[nsd-users] nsd does not fallback to axfr when ixfr doesn't work

W.C.A. Wijngaards wouter at NLnetLabs.nl
Wed Aug 27 15:53:45 UTC 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ralf Weber wrote:
> I've tested this on Linux with NSD 3.1.1. In that setup NSD is acting as
> a slave to an ANS server. And normally IXFR works fine, but in cases
> where ANS doesn't want to do an IXFR (e.g after a zone resign) it
> answers with an SERVFAIL. I am not sure what the RFC says, but I would
> expect NSD to fall back to axfr, but it does not do this and you have to
> remove the file to start an axfr manually.

According to the IXFR spec, it is allowed to return the full AXFR reply
in return to the IXFR query.  So, the RFC says that the ANS server could
have replied instead of servfail...

Best regards,
   Wouter
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAki1eIkACgkQkDLqNwOhpPgnQwCffCCMpcIuKcv9U8ZpPzw2tit8
yAEAnAhIqTKFFhBqLU27mjT0UCPPmf6x
=mnx+
-----END PGP SIGNATURE-----



More information about the nsd-users mailing list