Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Negative caching SERVFAIL responses

470 views
Skip to first unread message

Arjun Nair

unread,
Sep 18, 2008, 1:48:39 PM9/18/08
to
Hi,

Is there a way to turn on negative caching for SERVFAIL responses? RFC 2308 (DNS NCACHE) allows you to cache SERVFAIL responses for up to 5 mins.

Thanks,

Arjun

Peter Dambier

unread,
Sep 18, 2008, 2:39:38 PM9/18/08
to
Hi Arjun,

I did it and Im glad it is nolonger automatically done.

When I had a break in connectivity for a couple of minutes,
my resolver replied NXDOMAIN for everything and it would
not heal itself for more that an hour.

It would not work again until I stopped and restarted the
nameserver. When that happened more than once day I was
glad somebody told me how to switch it off with bind 8.

"auth-nxdomain yes" will cache permanently domains that were
missing once.

Kind regards
Peter

--
Peter and Karin Dambier
Cesidian Root - Radice Cesidiana
Rimbacher Strasse 16
D-69509 Moerlenbach-Bonsweiher
+49(6209)795-816 (Telekom)
+49(6252)750-308 (VoIP: sipgate.de)
mail: pe...@peter-dambier.de
http://www.peter-dambier.de/
http://iason.site.voila.fr/
https://sourceforge.net/projects/iason/

Arjun Nair

unread,
Sep 18, 2008, 4:09:46 PM9/18/08
to
Peter Dambier wrote:
> Hi Arjun,
>
> I did it and Im glad it is nolonger automatically done.
>
> When I had a break in connectivity for a couple of minutes,
> my resolver replied NXDOMAIN for everything and it would
> not heal itself for more that an hour.
>
> It would not work again until I stopped and restarted the
> nameserver. When that happened more than once day I was
> glad somebody told me how to switch it off with bind 8.
>
> "auth-nxdomain yes" will cache permanently domains that were
> missing once.
>
Thanks for the reply. I looked into the "auth-nxdomain yes" but could not find any info on how it would enable caching for SERVFAIL. I have caching enabled for negative responses, but it only authorized NXDOMAIN responses and not SERVFAILs.

You make a good point though, caching SERVFAIL responses will lead to undesired behavior when there is a break in connectivity.

Thanks,

Arjun

0 new messages