• broken trust chain

    From Youssef.FassiFihri@inwi.ma@21:1/5 to All on Tue Jul 28 23:10:25 2020
    Hi All,


    I am using Bind as resolver for end users .


    At various time, bind logs show "broken trust chain" continuously , for about 20mn ~ 30 mn causing an increase of "recursive clients" shown in "rndc status" and a decrease of "DNS sucess rate KPI" supervised from end users side. then the error
    disappear and everything is OK.


    the problem appears on different server at different time.


    What could be the problem?


    Regards,

    ________________________________

    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L'intégrité des messages électroniques n'étant
    pas garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l'expéditeur et le détruire y compris les pièces jointes.

    Merci. »

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have been modified, changed or falsified.

    If you have received this email in error, please notify the sender and delete this message and its attachments.

    Thank you. »


    <html>
    <head>
    <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
    <style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
    </head>
    <body dir="ltr">
    <div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
    <p>Hi All,</p>
    <p><br>

    <p>I am using Bind as resolver for end users &nbsp;.</p>
    <p><br>

    <p>At various time, bind logs show &quot;<span>broken trust chain&quot; continuously&nbsp;</span>&nbsp;, for about 20mn&nbsp; ~&nbsp;30 mn causing an increase of &quot;<span>recursive clients&quot; shown in &quot;rndc status&quot; and a decrease of&nbsp;
    &quot;DNS sucess rate KPI&quot; supervised from end users side.&nbsp;&nbsp;</span><span style="font-size: 12pt;">then
    the error disappear and everything is OK.</span></p>
    <p><span><br>
    </span></p>
    <p><span>the problem appears on different server at different time.</span></p> <p><span><br>
    </span></p>
    <p><span>What could be the problem?</span></p>
    <p><span><br>
    </span></p>
    <p><span>Regards,&nbsp;</span></p>
    </div>


    <font face="Arial" color="Gray" size="2"><br>
    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L&#8217;intégrité des messages électroniques n&#
    8217;étant pas
    garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.<br>

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l&#8217;expéditeur et le détruire y compris les pièces jointes.<br>

    Merci. »<br>

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------<br>

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have
    been modified, changed or falsified.<br>

    If you have received this email in error, please notify the sender and delete this message and its attachments.<br>

    Thank you. »<br>

    </font>
    </body>
    </html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From John W. Blue@21:1/5 to All on Tue Jul 28 23:30:54 2020
    What version of BIND are you using?

    John

    From: bind-users [mailto:bind-users-bounces@lists.isc.org] On Behalf Of Youssef.FassiFihri@inwi.ma
    Sent: Tuesday, July 28, 2020 6:10 PM
    To: bind-users@lists.isc.org
    Subject: broken trust chain


    Hi All,



    I am using Bind as resolver for end users .



    At various time, bind logs show "broken trust chain" continuously , for about 20mn ~ 30 mn causing an increase of "recursive clients" shown in "rndc status" and a decrease of "DNS sucess rate KPI" supervised from end users side. then the error
    disappear and everything is OK.



    the problem appears on different server at different time.



    What could be the problem?



    Regards,

    ________________________________

    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L'intégrité des messages électroniques n'étant
    pas garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l'expéditeur et le détruire y compris les pièces jointes.

    Merci. »

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have been modified, changed or falsified.

    If you have received this email in error, please notify the sender and delete this message and its attachments.

    Thank you. »

    <html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
    <head>
    <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
    <meta name="Generator" content="Microsoft Word 15 (filtered medium)">
    <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
    o\:* {behavior:url(#default#VML);}
    w\:* {behavior:url(#default#VML);}
    .shape {behavior:url(#default#VML);}
    </style><![endif]--><style><!--
    /* Font Definitions */
    @font-face
    {font-family:"Cambria Math";
    panose-1:2 4 5 3 5 4 6 3 2 4;}
    @font-face
    {font-family:Calibri;
    panose-1:2 15 5 2 2 2 4 3 2 4;}
    /* Style Definitions */
    p.MsoNormal, li.MsoNormal, div.MsoNormal
    {margin:0in;
    margin-bottom:.0001pt;
    font-size:12.0pt;
    font-family:"Times New Roman","serif";}
    a:link, span.MsoHyperlink
    {mso-style-priority:99;
    color:#0563C1;
    text-decoration:underline;}
    a:visited, span.MsoHyperlinkFollowed
    {mso-style-priority:99;
    color:#954F72;
    text-decoration:underline;}
    p
    {mso-style-priority:99;
    margin:0in;
    margin-bottom:.0001pt;
    font-size:12.0pt;
    font-family:"Times New Roman","serif";}
    span.EmailStyle18
    {mso-style-type:personal-reply;
    font-family:"Calibri","sans-serif";
    color:#1F497D;}
    .MsoChpDefault
    {mso-style-type:export-only;
    font-size:10.0pt;}
    @page WordSection1
    {size:8.5in 11.0in;
    margin:1.0in 1.0in 1.0in 1.0in;}
    div.WordSection1
    {page:WordSection1;}
    </style><!--[if gte mso 9]><xml>
    <o:shapedefaults v:ext="edit" spidmax="1026" />
    </xml><![endif]--><!--[if gte mso 9]><xml>
    <o:shapelayout v:ext="edit">
    <o:idmap v:ext="edit" data="1" />
    </o:shapelayout></xml><![endif]-->
    </head>
    <body lang="EN-US" link="#0563C1" vlink="#954F72">
    <div class="WordSection1">
    <p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">What version of BIND are you using?<o:p></o:p></span></p>
    <p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
    <p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">John<o:p></o:p></span></p>
    <p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
    <div>
    <div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
    <p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"> bind-users [mailto:bind-users-bounces@
    lists.isc.org]
    <b>On Behalf Of </b>Youssef.FassiFihri@inwi.ma<br>
    <b>Sent:</b> Tuesday, July 28, 2020 6:10 PM<br>
    <b>To:</b> bind-users@lists.isc.org<br>
    <b>Subject:</b> broken trust chain<o:p></o:p></span></p>
    </div>
    </div>
    <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
    <div id="divtagdefaultwrapper">
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">Hi All,<o:p></o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">I am using Bind as resolver for end users &nbsp;.<o:p></o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">At various time, bind logs show &quot;broken trust chain&quot; continuously&nbsp;&nbsp;, for about 20mn&nbsp; ~&nbsp;30 mn causing an increase of &quot;recursive clients&
    quot; shown in &quot;rndc status&quot; and a decrease of&nbsp; &quot;DNS sucess rate
    KPI&quot; supervised from end users side.&nbsp;&nbsp;then the error disappear and everything is OK.<o:p></o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">the problem appears on different server at different time.<o:p></o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">What could be the problem?<o:p></o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
    <p><span style="font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:black">Regards,&nbsp;<o:p></o:p></span></p>
    </div>
    <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
    <div class="MsoNormal" align="center" style="text-align:center">
    <hr size="2" width="100%" align="center">
    </div>
    <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:gray"><br>
    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L&#8217;intégrité des messages électroniques n&#
    8217;étant pas
    garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.<br>

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l&#8217;expéditeur et le détruire y compris les pièces jointes.<br>

    Merci. »<br>

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------<br>

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have
    been modified, changed or falsified.<br>

    If you have received this email in error, please notify the sender and delete this message and its attachments.<br>

    Thank you. »</span><o:p></o:p></p>
    </div>
    </body>
    </html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Mark Andrews@21:1/5 to All on Wed Jul 29 11:15:24 2020
    Copy: bind-users@lists.isc.org

    A network link that is dropping packets can trigger EDNS failures in versions of
    BIND before 9.13.3. These versions have code to compensate for servers that fail to respond to EDNS queries or fail to respond to EDNS queries with DO=1
    or fail to respond to queries with (particular) EDNS options set. BIND would fallback to plain DNS queries to workaround these issues, but that broke
    DNSSEC when the answers where coming from a signed zone and the packet loss
    is due to network issues.

    5029. [func] Workarounds for servers that misbehave when queried
    with EDNS have been removed, because these broken
    servers and the workarounds for their noncompliance
    cause unnecessary delays, increase code complexity,
    and prevent deployment of new DNS features. See
    https://dnsflagday.net for further details. [GL #150]


    On 29 Jul 2020, at 09:10, <Youssef.FassiFihri@inwi.ma> <Youssef.FassiFihri@inwi.ma> wrote:

    Hi All,

    I am using Bind as resolver for end users .

    At various time, bind logs show "broken trust chain" continuously , for about 20mn ~ 30 mn causing an increase of "recursive clients" shown in "rndc status" and a decrease of "DNS sucess rate KPI" supervised from end users side. then the error
    disappear and everything is OK.

    the problem appears on different server at different time.

    What could be the problem?

    Regards,


    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L’intégrité des messages é
    lectroniques n’étant pas garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l’expéditeur et le détruire y compris les pièces jointes.

    Merci. »

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages
    that have been modified, changed or falsified.

    If you have received this email in error, please notify the sender and delete this message and its attachments.

    Thank you. »

    _______________________________________________
    Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

    ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


    bind-users mailing list
    bind-users@lists.isc.org
    https://lists.isc.org/mailman/listinfo/bind-users

    --
    Mark Andrews, ISC
    1 Seymour St., Dundas Valley, NSW 2117, Australia
    PHONE: +61 2 9871 4742 INTERNET: marka@isc.org

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Youssef.FassiFihri@inwi.ma@21:1/5 to All on Wed Jul 29 10:31:19 2020
    Copy: bind-users@lists.isc.org

    Thank you, Andrews.


    ________________________________
    De : Mark Andrews <marka@isc.org>
    Envoyé : mercredi 29 juillet 2020 02:15:24
    À : Youssef Fassi Fihri
    Cc : bind-users@lists.isc.org
    Objet : Re: broken trust chain

    A network link that is dropping packets can trigger EDNS failures in versions of
    BIND before 9.13.3. These versions have code to compensate for servers that fail to respond to EDNS queries or fail to respond to EDNS queries with DO=1
    or fail to respond to queries with (particular) EDNS options set. BIND would fallback to plain DNS queries to workaround these issues, but that broke
    DNSSEC when the answers where coming from a signed zone and the packet loss
    is due to network issues.

    5029. [func] Workarounds for servers that misbehave when queried
    with EDNS have been removed, because these broken
    servers and the workarounds for their noncompliance
    cause unnecessary delays, increase code complexity,
    and prevent deployment of new DNS features. See
    https://dnsflagday.net for further details. [GL #150]


    On 29 Jul 2020, at 09:10, <Youssef.FassiFihri@inwi.ma> <Youssef.FassiFihri@inwi.ma> wrote:

    Hi All,

    I am using Bind as resolver for end users .

    At various time, bind logs show "broken trust chain" continuously , for about 20mn ~ 30 mn causing an increase of "recursive clients" shown in "rndc status" and a decrease of "DNS sucess rate KPI" supervised from end users side. then the error
    disappear and everything is OK.

    the problem appears on different server at different time.

    What could be the problem?

    Regards,


    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L’intégrité des messages électroniques n’é
    tant pas garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l’expéditeur et le détruire y compris les pièces jointes.

    Merci. »

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have been modified, changed or falsified.

    If you have received this email in error, please notify the sender and delete this message and its attachments.

    Thank you. »

    _______________________________________________
    Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

    ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


    bind-users mailing list
    bind-users@lists.isc.org
    https://lists.isc.org/mailman/listinfo/bind-users

    --
    Mark Andrews, ISC
    1 Seymour St., Dundas Valley, NSW 2117, Australia
    PHONE: +61 2 9871 4742 INTERNET: marka@isc.org


    ________________________________

    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L’intégrité des messages électroniques n’étant
    pas garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l’expéditeur et le détruire y compris les pièces jointes.

    Merci. »

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have been modified, changed or falsified.

    If you have received this email in error, please notify the sender and delete this message and its attachments.

    Thank you. »


    <html>
    <head>
    <meta http-equiv="Content-Type" content="text/html; charset=Windows-1252"> <meta name="Generator" content="Microsoft Exchange Server">
    <!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
    </head>
    <body>
    <meta content="text/html; charset=UTF-8">
    <style type="text/css" style="">
    <!--
    p
    {margin-top:0;
    margin-bottom:0}

    </style>
    <div dir="ltr">
    <div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
    <p>Thank you,&nbsp; Andrews.<br>

    <p><br>

    </div>
    <hr tabindex="-1" style="display:inline-block; width:98%">
    <div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>De :</b> Mark Andrews &lt;marka@isc.org&gt;<br>
    <b>Envoyé :</b> mercredi 29 juillet 2020 02:15:24<br>
    <b>À :</b> Youssef Fassi Fihri<br>
    <b>Cc&nbsp;:</b> bind-users@lists.isc.org<br>
    <b>Objet :</b> Re: broken trust chain</font>
    <div>&nbsp;</div>
    </div>
    </div>
    <font size="2"><span style="font-size:10pt;">
    <div class="PlainText">A network link that is dropping packets can trigger EDNS failures in versions of<br>
    BIND before 9.13.3.&nbsp; These versions have code to compensate for servers that<br>
    fail to respond to EDNS queries or fail to respond to EDNS queries with DO=1<br>
    or fail to respond to queries with (particular) EDNS options set. BIND would<br>
    fallback to plain DNS queries to workaround these issues, but that broke<br> DNSSEC when the answers where coming from a signed zone and the packet loss<br> is due to network issues.<br>

    5029.&nbsp;&nbsp; [func]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Workarounds for servers that misbehave when queried<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; with EDNS have been removed, because these broken<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; servers and the workarounds for their noncompliance<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; cause unnecessary delays, increase code complexity,<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; and prevent deployment of new DNS features. See<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href="https://dnsflagday.net">https://dnsflagday.net</a> for further details. [GL #150]<br>


    &gt; On 29 Jul 2020, at 09:10, &lt;Youssef.FassiFihri@inwi.ma&gt; &lt;Youssef.FassiFihri@inwi.ma&gt; wrote:<br>
    &gt; <br>
    &gt; Hi All,<br>
    &gt; <br>
    &gt; I am using Bind as resolver for end users&nbsp; .<br>
    &gt; <br>
    &gt; At various time, bind logs show &quot;broken trust chain&quot; continuously&nbsp; , for about 20mn&nbsp; ~ 30 mn causing an increase of &quot;recursive clients&quot; shown in &quot;rndc status&quot; and a decrease of&nbsp; &quot;DNS sucess rate KPI&
    quot; supervised from end users side.&nbsp; then the error disappear
    and everything is OK.<br>
    &gt; <br>
    &gt; the problem appears on different server at different time.<br>
    &gt; <br>
    &gt; What could be the problem?<br>
    &gt; <br>
    &gt; Regards, <br>
    &gt; <br>
    &gt; <br>
    &gt; « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L’intégrité des messages électroniques n’é
    tant pas
    garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.<br>
    &gt; <br>
    &gt; Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l’expéditeur et le détruire y compris les pièces jointes.<br>
    &gt; <br>
    &gt; Merci. »<br>
    &gt; <br>
    &gt; --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------<

    &gt; <br>
    &gt; « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages
    that have
    been modified, changed or falsified.<br>
    &gt; <br>
    &gt; If you have received this email in error, please notify the sender and delete this message and its attachments.<br>
    &gt; <br>
    &gt; Thank you. »<br>
    &gt; <br>
    &gt; _______________________________________________<br>
    &gt; Please visit <a href="https://lists.isc.org/mailman/listinfo/bind-users">https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from this list<br>
    &gt; <br>
    &gt; ISC funds the development of this software with paid support subscriptions. Contact us at
    <a href="https://www.isc.org/contact/">https://www.isc.org/contact/</a> for more information.<br>
    &gt; <br>
    &gt; <br>
    &gt; bind-users mailing list<br>
    &gt; bind-users@lists.isc.org<br>
    &gt; <a href="https://lists.isc.org/mailman/listinfo/bind-users">https://lists.isc.org/mailman/listinfo/bind-users</a><br>

    -- <br>
    Mark Andrews, ISC<br>
    1 Seymour St., Dundas Valley, NSW 2117, Australia<br>
    PHONE: &#43;61 2 9871 4742&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; INTERNET: marka@isc.org<br>

    </div>
    </span></font><br>

    <font face="Arial" color="Gray" size="2"><br>
    « Ce message et toutes les pièces y jointes sont susceptibles de contenir des informations confidentielles ou privilégiées, lesquelles ne doivent être reproduites, diffusées ou exploitées sans autorisation. L’intégrité des messages électroniques n’étant
    pas
    garantie, WANA CORPORATE décline toute responsabilité dans le cas où ce message aurait été altéré, déformé ou falsifié.<br>

    Ce message est établi à l'attention exclusive de ses destinataires. Si vous avez reçu ce message par erreur, veuillez le signaler à l’expéditeur et le détruire y compris les pièces jointes.<br>

    Merci. »<br>

    --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------<br>

    « This message and its attachments may contain confidential or privileged information that should not be copied, distributed or used without authorization. As the integrity of emails may not be guaranteed, WANA CORPORATE is not liable for messages that
    have
    been modified, changed or falsified.<br>

    If you have received this email in error, please notify the sender and delete this message and its attachments.<br>

    Thank you. »<br>

    </font>
    </body>
    </html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)