124.0/23 \
SRO 21889 (SRO = "Secure Route Origin")<o:p></o:p></span></p> \
<p class="MsoNormal"><o:p> </o:p></p> <p class="MsoNormal">I’m \
specifically looking at the “TYPE65400” record above. <o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The configuration file looks as follows:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">options {<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New""> # General BIND control \
options<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> notify \
yes;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> recursion \
no;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> auth-nxdomain \
no;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> zone-statistics \
yes;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> transfer-format \
many-answers;<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> # BIND accessibility options<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
allow-transfer { 209.244.127.174; localhost; };<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
allow-query { any; };<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> allow-query-on { any; \
};<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> allow-query-cache { any; \
};<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> allow-query-cache-on { any; \
};<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> # Server identification options<o:p></o:p></span></p> \
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
version "hostmaster@Level3.net";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> server-id \
"dns2.newyork1.Level3.net";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> hostname \
"dns2.newyork1.Level3.net";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> # Network and interface configuration \
options<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> use-v4-udp-ports { range 8192 \
65535; };<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> listen-on { 209.244.7.57; \
};<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> notify-source \
209.244.7.57;<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> transfer-source \
209.244.7.57;<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> query-source address \
209.244.7.57 port *;<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> interface-interval \
5;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> use-alt-transfer-source \
no;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> # File system options<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
directory "/usr/local/dns/dnssec1";<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
dump-file "dump";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> pid-file \
"pid";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> statistics-file \
"logs/stats";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> # DNSSEC options<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
dnssec-enable yes;<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> key-directory \
"keys";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> inline-signing \
yes;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> dnssec-loadkeys-interval \
60;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> # Performance options<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> \
minimal-responses yes;<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> transfers-in \
512;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> transfers-out \
512;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> transfers-per-ns \
48;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> tcp-clients \
500;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> max-transfer-time-in \
10;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> max-transfer-time-out \
10;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> max-refresh-time \
43200;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> max-retry-time \
900;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> serial-query-rate \
200;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> cleaning-interval \
2;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> min-retry-time \
15;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> max-cache-ttl \
43200;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> max-cache-size \
256000000;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> min-refresh-time \
120;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New""> \
max-ncache-ttl 900;<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""><o:p> </o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">};<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">include "/usr/local/dns/etc/bad-clients.conf";<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">acl query-clients {<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New""> 192.168.53.0/24;<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New""> !bad-clients;<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New""> any;<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New""><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">include \
"/usr/local/dns/dnssec1/conf/named.rndc";<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">include \
"/usr/local/dns/etc/named.logging.9.x";<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""><o:p> </o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">zone "." in {<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> type \
hint;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> file \
"/usr/local/dns/etc/root.cache";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">};<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">/* ID zone */<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">zone "nameserver" in {<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""> type \
master;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> file \
"/usr/local/dns/etc/nameserver";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">};<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">. . . <o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New""><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">zone "m.202.216.in-addr.arpa" in \
{<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> type \
master;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> file \
"zones/m.202.216.in-addr.arpa";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> allow-update { localhost; \
};<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> auto-dnssec \
maintain;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> inline-signing \
yes;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> key-directory \
"keys";<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> check-names \
ignore;<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New"">};<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Queries for this record show an obvious \
corruption:<o:p></o:p></p> <p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier New"">[root@dns1] /usr/local/dns/dnssec1/zones> dig \
@dnssec1 m.202.216.in-addr.arpa TYPE65400 +dnssec +multi \
<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New"">;; Truncated, retrying \
in TCP mode.<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">; <<>> DiG 9.9.1 <<>> @dnssec1 \
m.202.216.in-addr.arpa TYPE65400 +dnssec +multi<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">; (1 server found)<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">;; global options: \
+cmd<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New"">;; Got \
answer:<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New"">;; \
->>HEADER<<- opcode: QUERY, status: NOERROR, id: \
18188<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New"">;; flags: qr aa rd; \
QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">;; WARNING: recursion requested but not \
available<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">;; OPT PSEUDOSECTION:<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">; EDNS: version: 0, flags: do; udp: 4096<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">;; QUESTION SECTION:<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New"">;m.202.216.in-addr.arpa. IN \
TYPE65400<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">;; ANSWER SECTION:<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">m.202.216.in-addr.arpa. 86400 IN TYPE65400 \# 48830 ( \
00000001000151800000FF7800000009000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
0000002A4D90000000000000003E0000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
002A51A000000000FFFFFFFFFFFFFFFF000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
00000001000000000001000151800000FF7800000009<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
0000000000000000002A4C00000000000000005A0000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
000000000000002A4F7000000000FFFFFFFFFFFFFFFF<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
000000000000000000010000002A51A0000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
00000000000000000000FFFFFFFFFFFFFFFFC00E070E<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
03124AEE002A4B100060000001300131013101310131<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
013101300700020406080A0CBEBEBEBEBEBE00000001<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> \
000151800000FF780000000900000000000000000036<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier \
New""> &nb \
sp; \
2FB00000000000000091000000000000000000362E20<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New""><o:p> </o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">. . . <o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier \
New""> &nb \
sp; \
000000000000000000010029DB6000000001BEBEBEBE<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
0004000000004D580000000000000000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
00000000000000000000000000000000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> \
00000000000000000000000000000000000000000000<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt;
font-family:"Courier \
New""> &nb \
sp; \
000000BE000000000000000000000000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
00000000000000000000000000000000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
00000000000000000000000000000000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
00000000000000000000000000000000000000000000<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
000000000000000000000000 )<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">m.202.216.in-addr.arpa. 86400 IN RRSIG TYPE65400 5 5 86400 \
(<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""> &nb \
sp; \
20120630132728 20120531122728 60792 \
m.202.216.in-addr.arpa.<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""> &nb \
sp; \
kwvclR3r1j24reESiD1oYcQ9026xjflfHrfO0/gt4beG<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
PTWssGfpT7vDnqYX3xjUgLrYaE3hxzr6wonBHwmrifyQ<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
nkgnoywE7CE+XVajB9834LCwRzbNT8UAIhL1xsDqsJlr<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier \
New""> &nb \
sp; \
/7j4f5IiNuAnxj3kFJTFQ0dKsIBKwk64dc6DZIg= )<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">;; Query time: 275 msec<o:p></o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New"">;; SERVER: 209.244.7.57#53(209.244.7.57)<o:p></o:p></span></p> <p \
class="MsoNormal" style="margin-left:.5in"><span style="font-size:8.0pt; \
font-family:"Courier New"">;; WHEN: Thu May 31 17:35:20 \
2012<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier New"">;; MSG SIZE rcvd: \
49075<o:p></o:p></span></p> <p class="MsoNormal" style="margin-left:.5in"><span \
style="font-size:8.0pt; font-family:"Courier \
New""><o:p> </o:p></span></p> <p class="MsoNormal" \
style="margin-left:.5in"><span style="font-size:8.0pt; font-family:"Courier \
New";color:black"><o:p> </o:p></span></p> <p class="MsoNormal"><span \
style="color:black">The “MSG SIZE rcvd” status says it all. Additionally, \
I’m getting sporadic messages where my inline-signed zones have “No \
signing records found”, including this one, and experiencing crashes when \
trying to transfer these zones to my secondary.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’ve experienced this on several other zones, forcing me \
to revert to the “old school” method of signing zones. Has anyone \
experienced such an issue, and can I supply more information to help identify what is \
causing this error, and more importantly, how to fix it?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b><span \
style="font-size:9.0pt;font-family:"Arial","sans-serif"; \
color:#CC3333">Dan Luther</span></b><span style="color:#1F497D"><br> </span><b><span \
style="font-size:8.0pt;font-family:"Arial","sans-serif"; \
color:#333333">Operations Engineer<o:p></o:p></span></b></p> <p \
class="MsoNormal"><b><span \
style="font-size:8.0pt;font-family:"Arial","sans-serif"; \
color:#333333">Systems Operation Engineering <br>
</span></b><b><span style="font-size:8.0pt;font-family:"Arial","sans-serif";
color:#7A7A7A">Level 3 Communications<br>
One Technology Center, Tulsa OK 74103<br>
p: 918-547-4370<br>
e: <a href="mailto:name.name@level3.com">dan.luther@level3.com</a></span></b><span \
style="color:#1F497D"><o:p></o:p></span></p> <p \
class="MsoNormal"><o:p> </o:p></p> </div>
</body>
</html>
_______________________________________________
bind-workers mailing list
bind-workers@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-workers
--===============2909692801975828354==--
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic