1 |
On Tue, 17 Sep 2019 18:33:51 -0400, |
2 |
Ian Zimmerman wrote: |
3 |
> |
4 |
> On 2019-09-17 13:01, John Covici wrote: |
5 |
> |
6 |
> > > > Also, when I restart named (which I have now done automatically by |
7 |
> > > > systemd) it gives me a lot of errors like the following: |
8 |
> > > > Sep 17 03:11:59 ccs.covici.com named[3299910]: validating arpa/DS: no |
9 |
> > > > valid signature found |
10 |
> > > > or this: |
11 |
> > > > Sep 17 03:12:00 ccs.covici.com named[3299910]: validating com/DS: no |
12 |
> > > > valid signature found |
13 |
> > > |
14 |
> > > This looks like a DNSSEC problem. I don't run bind on my gentoo system, |
15 |
> > > but I did this: |
16 |
> |
17 |
> > > [snipped] |
18 |
> |
19 |
> > > Try running "ldd /usr/sbin/named". Is openssl (ie. libssl and |
20 |
> > > libcrypto) part of the output? |
21 |
> |
22 |
> > libcrypto is there along with libgnutls, but no libssl. |
23 |
> |
24 |
> Ok, so it probably is built with DNSSEC support. |
25 |
> |
26 |
> How do you populate your cache? Do you recurse to the root servers, or |
27 |
> do you have a "forwarder" (for example, your ISP server) to which you |
28 |
> pass all queries that miss the cache? |
29 |
|
30 |
I have more than one, but they are forwarders. |
31 |
|
32 |
-- |
33 |
Your life is like a penny. You're going to lose it. The question is: |
34 |
How do |
35 |
you spend it? |
36 |
|
37 |
John Covici wb2una |
38 |
covici@××××××××××.com |