Re: [bitfolk] BIND9 not authorised - Master zone

Top Page
Author: Andy Smith
Date:  
To: users
Subject: Re: [bitfolk] BIND9 not authorised - Master zone

Reply to this message
gpg: Signature made Wed Jul 24 15:12:30 2019 UTC
gpg: using DSA key 2099B64CBF15490B
gpg: Good signature from "Andy Smith <andy@strugglers.net>" [unknown]
gpg: aka "Andrew James Smith <andy@strugglers.net>" [unknown]
gpg: aka "Andy Smith (UKUUG) <andy.smith@ukuug.org>" [unknown]
gpg: aka "Andy Smith (BitFolk Ltd.) <andy@bitfolk.com>" [unknown]
gpg: aka "Andy Smith (Linux User Groups UK) <andy@lug.org.uk>" [unknown]
gpg: aka "Andy Smith (Cernio Technology Cooperative) <andy.smith@cernio.com>" [unknown]
Hi Keith,

Now we have got to the bottom of the NOTAUTH thing, I thought I
better comment on some other issues.

On Tue, Jul 23, 2019 at 10:06:20PM +0100, Keith Williams wrote:
> And just for good measure the zone file


[…]

> keiths-place.co.uk.     IN      NS      a.authns.bitfolk.com.
> keiths-place.co.uk.     IN      NS      b.authns.bitfolk.com.
> keiths-place.co.uk.     IN      NS      c.authns.bitfolk.com.
> keiths-place.co.uk.     IN      NS      ns3.keiths-place.co.uk.


It is okay to have a.authns.bitfolk.com but I do suggest using
a.authns.bitfolk.co.uk instead, just so that there are nameservers
in different TLDs (com and uk).

You do also list ns3.keiths-place.co.uk but this is not present at
the registry:

$ whois keiths-place.co.uk | grep -A3 'Name servers:'
    Name servers:
        a.authns.bitfolk.co.uk    85.119.80.222  2001:ba8:1f1:f085::53
        b.authns.bitfolk.com
        c.authns.bitfolk.com


So you should either add ns3.keiths-place.co.uk at the registry or
else remove ns3.keiths-place.co.uk from the list of NS records in
the zone.

Neither of these are major issues.

Cheers,
Andy

--
https://bitfolk.com/ -- No-nonsense VPS hosting