From: Alex Dehnert Date: Thu, 13 Aug 2026 20:02:04 +0000 (+0000) Subject: Clean up some old config X-Git-Url: https://www.dehnerts.com/gitweb/?a=commitdiff_plain;h=1a9b1c5c2f2c14ee679247624721b1567ef3d948;p=sysconfig%2Fbind.git Clean up some old config --- diff --git a/named.conf.local b/named.conf.local index 85cfdde..b848c99 100644 --- a/named.conf.local +++ b/named.conf.local @@ -12,8 +12,9 @@ # notify no; #}; -// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they -// can make the requests) *and* as masters (so they get the notify). +// Unfortunately, AFAICT we need to list the Linode IPs as an ACL (so they can +// make the requests) *and* as masters (so they get the notify -- +// secondaries-only, not the importers). acl "linode" { // Linode // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#operate-as-a-secondary-read-only-dns-service @@ -48,37 +49,33 @@ masters "linode" { 2600:3c02::a; 2600:3c03::a; 2a01:7e00::a; - // Import - // https://www.linode.com/docs/products/networking/dns-manager/guides/incoming-dns-zone-transfers/#import-a-dns-zone - 96.126.114.97; - 96.126.114.98; - 2600:3c00::5e; - 2600:3c00::5f; }; // The actual ACL building blocks acl "transfer-allowed" { - localhost; 207.29.250.54; // ??? - 18.4.60.36; // charon - 18.49.3.1; // charon4 - 18.25.131.1; // charon4 + 18.4.60.36; // charon (SIPB-DNS) + 18.49.3.1; // charon4 (SIPB-DNS) + 18.25.131.1; // charon4 (SIPB-DNS) 74.207.246.137; // arctic 66.92.29.156; // copan 18.18.208.12; // olinda - 18.25.129.162; // adehnert3.xvm - 130.44.166.3; // DD 18.18.208.22; // chankillo + 18.25.129.162; // adehnert3.xvm + 73.149.184.234; // Fulgora Comcast IPv4 + 2601:189:8482:d823:9d98:6c9f:ffec:ccdc; // Fulgora Comcast IPv6 + 66.228.43.247; // goslar "linode"; }; masters "primary-ns" { - 18.18.208.22; // chankillo + //18.18.208.22; // chankillo + 66.228.43.247; // goslar }; masters "secondary-ns" { - 18.25.129.162; // adehnert3.xvm - 18.18.208.12; // olinda + //18.25.129.162; // adehnert3.xvm + //18.18.208.12; // olinda linode; }; @@ -105,7 +102,6 @@ zone "dehnert.arctic.org" IN { zone "dehnerts.com" IN { type master; file "/etc/bind/pri/combined-dehnerts.zone"; - #update-policy { grant * selfsub * A TXT;}; allow-update { none; }; allow-transfer { "transfer-allowed"; }; allow-query { any; }; diff --git a/named.conf.options b/named.conf.options index 8c01847..1a64030 100644 --- a/named.conf.options +++ b/named.conf.options @@ -12,12 +12,12 @@ options { // ALEX DEHNERT: slightly updated 2008-12-19 // ALEX DEHNERT: slightly updated 2010-03-01 - forward first; - forwarders { - 18.0.71.151; - 18.0.70.160; - 18.0.72.3; - }; + //forward first; + //forwarders { + // 18.0.71.151; + // 18.0.70.160; + // 18.0.72.3; + //}; //======================================================================== // If BIND logs error messages about the root key being expired, @@ -28,7 +28,7 @@ options { // ALEX DEHNERT: copied from old arctic version on 2008-12-19 //ALEX DEHNERT: Security-related stuff: // Secure(ish): - allow-recursion { 18.18.208.12; 66.92.29.156; 66.92.29.144; 127.0.0.1; 192.168.0.0/16; 18.0.0.0/8; }; + allow-recursion { 18.18.208.12; 66.92.29.156; 66.92.29.144; 127.0.0.1; 192.168.0.0/16; }; //allow-query { 66.92.29.156; 66.92.29.144; 127.0.0.1; }; allow-transfer { none; };