Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Habbie
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Habbie
5y ago
Hey, thanks for the PR, love that! The wasteful SOA query is a result of our internal code flow. You can reduce wasteful queries a bit with the new `consistent-backends` setting, but the SOA query will remain. We (no longer) have a knob to
2.
▲
by
Habbie
5y ago
Hello! PowerDNS developer here. Did you spot https://doc.powerdns.com/authoritative/appendices/internals.... and https://doc.powerdns.com/authoritative/appendices/backend-wr... ? And if
3.
▲
by
Habbie
6y ago
I can echo all of this - we also pay, we're very happy, the concurrency is nice (I believe they're bumping it to 80x soon - when my coworker asked "but what's the catch" I realised we pay by the CPU minute anyway so
4.
▲
by
Habbie
8y ago
Can you share the domain name so we can investigate?
5.
▲
by
Habbie
8y ago
I bet this was in before the SPF also went in. You should feel free to take this up with IANA, of course :)
6.
▲
by
Habbie
8y ago
If you are managing your zone data in RCS or similar, why not expose that information in DNS as well? Could be useful for debugging. Indeed, on 2015-01-01, it said "$Id: example.com 3280 2014-12-10 00:15:12Z spowell $". It does no
7.
▲
by
Habbie
9y ago
Thank you for the kind words! - Peter van Dijk, PowerDNS
8.
▲
by
Habbie
9y ago
Hello, PowerDNS developer here! Not trying to steal Tenta's thunder here, but you should know that the PowerDNS GeoIP backend can be used without a GeoIP database, in which case it might better be called the 'YAML backend'. A
9.
▲
by
Habbie
9y ago
The .nl registry does not support algo 15 (and 16) for DS records yet. Support is expected soon.
10.
▲
by
Habbie
9y ago
You said it right - can help defend. On the other end of your dnscrypt tunnel, the queries will still go out unencrypted. They will just be harder to correlate to you specifically.
11.
▲
by
Habbie
9y ago
PowerDNS developer here - any nits we should know about?
12.
▲
by
Habbie
9y ago
It means that for those zones, they explicitly put the IPs of the edge servers in their resolver (Unbound) configuration, so that lookups of names in those zones don't have to go the root servers and then the TLD (like .com) servers, o
13.
▲
by
Habbie
11y ago
No, not in the narrowest way. You can go 'somewhere in between' at the cost of blowing up your zone size tremendously, but it's not worth it.
14.
▲
by
Habbie
11y ago
So have three online signers.
15.
▲
by
Habbie
11y ago
I.E. the way SSL/TLS is run today.
16.
▲
by
Habbie
11y ago
I don't know of any either, but there are plenty running PowerDNS in online 'white lies' signing mode. And then, of course, there is Cloudflare. (And indeed, it cannot be done offline - although doing much narrower NSEC/
17.
▲
by
Habbie
15y ago
Just add !gm to your query. If you do it a few times, DDG will remember it and make it easy to add !gm just by pushing ! to open the dropdown.