As a lazy slacker I do wonder about such a knot-in-a-nutshell-for-tor-exit-relay-operator-dummies doc ?
;)
--
Toralf
PGP: C4EACDDE 0076E94E, OTR: 420E74C8 30246EE7
Hi,
This is mainly a question for the Knot developers. Suppose I have:
template:
- id: default
acl: acl1
zone:
- domain: zone
acl: acl2
Does "zone" get "acl2" or "acl1, acl2" applied to it?
Regards,
Anand
Hi fellow Knot DNS users and other mailing list lurkers,
CZ.NIC just released a new version of Knot DNS. There are some bug fixes
and improvements as usual.
We fixed missing glue records in some responses, and there were some
other minor nits.
The most notable improvement was a speed-up of conf-commit and conf-diff
operations when using zonedb. Users with hundred thousands zones and
more will be amazed (we hope).
There's also new EDNS Client Subnet API in libknot soon to be used
in our sibling project Knot Resolver.
On the new features front, kdig now can print TLS hierarchy for DNS
over TLS, the knotc now contains zone-purge command and we have new
mod-whoami module and new dnstap logging options contributed by
Robert Edmonds.
We would also like to invite everyone to migrate from Knot DNS 1.6.x
to the current stable Knot DNS 2.x.x release.
And that's it! Thank you for using Knot DNS. And we are really looking
forward to your feedback.
Full changelog:
https://gitlab.labs.nic.cz/labs/knot/raw/v2.3.1/NEWS
Sources:
https://secure.nic.cz/files/knot-dns/knot-2.3.1.tar.xz
GPG signature:
https://secure.nic.cz/files/knot-dns/knot-2.3.1.tar.xz.asc
Documentation:
https://www.knot-dns.cz/docs/2.x/html/
Regards,
--
Ondřej Surý -- Technical Fellow
--------------------------------------------
CZ.NIC, z.s.p.o. -- Laboratoře CZ.NIC
Milesovska 5, 130 00 Praha 3, Czech Republic
mailto:ondrej.sury@nic.cz https://nic.cz/
--------------------------------------------
I would like to thank Jan Včelák for submitting the gnutls30 package
into EPEL 6. This allows one to build Knot 2 for RHEL/CentOS 6 without
having to hunt down any dependencies. We still run CentOS 6 and it's
useful to be able to upgrade to Knot 2 on our servers. Thanks Jan!
Regards,
Anand
Hi everybody!
Today I wrote some code to test support for DNS Cookies. But unfortunately
I couldn't find any servers supporting DNS Cookies.
Of course this is most likely an error in my code.
I couldn't find anything in the documentation, so my question is, does knot
2.3.0 support DNS Cookies?
Could someone please point me to a server supporting DNS Cookies?
What would be a good test?
Right now I do send a query with a cookie and see if I get a cookie in
return.
Kind Regards
Ulrich
--
Ulrich Wisser
ulrich(a)wisser.se
On 2016-08-22 19:55, Hugo Salgado wrote:
> Hi Daniel.
> Yes, I changed the storage directory to other location with right
> permissions, and now the logs said:
>
> 2016-08-22T17:52:21 info: [manojitos.cl] zone loader, semantic check,
> completed
> 2016-08-22T17:52:21 info: [manojitos.cl] loaded, serial 2016010416 ->
> 2016010417
> 2016-08-22T17:52:21 info: [manojitos.cl] NOTIFY, outgoing,
> 200.1.123.7@53: serial 2016010417
> 2016-08-22T17:52:22 info: [manojitos.cl] IXFR, outgoing,
> 200.1.123.7@16933: incomplete history, fallback to AXFR
> 2016-08-22T17:52:22 info: [manojitos.cl] AXFR, outgoing,
> 200.1.123.7@16933: started, serial 2016010417
> 2016-08-22T17:52:22 info: [manojitos.cl] AXFR, outgoing,
> 200.1.123.7@16933: finished, 0.00 seconds, 1 messages, 3820 bytes
>
> So there's no error.
>
> Thanks a lot. Can I suggest to improve the previous error log? Maybe
> if it can say "bad permission" instead of "not enough memory" could
> be better to administrators :)
>
Of course, the message is very confusing.
Best,
Daniel
> Best,
>
> Hugo
>
>
> On 08/22/2016 01:22 PM, daniel.salzman(a)nic.cz wrote:
>> Hi,
>>
>> You have the storage directory under /etc. I suspect the server is not
>> allowed to create a zone journal file there. The journal is important
>> for IXFR.
>> Could you verify that? In such a case you can configure proper
>> zone.file location
>> but different zone.storage directory.
>>
>> Daniel
>>
>> On 2016-08-22 16:18, Hugo Salgado wrote:
>>> Hi Daniel. Here I'm attaching my .conf.
>>>
>>> Thanks a lot!
>>>
>>> Hugo
>>>
>>> On 08/22/2016 05:46 AM, Daniel Salzman wrote:
>>>> Hi Hugo,
>>>>
>>>> I can't reproduce your problem. Could you send me your configuration
>>>> file
>>>> please? Don't forget to mangle sensitive information, like TSIG key.
>>>>
>>>> Thank you,
>>>> Daniel
>>>>
>>>> On 08/19/2016 07:57 PM, Hugo Salgado wrote:
>>>>> Hi.
>>>>> I have a KNOT master with a small zone (32 records), which is
>>>>> logging an
>>>>> error after the secondary (BIND) tries to update the zone. AFAIK,
>>>>> Bind
>>>>> tries with IXFR first, but my master says:
>>>>>
>>>>> 2016-08-19T16:32:12 error: [manojitos.cl] IXFR, outgoing,
>>>>> 200.1.123.7@29095: failed to start (not enough memory)
>>>>>
>>>>> After that the secondary retries with AXFR, and that works:
>>>>>
>>>>> 2016-08-19T16:32:12 info: [manojitos.cl] AXFR, outgoing,
>>>>> 200.1.123.7@13644: started, serial 2016011013
>>>>> 2016-08-19T16:32:12 info: [manojitos.cl] AXFR, outgoing,
>>>>> 200.1.123.7@13644: finished, 0.00 seconds, 1 messages, 2573 bytes
>>>>>
>>>>> The error is the same the first time I provision the zone in the
>>>>> secondary as in following updates. Is there a bug in the error
>>>>> message,
>>>>> or should I worry for some memory requirement in my server (or
>>>>> service)?
>>>>>
>>>>> I'm with Knot 2.3.0 on a FreeBSD 10.3-release-p7. The secondary is
>>>>> not
>>>>> under my administration, but I was told is Bind with an up-to-date
>>>>> version.
>>>>>
>>>>> Thanks!
>>>>>
>>>>> Hugo
>>>>>
>>>>> _______________________________________________
>>>>> knot-dns-users mailing list
>>>>> knot-dns-users(a)lists.nic.cz
>>>>> https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users
>>>>
Hi,
I recently tested the mod-dnsproxy performance and I am disappointed in
the results:
Knot in our test setup can do ~320K QPS.
When using our own proxy in front of knot, we achieve quite a
performance hit, only able to do ~120K QPS.
However, when configuring knot to use the mod-dnsproxy, the performance
drops to ~7K QPS.
I am planning to investigate what causes this significant drop, but if
you have any insights or other measurements already I would love to hear
about them.
Best regards,
Matthijs