Re: DNSSEC



On Tue, May 4, 2010 at 10:43 AM, Stephane Bortzmeyer <bortzmeyer@xxxxxx>wrote:

On Tue, May 04, 2010 at 10:27:25AM -0400,
Linux Addict <linuxaddict7@xxxxxxxxx> wrote
a message of 89 lines which said:

lacks EDNS, defaults to 512"
DNS reply size limit is at least 490"
"Tested at 2010-05-04 14:21:02 UTC"

You edited the responses (which includes an IP address). Is it the IP
address of your resolver? There is may be a forwarder which does not
have EDNS.

Second possibility, a middlebox mangles your packets and deletes EDNS
options.


Actually that IP was our external NAT. One information I neglected to
mention is bind forwards to a tinydns appliance which of course does not
support DNSSEC for obvious reasons.

So what are my options now? Will the internet work for me tomorrow?
At least I have company in Google..

dig +short rs.dns-oarc.net txt @8.8.8.8
rst.x476.rs.dns-oarc.net.
rst.x485.x476.rs.dns-oarc.net.
rst.x490.x485.x476.rs.dns-oarc.net.
"64.233.168.94 DNS reply size limit is at least 490"
"64.233.168.94 lacks EDNS, defaults to 512"
"Tested at 2010-05-04 15:00:07 UTC"


Relevant Pages

  • Re: DNSSEC
    ... Linux Addict wrote ... DNS reply size limit is at least 490" ... You edited the responses. ... a middlebox mangles your packets and deletes EDNS ...
    (comp.protocols.dns.bind)
  • Re: SBS Unable to resolve domain but Bind can?
    ... The SBS server is unable to resolve some domains ... Using bind or forwarders is out of the question as I would like to ... increases efficiency by allowing DNS to resolve larger DNS responses without ... Large DNS responses are answers that have several CNAME or MX ...
    (microsoft.public.windows.server.dns)
  • Re: DNS-Urgent-Help-Please
    ... but the responses are only seen attached to the message (unless ... | i am going to install KTC.COM as the Forest Root Domain, & Install DNS ... Bring New Server. ...
    (microsoft.public.win2000.general)
  • Re: DNS Help- Urgent
    ... but the responses are only seen attached to the message (unless ... | i am going to install KTC.COM as the Forest Root Domain, & Install DNS ... Bring New Server. ...
    (microsoft.public.win2000.cmdprompt.admin)
  • Re: DNS-Urgent -Help-is Required
    ... but the responses are only seen attached to the message (unless ... | i am going to install KTC.COM as the Forest Root Domain, & Install DNS ... Bring New Server. ...
    (microsoft.public.win2000.advanced_server)