[dns-operations] Bind 9.8.0 intermittent problem with non-recursive responses

Matthew Pounsett matt at conundrum.com
Fri May 20 00:08:39 UTC 2011

While it's possible you have encountered a bug with BIND, it's generally a bad idea to mix recursive and authoritative service in the same process. The RFCs that define the resolution algorithms were never written with mixed service in mind, and there are conflicts that can result in undefined, and therefore unpredictable, behaviours.   It will be hard to determine which you're seeing without more specific information about the configuration of the servers in question (e.g. which zones they're actually authoritative for).  

You will particularly run into problems if you ever intend to do DNSSEC validation on these name servers.. it just won't work.

I maintained the cross-posting for this reply because of the general DNS service advice, but my suggestion would be to limit the thread to the bind-users until you identify or rule-out a bug.

