Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #192691 > unrolled thread
| Started by | 啊肥坚lolz <rex12425@gmail.com> |
|---|---|
| First post | 2018-02-19 18:10 +0100 |
| Last post | 2018-03-09 19:30 +0100 |
| Articles | 17 — 7 participants |
Back to article view | Back to linux.debian.user
Issues while installing Debian 啊肥坚lolz <rex12425@gmail.com> - 2018-02-19 18:10 +0100
Re: Issues while installing Debian Hans <hans.ullrich@loop.de> - 2018-02-19 18:10 +0100
Re: Issues while installing Debian Raju Devidas <rajudev@disroot.org> - 2018-02-19 19:00 +0100
dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-02-28 01:30 +0100
Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-02-28 06:50 +0100
Re: Re: dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-03-01 02:10 +0100
Re: Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-01 07:40 +0100
Re: dnsmasq and SOA Curt <curty@free.fr> - 2018-03-02 22:00 +0100
Re: Re: dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-03-06 03:00 +0100
Re: Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-06 07:30 +0100
Re: Re: Re: dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-03-07 22:20 +0100
Re: Re: Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-08 10:00 +0100
Re: dnsmasq and SOA Jacques Rodary <rodaryj@free.fr> - 2018-03-08 19:00 +0100
Re: dnsmasq and SOA Jacques Rodary <rodaryj@free.fr> - 2018-03-09 03:40 +0100
Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-09 08:40 +0100
Re: dnsmasq and SOA Jacques Rodary <rodaryj@free.fr> - 2018-03-09 18:30 +0100
Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-09 19:30 +0100
| From | 啊肥坚lolz <rex12425@gmail.com> |
|---|---|
| Date | 2018-02-19 18:10 +0100 |
| Subject | Issues while installing Debian |
| Message-ID | <vkX6V-5Pi-5@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Hello Debian Team, I faced an issue while installing Debian. Please Have A Look At My Issue If Can, Thank You. I'm using non-graphical (text) installer to install Debian, After a manual partitioning, The installation started(system installation) After installing till 7% it say installation step failed, I started the installation again(and even formatted the disk), This problem still occurred. This issue many people may happened before. So I searched online(google) and didn't found any solution. I even looked into the debian installation documentation. Here are some of my computer specifications for you if you requires: Intel Core 2 Duo E6400 1GB RAM(1014MB) Intel Express Chipset Q45 The Installation Images(ISO) I downloaded from debian website is a i386 architecture live image(DVD). Please Reply If You Need More Information About My Issue. Thanks For Your Reading. Looking Forward For Your Reply.
[toc] | [next] | [standalone]
| From | Hans <hans.ullrich@loop.de> |
|---|---|
| Date | 2018-02-19 18:10 +0100 |
| Message-ID | <vkX6V-5Pi-15@gated-at.bofh.it> |
| In reply to | #192691 |
Am Montag, 19. Februar 2018, 17:44:49 CET schrieb 啊肥坚lolz: Don't use a live debian dvd. Use the official installer cd/dvd fromn debian's site. This is Debian, not Ubuntu! Good luck Hans > Hello Debian Team, > > I faced an issue while installing Debian. > Please Have A Look At My Issue If Can, Thank You. > > I'm using non-graphical (text) installer to install Debian, After a manual > partitioning, The installation started(system installation) > > After installing till 7% it say installation step failed, I started the > installation again(and even formatted the disk), This problem still > occurred. > > This issue many people may happened before. > So I searched online(google) and didn't found any solution. I even looked > into the debian installation documentation. > > Here are some of my computer specifications for you if you requires: > > Intel Core 2 Duo E6400 > 1GB RAM(1014MB) > Intel Express Chipset Q45 > > The Installation Images(ISO) I downloaded from debian website is a i386 > architecture live image(DVD). > > Please Reply If You Need More Information About My Issue. > > Thanks For Your Reading. > Looking Forward For Your Reply.
[toc] | [prev] | [next] | [standalone]
| From | Raju Devidas <rajudev@disroot.org> |
|---|---|
| Date | 2018-02-19 19:00 +0100 |
| Message-ID | <vkXTj-65P-9@gated-at.bofh.it> |
| In reply to | #192691 |
On 02/19/2018 10:14 PM, 啊肥坚lolz wrote: > Hello Debian Team, > > I faced an issue while installing Debian. > Please Have A Look At My Issue If Can, Thank You. > > I'm using non-graphical (text) installer to install Debian, After a > manual partitioning, The installation started(system installation) > > After installing till 7% it say installation step failed, I started > the installation again(and even formatted the disk), This problem > still occurred. > > This issue many people may happened before. > So I searched online(google) and didn't found any solution. I even > looked into the debian installation documentation. > > Here are some of my computer specifications for you if you requires: > > Intel Core 2 Duo E6400 > 1GB RAM(1014MB) > Intel Express Chipset Q45 > > The Installation Images(ISO) I downloaded from debian website is a > i386 architecture live image(DVD). > > Please Reply If You Need More Information About My Issue. Use DVD1 from this page. https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/ let us know, if you still face issues later > > Thanks For Your Reading. > Looking Forward For Your Reply.
[toc] | [prev] | [next] | [standalone]
| From | RODARY Jacques <rodaryj@free.fr> |
|---|---|
| Date | 2018-02-28 01:30 +0100 |
| Subject | dnsmasq and SOA |
| Message-ID | <vnXN7-3Zk-1@gated-at.bofh.it> |
| In reply to | #192691 |
I finally surrendered, and now use dnsmasq instead of bind. But in my setup with named, my box was Start Of Authority, and when there was a change and reload of the zone files, the only other name server was notified, before the TTL is over. How can I do that with dnsmasq? If the dnsmasqHowto wiki is quite clear, but not very detailed, the manpage is too detailed, and not clear to me. Thanks for your help. Jacques
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-02-28 06:50 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <vo2MN-7lY-1@gated-at.bofh.it> |
| In reply to | #193198 |
Hi. On Wed, Feb 28, 2018 at 01:25:00AM +0100, RODARY Jacques wrote: > I finally surrendered, and now use dnsmasq instead of bind. Welcome to the dark side, we have cookies. > But in my setup with named, my box was Start Of Authority, and when > there was a change and reload of the zone files, the only other name > server was notified, before the TTL is over. How can I do that with > dnsmasq? > If the dnsmasqHowto wiki is quite clear, but not very detailed, the > manpage is too detailed, and not clear to me. Thanks for your help. Dnsmasq is a caching DNS first, and an authoritative much later. So, it's possible for dnsmasq to have a SOA record, but changing it would probably require editing dnsmasq.conf and restarting dnsmasq. The part of dnsmasq.conf you need is "auth-soa": auth-soa=2016021014,hostmaster.example.com,1200,120,604800 The meaning of these fields is described in dnsmasq(8), and from left to right it is: serial, hostmaster, refresh, retry, expiry. Reco
[toc] | [prev] | [next] | [standalone]
| From | RODARY Jacques <rodaryj@free.fr> |
|---|---|
| Date | 2018-03-01 02:10 +0100 |
| Subject | Re: Re: dnsmasq and SOA |
| Message-ID | <vokTn-3hG-1@gated-at.bofh.it> |
| In reply to | #193206 |
I learnt about dnsmasq when I used Tor to see wiki, thanks for this hint. For now it works but I am not sure your help about auth-soa is all I need to get notifying to the other name server. I just added this line: "auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800" in /etc/dnsmasq.conf, and after restarting dnsmasq (systemctl restart dnsmaq.service) I get this result with "systemctl status dnsmaq.service: " dnsmasq.service - dnsmasq - A lightweight DHCP and caching DNS server ................................ févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53 févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53 févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53 févr. 28 23:52:33 ns dnsmasq[24452]: aucun serveur trouvé dans /run/dnsmasq/resolv.conf, va réessayer févr. 28 23:52:33 ns dnsmasq[24452]: Lecture de /run/dnsmasq/resolv.conf févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53 févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53 févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53" First 88.170.1.14 is my main IP to the outside, is it local? Second, before I added the refresh,retry, expire fields, supposed to have defaults values (said man 8 dnsmasq), I had another line in the output: "févr. 28 23:20:17 ns dnsmasq[24453]: Too few arguments." Does this mean dnsmasq will notify the other name server (ns6.gandi.net, 217.70.177.40#53) when needed? For now this server answers query about hosts I didn't put in /etc/hosts? Anyway it works for the time present, and many thanks again. Jacques P.S.: Cookies are not my favorites, but I know some recipes you would like, I am sure!
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-03-01 07:40 +0100 |
| Subject | Re: Re: dnsmasq and SOA |
| Message-ID | <voq2P-7rw-3@gated-at.bofh.it> |
| In reply to | #193238 |
On Thu, Mar 01, 2018 at 02:04:40AM +0100, RODARY Jacques wrote: > I learnt about dnsmasq when I used Tor to see wiki, thanks for this hint. For now it works but I am not sure your help about auth-soa is all I need to get > notifying to the other name server. Ok. > I just added this line: > "auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800" > in /etc/dnsmasq.conf, and after restarting dnsmasq (systemctl restart dnsmaq.service) I get this result with "systemctl status dnsmaq.service: " dnsmasq.service - dnsmasq > - A lightweight DHCP and caching DNS server > ................................ > > févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale > févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53 > févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53 > févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53 > févr. 28 23:52:33 ns dnsmasq[24452]: aucun serveur trouvé dans /run/dnsmasq/resolv.conf, va réessayer > févr. 28 23:52:33 ns dnsmasq[24452]: Lecture de /run/dnsmasq/resolv.conf > févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale > févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53 > févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53 > févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53" > > First 88.170.1.14 is my main IP to the outside, is it local? My French is *very* rusty (tried to learn the language back in high school, and that was some time ago). I remember some expletives vaguely, but that's it. Can you please provide your dnsmasq.conf? A simple grep -v '^#' /etc/dnsmasq.conf | uniq would suffice. > Second, before I added the refresh,retry, expire fields, supposed to have defaults values (said man 8 > dnsmasq), I had another line in the output: > "févr. 28 23:20:17 ns dnsmasq[24453]: Too few arguments." Dnsmasq can be stubborn sometimes. While manpage says that everything except serial is optional, it may not be the truth. The idea is that you define "auth-zone" for your domain first, and create a SOA record for it with "auth-soa" secord. > Does this mean dnsmasq will notify the other name server (ns6.gandi.net, 217.70.177.40#53) when needed? Your registered domain is "rodary.net", so that means that your registrar nameserver should see appropriate SOA record. The question is - does it see it now? What does show (your DNS): dig in soa rodary.net @127.0.0.1 Because dig shows old SOA record for me: dig in soa rodary.net rodary.net. 3599 IN SOA ns.rodary.net. root.ns.rodary.net. 2018022101 10800 3600 604800 3600 > For now this server answers query about hosts I didn't put in > /etc/hosts? Unless you put some domains into "local" stanza, queries for such domain should be resolved via nameservers put in /etc/resolv.conf or "server" stanza. In your case it's resolv.conf. The exception to the rule is auto-registered DHCP leases. As long as DHCP client provides "client-id" identifier, dnsmasq should create temporary A and PTR records for such client. Reco
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2018-03-02 22:00 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <voZWx-7Aa-7@gated-at.bofh.it> |
| In reply to | #193244 |
On 2018-03-01, Reco <recoverym4n@gmail.com> wrote: >> >> févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale >> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53 >> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53 >> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53 >> févr. 28 23:52:33 ns dnsmasq[24452]: aucun serveur trouvé dans /run/dnsmasq/resolv.conf, va réessayer >> févr. 28 23:52:33 ns dnsmasq[24452]: Lecture de /run/dnsmasq/resolv.conf >> févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale >> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53 >> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53 >> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53" >> >> First 88.170.1.14 is my main IP to the outside, is it local? > > My French is *very* rusty (tried to learn the language back in high > school, and that was some time ago). I remember some expletives vaguely, > but that's it. > More or less ignoring name server 88.170.1.143 - local interface using name server 217.70.177.40#53 (...) no server found in /run/dnsmasq/resolv.conf, will retry Reading /run/dnsmasq/resolv.conf ignoring name server 88.170.1.143 - local interface (...) -- Bah, the latest news, the latest news is not the last. Samuel Beckett
[toc] | [prev] | [next] | [standalone]
| From | RODARY Jacques <rodaryj@free.fr> |
|---|---|
| Date | 2018-03-06 03:00 +0100 |
| Subject | Re: Re: dnsmasq and SOA |
| Message-ID | <vqa3w-2Go-3@gated-at.bofh.it> |
| In reply to | #193284 |
For the time being, my main concern is to keep my connection up! I did succeed, without succeeding for long. Each time I rebooted I had no access to interness. Three times (or more) I couldn't have a full access including on my home wifi access point. I even reinstalled Stretch two times, before suspecting something else than my dnmasq, NetworkManager etc... It was difficult to find the guilty program, until I thought about Ivahi-daemon which didn't appear in the logs. Shouldn't I suppress the Avahis pachages? As soon as I know, I come back to my main concern, i.e. DNS,SOA... Anyway Thanks you both Reco and Curt
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-03-06 07:30 +0100 |
| Subject | Re: Re: dnsmasq and SOA |
| Message-ID | <vqegN-685-1@gated-at.bofh.it> |
| In reply to | #193397 |
Hi. On Tue, Mar 06, 2018 at 02:50:34AM +0100, RODARY Jacques wrote: > For the time being, my main concern is to keep my connection up! I did succeed, without succeeding for long. Each time I rebooted I had no access to interness. Three > times (or more) I couldn't have a full access including on my home wifi access point. I even reinstalled Stretch two times, before suspecting something else than my > dnmasq, NetworkManager etc... > It was difficult to find the guilty program, until I thought about Ivahi-daemon which didn't appear in the logs. Shouldn't I suppress the Avahis pachages? As > soon as I know, I come back to my main concern, i.e. DNS,SOA... Anyway Thanks you both Reco and Curt As long as you don't need mDNS, you can safely remove these: apt-get autoremove --purge avahi-autoipd avahi-daemon Reco
[toc] | [prev] | [next] | [standalone]
| From | RODARY Jacques <rodaryj@free.fr> |
|---|---|
| Date | 2018-03-07 22:20 +0100 |
| Subject | Re: Re: Re: dnsmasq and SOA |
| Message-ID | <vqODE-5Fx-11@gated-at.bofh.it> |
| In reply to | #193244 |
Sorry for my last post: I sent a draft mail instead of the corrected one. Let's go back to my own concern: dnsmasq and soa, if you don't mind. Here is my dnsmasq.conf file: resolv-file=/etc/dnsmasqresolv.conf interface=eno1 interface=wlp3s0 no-dhcp-interface=enp2s0 auth-zone=rodary.net auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800 dhcp-range=10.42.0.20,10.42.0.200,infinite As you guessed enp2s0 (eth0 now) is my INET interface. Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to ns6.gandi.net? With all my stupid previous acts, I don't dare to try it, specially when it could affect outside hosts e.g. my registrar. Jacques
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-03-08 10:00 +0100 |
| Subject | Re: Re: Re: dnsmasq and SOA |
| Message-ID | <vqZz3-4EM-5@gated-at.bofh.it> |
| In reply to | #193495 |
Hi. On Wed, Mar 07, 2018 at 10:19:32PM +0100, RODARY Jacques wrote: > Sorry for my last post: I sent a draft mail instead of the corrected one. Let's go back to my own concern: dnsmasq and soa, > if you don't mind. Here is my dnsmasq.conf file: > resolv-file=/etc/dnsmasqresolv.conf > > interface=eno1 > interface=wlp3s0 > no-dhcp-interface=enp2s0 > > auth-zone=rodary.net > > auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800 > > dhcp-range=10.42.0.20,10.42.0.200,infinite > > As you guessed enp2s0 (eth0 now) is my INET interface. > > Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to ns6.gandi.net? With all my stupid previous acts, I don't dare to try it, > specially when it could affect outside hosts e.g. my registrar. I never tried it myself, but the manpage says this on auth-peer: If this option is not given, then AXFR requests will be accepted from any secondary. The way I understand it, your configuration should work without auth-peer, while being somewhat insecure. You may need to specify ns6.gandi.net as secondary through auth-sec-servers, on the other hand. Yet your configuration does not work, apparently, as 'dig +trace' shows me this: rodary.net. 3600 IN SOA ns.rodary.net. root.ns.rodary.net. 2018022101 10800 3600 604800 3600 rodary.net. 3600 IN NS ns.rodary.net. rodary.net. 3600 IN NS ns6.gandi.net. ;; Received 169 bytes from 217.70.177.40#53(ns6.gandi.net) in 64 ms Did your previous BIND configuration implement DNSSEC? Your dnsmasq should not provide DS records with this config, yet Gandi resolver could require them. Reco
[toc] | [prev] | [next] | [standalone]
| From | Jacques Rodary <rodaryj@free.fr> |
|---|---|
| Date | 2018-03-08 19:00 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <vr7ZE-1w8-13@gated-at.bofh.it> |
| In reply to | #193516 |
On 08/03/2018 09:51, Reco wrote: > Hi. > > On Wed, Mar 07, 2018 at 10:19:32PM +0100, RODARY Jacques wrote: >> Sorry for my last post: I sent a draft mail instead of the corrected one. Let's go back to my own concern: dnsmasq and soa, >> if you don't mind. Here is my dnsmasq.conf file: >> resolv-file=/etc/dnsmasqresolv.conf >> >> interface=eno1 >> interface=wlp3s0 >> no-dhcp-interface=enp2s0 >> >> auth-zone=rodary.net >> >> auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800 >> >> Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to ns6.gandi.net? With all my stupid previous acts, I don't dare to try it, >> specially when it could affect outside hosts e.g. my registrar. > I never tried it myself, but the manpage says this on auth-peer: > > If this option is not given, then AXFR requests will be accepted from any secondary. > > > The way I understand it, your configuration should work without > auth-peer, while being somewhat insecure. You may need to specify > ns6.gandi.net as secondary through auth-sec-servers, on the other hand. > > Yet your configuration does not work, apparently, as 'dig +trace' > shows me this: > > rodary.net. 3600 IN SOA ns.rodary.net. > root.ns.rodary.net. 2018022101 10800 3600 604800 3600 > rodary.net. 3600 IN NS ns.rodary.net. > rodary.net. 3600 IN NS ns6.gandi.net. > ;; Received 169 bytes from 217.70.177.40#53(ns6.gandi.net) in 64 ms Today "dig in soa rodary.net" gives me: rodary.net. 600 IN SOA . root.ns.rodary.net. 2018022801 10800 3600 10800 600 Which is neither the answer I had yesterday, neither yours (by the way I don't find how to use the "dig +trace" command), and "dig in ns rodary.net" which gave me ns.rodary.net and ns6.gandi.net , gives me only ns.rodary.net now, and "dig in ns/soa rodary.net @ns6.gandi.net" has no answer, but "recursion requested but not available" > Did your previous BIND configuration implement DNSSEC? No. ns6.gandi.net was NS in my main zone file; so I think I will try auth-sec-servers=ns6.gandi.net as it was in my BIND setup Jacques
[toc] | [prev] | [next] | [standalone]
| From | Jacques Rodary <rodaryj@free.fr> |
|---|---|
| Date | 2018-03-09 03:40 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <vrg6R-72t-3@gated-at.bofh.it> |
| In reply to | #193533 |
On 08/03/2018 18:58, Jacques Rodary wrote: > > > On 08/03/2018 09:51, Reco wrote: >> Hi. >> >> On Wed, Mar 07, 2018 at 10:19:32PM +0100, RODARY Jacques wrote: >>> Sorry for my last post: I sent a draft mail instead of the >>> corrected one. Let's go back to my own concern: dnsmasq and soa, >>> if you don't mind. Here is my dnsmasq.conf file: >>> resolv-file=/etc/dnsmasqresolv.conf >>> >>> interface=eno1 >>> interface=wlp3s0 >>> no-dhcp-interface=enp2s0 >>> >>> auth-zone=rodary.net >>> >>> auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800 >>> >>> Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to >>> ns6.gandi.net? With all my stupid previous acts, I don't dare to try >>> it, >>> specially when it could affect outside hosts e.g. my registrar. >> I never tried it myself, but the manpage says this on auth-peer: >> >> If this option is not given, then AXFR requests will be accepted from >> any secondary. >> >> >> The way I understand it, your configuration should work without >> auth-peer, while being somewhat insecure. You may need to specify >> ns6.gandi.net as secondary through auth-sec-servers, on the other hand. >> >> Yet your configuration does not work, apparently, as 'dig +trace' >> shows me this: >> >> rodary.net. 3600 IN SOA ns.rodary.net. >> root.ns.rodary.net. 2018022101 10800 3600 604800 3600 >> rodary.net. 3600 IN NS ns.rodary.net. >> rodary.net. 3600 IN NS ns6.gandi.net. >> ;; Received 169 bytes from 217.70.177.40#53(ns6.gandi.net) in 64 ms > Today "dig in soa rodary.net" gives me: > rodary.net. 600 IN SOA . root.ns.rodary.net. > 2018022801 10800 3600 10800 600 > Which is neither the answer I had yesterday, neither yours (by the > way I don't find how to use the "dig +trace" command), and "dig in ns > rodary.net" which gave me ns.rodary.net and ns6.gandi.net , gives me > only ns.rodary.net now, and "dig in ns/soa rodary.net @ns6.gandi.net" > has no answer, but "recursion requested but not available" >> Did your previous BIND configuration implement DNSSEC? No ns6.gandi.net was NS in my main zone file; so I think I will try auth-sec-servers=ns6.gandi.net as it was in my BIND setup. I did and it worked: "dig in soa rodary.net" gives me: ;; ANSWER SECTION: rodary.net. 600 IN SOA . root.ns.rodary.net. 2018022801 10800 3600 10800 600 ;; AUTHORITY SECTION: rodary.net. 600 IN NS . rodary.net. 600 IN NS ns6.gandi.net. and even if I don't quite understand why "." (the root) is my secondary server, I suppose it means I succeeded to have my host as a stealth server! But when I added "auth-peer=217.70.177.40" I had to restart everything, which means reboot for me because I don't understand quite well how NetworkManager works. Jacques
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-03-09 08:40 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <vrkNb-1WT-5@gated-at.bofh.it> |
| In reply to | #193544 |
Hi. On Fri, Mar 09, 2018 at 03:34:27AM +0100, Jacques Rodary wrote: > > Today "dig in soa rodary.net" gives me: > > rodary.net. 600 IN SOA . root.ns.rodary.net. > > 2018022801 10800 3600 10800 600 > > Which is neither the answer I had yesterday, neither yours (by the way > > I don't find how to use the "dig +trace" command), and "dig in ns > > rodary.net" which gave me ns.rodary.net and ns6.gandi.net , gives me > > only ns.rodary.net now, and "dig in ns/soa rodary.net @ns6.gandi.net" > > has no answer, but "recursion requested but not available" > > > Did your previous BIND configuration implement DNSSEC? > No > ns6.gandi.net was NS in my main zone file; so I think I will try > auth-sec-servers=ns6.gandi.net as it was in my BIND setup. I did and it > worked: "dig in soa rodary.net" gives me: > ;; ANSWER SECTION: > rodary.net. 600 IN SOA . root.ns.rodary.net. > 2018022801 10800 3600 10800 600 > > ;; AUTHORITY SECTION: > rodary.net. 600 IN NS . > rodary.net. 600 IN NS ns6.gandi.net. Hate to break it to you, but it seems to fail for everyone else. Today "dig in soa rodary.net" gives me SERVFAIL. > and even if I don't quite understand why "." (the root) is my secondary > server, I suppose it means I succeeded to have my host as a stealth server! I believe that it means that somehow you're announcing authority on root domain. I would advise against it. "dig +trace" gives me "BAD REFERRAL", which is not a good sign, to say the least. > But when I added "auth-peer=217.70.177.40" I had to restart everything, > which means reboot for me because I don't understand quite well how > NetworkManager works. I don't understand it either, but frankly I don't need to. IP adresses, routing table and packet flow are the state of the kernel. Using always-running userland tool for their configuration *may* be appropriate in certain cases (DHCP, anyone?), but for your typical server environment such cases do not apply. That said, for your typical server environment nothing beats ifupdown. So my advice is - if you need a predictable behaviour - you exterminate NetworkManager, connman and other fancy toys, and stick to the ifupdown, or maybe systemd-networkd. Reco
[toc] | [prev] | [next] | [standalone]
| From | Jacques Rodary <rodaryj@free.fr> |
|---|---|
| Date | 2018-03-09 18:30 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <vru09-854-3@gated-at.bofh.it> |
| In reply to | #193550 |
On 09/03/2018 08:32, Reco wrote: > Hi. > > On Fri, Mar 09, 2018 at 03:34:27AM +0100, Jacques Rodary wrote: > >> ;; AUTHORITY SECTION: >> rodary.net. 600 IN NS . >> rodary.net. 600 IN NS ns6.gandi.net. Here is my new dnsmasq.conf: no-dhcp-interface=enp2s0 auth-server=ns.rodary.net,88.170.1.143 auth-zone=rodary.net auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800 auth-sec-servers=ns6.gandi.net dhcp-range=10.42.0.20,10.42.0.200,infinite I added the auth-server line, and "dig in soa rodary.net" gives: ;; ANSWER SECTION: rodary.net. 600 IN SOA ns.rodary.net. root.ns.rodary.net. 2018022801 10800 3600 10800 600 ;; AUTHORITY SECTION: rodary.net. 600 IN NS ns.rodary.net. rodary.net. 600 IN NS ns6.gandi.net. ;; Query time: 0 msec ;; SERVER: 88.170.1.143#53(88.170.1.143) which means ns.rodary.net is SOA of my zone and ns6.gandi.net is slave server. Without master server the root zone "." servers were authoritative for my zone (as they are for all zones). >> Hate to break it to you, but it seems to fail for everyone else. >> Today "dig in soa rodary.net" gives me SERVFAIL. Tell me please if it works now. >> and even if I don't quite understand why "." (the root) is my secondary >> server, I suppose it means I succeeded to have my host as a stealth server! > I believe that it means that somehow you're announcing authority on root > domain. I would advise against it. No, root servers announced authority on rodary.net, since nobody else delegated this authority. >> I don't understand quite well how NetworkManager works. > I don't understand it either, but frankly I don't need to. IP adresses, > routing table and packet flow are the state of the kernel. Using > always-running userland tool for their configuration *may* be > appropriate in certain cases (DHCP, anyone?), but for your typical > server environment such cases do not apply. > That said, for your typical server environment nothing beats ifupdown. > So my advice is - if you need a predictable behaviour - you exterminate > NetworkManager, connman and other fancy toys, and stick to the ifupdown, > or maybe systemd-networkd. I may do that soon. Thanks for your precious help. Jacques
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-03-09 19:30 +0100 |
| Subject | Re: dnsmasq and SOA |
| Message-ID | <vruWe-d5-7@gated-at.bofh.it> |
| In reply to | #193559 |
Hi. On Fri, Mar 09, 2018 at 06:25:24PM +0100, Jacques Rodary wrote: > > On Fri, Mar 09, 2018 at 03:34:27AM +0100, Jacques Rodary wrote: > > > > > ;; AUTHORITY SECTION: > > > rodary.net. 600 IN NS . > > > rodary.net. 600 IN NS ns6.gandi.net. > Here is my new dnsmasq.conf: > no-dhcp-interface=enp2s0 > auth-server=ns.rodary.net,88.170.1.143 > auth-zone=rodary.net > auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800 > auth-sec-servers=ns6.gandi.net > dhcp-range=10.42.0.20,10.42.0.200,infinite > I added the auth-server line, and "dig in soa rodary.net" gives: > ;; ANSWER SECTION: > rodary.net. 600 IN SOA ns.rodary.net. > root.ns.rodary.net. 2018022801 10800 3600 10800 600 > ;; AUTHORITY SECTION: > rodary.net. 600 IN NS ns.rodary.net. > rodary.net. 600 IN NS ns6.gandi.net. > ;; Query time: 0 msec > ;; SERVER: 88.170.1.143#53(88.170.1.143) > which means ns.rodary.net is SOA of my zone and ns6.gandi.net is slave > server. Without master server the root zone "." servers were authoritative > for my zone (as they are for all zones). > > > Hate to break it to you, but it seems to fail for everyone else. > > > Today "dig in soa rodary.net" gives me SERVFAIL. > Tell me please if it works now. Yup, all lights are green: ; <<>> DiG 9.10.3-P4-Debian <<>> in soa rodary.net ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31015 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;rodary.net. IN SOA ;; ANSWER SECTION: rodary.net. 599 IN SOA ns.rodary.net. root.ns.rodary.net. 2018022801 10800 3600 10800 600 Save this config elsewhere just in case. A backup never hurts. > > > I don't understand quite well how NetworkManager works. > > I don't understand it either, but frankly I don't need to. IP adresses, > > routing table and packet flow are the state of the kernel. Using > > always-running userland tool for their configuration *may* be > > appropriate in certain cases (DHCP, anyone?), but for your typical > > server environment such cases do not apply. > > That said, for your typical server environment nothing beats ifupdown. > > So my advice is - if you need a predictable behaviour - you exterminate > > NetworkManager, connman and other fancy toys, and stick to the ifupdown, > > or maybe systemd-networkd. > I may do that soon. Thanks for your precious help. You're welcome. Reco
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web