Clean up some old config
authorAlex Dehnert <alex@dehnerts.com>
Thu, 13 Aug 2026 20:02:04 +0000 (20:02 +0000)
committerAlex Dehnert <alex@dehnerts.com>
Thu, 13 Aug 2026 20:02:39 +0000 (20:02 +0000)
named.conf.local
named.conf.options

index 85cfdde00491b0f71261065abf0156270b258619..b848c9924b77e49b68d2083ff0bcf170e1084898 100644 (file)
@@ -12,8 +12,9 @@
 #        notify no;
 #};
 
-// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they
-// can make the requests) *and* as masters (so they get the notify).
+// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they can
+// make the requests) *and* as masters (so they get the notify --
+// secondaries-only, not the importers).
 acl "linode" {
     // Linode
     // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#operate-as-a-secondary-read-only-dns-service
@@ -48,37 +49,33 @@ masters "linode" {
     2600:3c02::a;
     2600:3c03::a;
     2a01:7e00::a;
-    // Import
-    // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#import-a-dns-zone
-    96.126.114.97;
-    96.126.114.98;
-    2600:3c00::5e;
-    2600:3c00::5f;
 };
 
 // The actual ACL building blocks
 acl "transfer-allowed" {
-    localhost;
     207.29.250.54;  // ???
-    18.4.60.36;     // charon
-    18.49.3.1;      // charon4
-    18.25.131.1;    // charon4
+    18.4.60.36;     // charon (SIPB-DNS)
+    18.49.3.1;      // charon4 (SIPB-DNS)
+    18.25.131.1;    // charon4 (SIPB-DNS)
     74.207.246.137; // arctic
     66.92.29.156;   // copan
     18.18.208.12;   // olinda
-    18.25.129.162;  // adehnert3.xvm
-    130.44.166.3;   // DD
     18.18.208.22;   // chankillo
+    18.25.129.162;  // adehnert3.xvm
+    73.149.184.234; // Fulgora Comcast IPv4
+    2601:189:8482:d823:9d98:6c9f:ffec:ccdc; // Fulgora Comcast IPv6
+    66.228.43.247;  // goslar
     "linode";
 };
 
 masters "primary-ns" {
-    18.18.208.22;   // chankillo
+    //18.18.208.22;   // chankillo
+    66.228.43.247;  // goslar
 };
 
 masters "secondary-ns" {
-    18.25.129.162;  // adehnert3.xvm
-    18.18.208.12;   // olinda
+    //18.25.129.162;  // adehnert3.xvm
+    //18.18.208.12;   // olinda
     linode;
 };
 
@@ -105,7 +102,6 @@ zone "dehnert.arctic.org" IN {
 zone "dehnerts.com" IN {
        type master;
        file "/etc/bind/pri/combined-dehnerts.zone";
-       #update-policy { grant * selfsub * A TXT;};
         allow-update { none; };
        allow-transfer { "transfer-allowed"; };
        allow-query { any; };
index 8c01847565887cd364a58d456b888bb360eedd1a..1a6403069f00cbed13f5bf77249b1550b9d2304e 100644 (file)
@@ -12,12 +12,12 @@ options {
 
        // ALEX DEHNERT: slightly updated 2008-12-19
        // ALEX DEHNERT: slightly updated 2010-03-01
-       forward first;
-       forwarders {
-               18.0.71.151;
-               18.0.70.160;
-               18.0.72.3;
-       };
+       //forward first;
+       //forwarders {
+       //      18.0.71.151;
+       //      18.0.70.160;
+       //      18.0.72.3;
+       //};
 
        //========================================================================
        // If BIND logs error messages about the root key being expired,
@@ -28,7 +28,7 @@ options {
        // ALEX DEHNERT: copied from old arctic version on 2008-12-19
        //ALEX DEHNERT: Security-related stuff:
        // Secure(ish):
-       allow-recursion { 18.18.208.12; 66.92.29.156; 66.92.29.144; 127.0.0.1; 192.168.0.0/16; 18.0.0.0/8; };
+       allow-recursion { 18.18.208.12; 66.92.29.156; 66.92.29.144; 127.0.0.1; 192.168.0.0/16; };
        //allow-query   { 66.92.29.156; 66.92.29.144; 127.0.0.1; };
        allow-transfer { none; };