bind9 dns troubles

Scott Schulz swschulz at astrum.com
Mon Jul 18 21:18:28 UTC 2016


On 18 Jul 2016, at 12:12, Bob wrote:

> Thanks Scott.
>
> It seems to be working now. I do have a question about nslookup. Why 
> does it give me a non-authoritative answer for my domain? I looked 
> this up and it says that the this means that the primary nameserver 
> (faithwalk.ca) is not listed at the parent. I take this to mean at my 
> registrar and it actually is listed there. Is there another reason? 
> Shouldn't it be authoritative?

Really depends on the configuration, but on a typical machine nslookup 
uses whichever DNS servers are provided by DHCP or (on linux, etc) 
whatever is in /etc/resolv.conf.  These may or may not be machines 
authoritative for the zone, e.g.


1) Using my default OpenDNS resolver returns the Non-authoritative 
message as expected:

    $ nslookup

   > faithwalk.ca
    Server:         208.67.222.222
    Address:        208.67.222.222#53

    Non-authoritative answer:
    Name:   faithwalk.ca
    Address: 24.72.66.135


2) However, when we switch to query one of the servers specified in the 
zone file, we no longer receive that:

   > server server.faithwalk.ca
    Default server: server.faithwalk.ca
    Address: 24.72.66.135#53

   > faithwalk.ca
    Server:         server.faithwalk.ca
    Address:        24.72.66.135#53

    Name:   faithwalk.ca
    Address: 24.72.66.135


3)  And, the same from its alias,

   > server faithwalk.ca
    Default server: faithwalk.ca
    Address: 24.72.66.135#53

   > faithwalk.ca
    Server:         faithwalk.ca
    Address:        24.72.66.135#53

    Name:   faithwalk.ca
    Address: 24.72.66.135

4)  And from any machine specified in the zone file:

   > server ns0.xname.org
    Default server: ns0.xname.org
    Address: 195.234.42.1#53

   > faithwalk.ca
    Server:         ns0.xname.org
    Address:        195.234.42.1#53

    Name:   faithwalk.ca
    Address: 24.72.66.135

This is completely expected behavior, and while I personally might tweak 
some things, there’s nothing else grossly incorrect in the config 
(imho).  You should be good to go.

SwS




More information about the ubuntu-users mailing list