13 msgManaging an Internet outage
2 msgWPAD / PAC woes
5 msgdnssec-keygen: a key with algorithm 'HMAC-MD5' ...
4 msgResolution Check
3 msgBIND can't resolve with unreachable second NS
10 msgspecial features
2 msgModifying BIND to provide requesting IP address...
3 msgSetting up my MX's records to redirect mail fro...

Multiple SOA records?
\ Lars Hecking (6 May 2008)
. \ Kevin Darcy (6 May 2008)
. . \ Lars Hecking (6 May 2008)
. . . \ Kevin Darcy (6 May 2008)
. . . . \ Lars Hecking (7 May 2008)
. . \ Lars Hecking (7 May 2008)
. . . \ Chris Buxton (7 May 2008)
. . . \ Kevin Darcy (7 May 2008)
. \ Chris Thompson (7 May 2008)

6 msgBind and OpenLDAP
3 msgbind dlz : using only Mysql
8 msgSuggestions for coping with this issue
7 msgQuestions about Bind and AD dns integration
14 msgOverriding MX records to internal gateways
3 msgBind + DKIM (ran out of space)
2 msgtime set to UTC
1 msgSplit horizon with forwarding
8 msgAre failures cached?
2 msgcatch-all
2 msgProblems Configuring Bind on Windows Server 2003
Subject:Re: Multiple SOA records?
Group:Bind-users
From:Lars Hecking
Date:7 May 2008


 
Kevin Darcy writes:
[...]
> traininghott.com definitely seems to have a standards-conformance issue
> in the way it handles SOA queries
[...]

Hhm, I think I would disagree here. After all, their name servers do return
SOA records when queried directly, even if they are too many.

The interesting bit is, if I let my own name server do the querying, I get
SERVFAIL:

; <<>> DiG 9.3.3rc2 <<>> @server traininghott.com. soa
; (1 server found)
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 49324
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;traininghott.com. IN SOA

;; Query time: 331 msec

but a tcpdump/wireshark analysis shows that there were two answers (the
SOA RRs, two name servers, and nothing in the additional section; 2/2/0
in tcpdump output). This means that the querying server, which runs BIND
9.4.1_P1 btw., has decided to discard the response. I guess this kinda
clarifies my original question "What kind of consequences can I expect
trying to resolve records in a domain that has more than one SOA?".

Kevin, can you explain

> Note, however, that *transactionally* a zone transfer response includes
> 2 SOA RRs.

I cannot find anything on this?





© 2004-2008 readlist.com