[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: OT: dns zone transfer (was: public key is not available)



On Wed, Jan 18, 2006 at 10:53:46PM +0100, Kiko Piris wrote:
> On 18/01/2006 at 22:16 +0100, Hans Ekbrand wrote:
> 
> > pgp.net is not a host, it's a zone. My guess is that your nameserver
> > is broken, but I'm no DNS guru.
> > 
> > Here are some of the servers that my nameserver replies to the above
> > command:
> 
> His nameserver doesn't need to be broken, your's might very well be.
> His nameserver refuses to answer a zone transfer request (9 NOAUTH)
> because it's not authoritative on that zone (that's absolutely correct
> behaviour).

OK I'll take your word for that my DNS is broken, his is not. As I
said, I am no DNS guru.

I have bind running locally, could that explain it?

> Your's does answer that request. The funny thing is that among the
> authoritative nameservers of the pgp.net zone, some answer the zone
> transfer request and some do not (5 REFUSED).

I don't really see the fun in it :-) I do find it funny that the
broken DNS:s return the info requested, while the non-broken ones do
not.

I took the "host -l pgp.net"-method from the default .gnupg/options, is
there anything wrong with that method?

-- 
Hans Ekbrand (http://sociologi.cjb.net) <hans@sociologi.cjb.net>
Q. What is that strange attachment in this mail?
A. My digital signature, see www.gnupg.org for info on how you could
   use it to ensure that this mail is from me and has not been
   altered on the way to you.

Attachment: signature.asc
Description: Digital signature


Reply to: