[Opendnssec-user] OpenDNSSEC in ISP environment (lots of small zones)?

Jan-Piet Mens jpmens at gmail.com
Mon Jan 31 13:04:23 UTC 2011


Matthijs,

> It does not look a permission problem to me: the log message appears
> because ldns_axfr_next() could not get a RR from the AXFR.
>
> The most obvious reasons for this failure are
> - - the wire could not be converted to the ldns packet structure (for
> example, a RR could not be parsed)
> - - the RCODE does not equal NOERROR

I consider that a bit doubtful: the zone is served by BIND 9.7.2-P3 and 
contains nothing terribly exciting in the way of RR. Furthermore Unbound 
can query any record in those zones.

Additionally, as shown in a message a few minutes ago, increasing the 
verbosity of the signer triggers a successful AXFR ...

	-JP




More information about the Opendnssec-user mailing list