RPZ and www.rackspace.com

Carl Byington carl at byington.org
Fri May 30 16:16:57 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, 2014-05-08 at 01:44 +1000, Mark Andrews wrote:
> Because NS queries are not common with normal DNS lookups.  For
> some reason people that deploy load balancers think they don't need
> to fix issues like this.  Send something other than a A record and
> you get:

I presume this is also the issue with ocsp.verisign.net/aaaa

DNS format error from 199.7.52.206#53 resolving ocsp.verisign.net/AAAA
for client xxx#52373: Name verisign.net (SOA) not subdomain of zone
ocsp.verisign.net -- invalid response


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)

iEYEARECAAYFAlOIrtYACgkQL6j7milTFsHivACfT3/PUHbtN6LYPDUlxKgUCJZ6
R/AAn3/1H3b34tieeOIy5aScEwZijBsx
=ShpG
-----END PGP SIGNATURE-----




More information about the bind-users mailing list