here is output when doing drill
www.nic.cz
-----------------------------
Nov 09 11:58:54 skriatok kresd[4702]: [00000.00][plan] plan 'www.nic.cz.' type
'A' uid [15793.00]
Nov 09 11:58:54 skriatok kresd[4702]: [15793.00][iter] 'www.nic.cz.' type
'A' new uid was assigned .01, parent uid .00
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][cach] => no NSEC* cached for zone:
.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][cach] => skipping zone: ., NSEC,
hash 0;new TTL -123456789, ret -2
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][resl] => going insecure because
there's no covering TA
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][zcut] found cut: . (rank 020 return
codes: DS -2, DNSKEY -2)
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][wrkr] => connecting to:
'198.41.0.4#00053'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][wrkr] => connected to
'198.41.0.4'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][resl] => id: '10852'
querying: '198.41.0.4' score: 1644 zone cut: '.' qname: 'Cz.'
qtype: 'NS' proto: 'tcp'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
k.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
l.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
c.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
j.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
d.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
g.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
e.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
h.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
m.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
i.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
b.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= authority: missing
mandatory glue, skipping NS
f.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= loaded 1 glue addresses
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= rcode: NOERROR
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] <= retrying with non-minimized
name
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][cach] => not overwriting A
a.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][resl] <= server:
'198.41.0.4' rtt: 50 ms
Nov 09 11:58:54 skriatok kresd[4702]: [15793.01][iter] 'www.nic.cz.' type
'A' new uid was assigned .02, parent uid .00
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][resl] => id: '29577'
querying: '198.41.0.4' score: 847 zone cut: '.' qname:
'WWW.nIc.CZ.' qtype: 'A' proto: 'udp'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
f.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
g.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
d.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
k.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
l.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
i.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
b.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
j.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
h.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
e.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
m.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= authority: missing
mandatory glue, skipping NS
c.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= loaded 1 glue addresses
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= rcode: NOERROR
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] <= lame response: non-auth
sent negative response
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][cach] => not overwriting A
a.root-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][resl] => server:
'198.41.0.4' flagged as 'bad'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.02][iter] 'www.nic.cz.' type
'A' new uid was assigned .03, parent uid .00
Nov 09 11:58:54 skriatok kresd[4702]: [15793.03][plan] plan
'i.root-servers.net.' type 'AAAA' uid [15793.04]
Nov 09 11:58:54 skriatok kresd[4702]: [15793.04][iter] 'i.root-servers.net.'
type 'AAAA' new uid was assigned .05, parent uid .03
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => no NSEC* cached for zone:
net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => skipping zone: net.,
NSEC, hash 0;new TTL -123456789, ret -2
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][resl] => id: '02676'
querying: '198.41.0.4' score: 1373 zone cut: '.' qname: 'Net.'
qtype: 'NS' proto: 'udp'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][iter] <= loaded 26 glue addresses
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][iter] <= referral response,
follow
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting NS net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
l.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
l.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
a.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
a.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
f.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
f.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
d.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
d.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
j.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
j.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
e.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
e.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
i.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
i.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
c.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
c.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
h.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
h.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
b.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
b.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
k.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
k.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
g.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
g.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting AAAA
m.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][cach] => not overwriting A
m.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][resl] <= server:
'198.41.0.4' rtt: 14 ms
Nov 09 11:58:54 skriatok kresd[4702]: [15793.05][iter] 'i.root-servers.net.'
type 'AAAA' new uid was assigned .06, parent uid .03
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS:
2001:503:a83e::2:30, score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS: 192.5.6.30,
score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS:
2001:503:231d::2:30, score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS: 192.33.14.30,
score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS:
2001:503:83eb::30, score 200
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS:
2001:503:d2d::30, score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS: 192.52.178.30,
score 1903
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS:
2001:500:d937::30, score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS: 192.41.162.30,
score 1900
Nov 09 11:58:54 skriatok kresd[4702]: [ ][nsre] probing timeouted NS:
2001:501:b1f9::30, score 2000
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][resl] => id: '63676'
querying: '2001:501:b1f9::30' score: 1424 zone cut: 'net.' qname:
'rOoT-SeRveRS.neT.' qtype: 'NS' proto: 'udp'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][resl] => id: '63676'
querying: '192.55.83.30' score: 1424 zone cut: 'net.' qname:
'rOoT-SeRveRS.neT.' qtype: 'NS' proto: 'udp'
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][iter] <= loaded 26 glue addresses
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][iter] <= rcode: NOERROR
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][iter] <= retrying with
non-minimized name
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][cach] => not overwriting AAAA
d.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][cach] => not overwriting A
d.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][cach] => not overwriting AAAA
a.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][cach] => not overwriting A
a.gtld-servers.net.
Nov 09 11:58:54 skriatok kresd[4702]: [15793.06][cach] => not overwriting AAAA
m.gtld-servers.net.
jb.
Sent with ProtonMail Secure Email.
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Friday, November 9, 2018 11:33 AM, Petr Špaček <petr.spacek(a)nic.cz> wrote:
Hello,
please enable verbose logging - you just need to add
this line to your
config file:
verbose(true)
and restart daemon so we can see what happened.
Petr Špaček @ CZ.NIC
On 09. 11. 18 15:09, Ján Boroš wrote:
> hi
> My idea is to use knot resolver as dns forwarder / cache instead
> using dnsmasq. I am using old PC with archlinux as router.
> I did change dnsmasq config so it listen on port 5353.
> following steps here
>
https://wiki.archlinux.org/index.php/Knot_Resolver I did change
> systemd unit so my kresd is listening on both local interfaces. I
> am checking that with ss command and it is ok.
> here is my config of kresd
> cat /etc/knot-resolver/kresd.conf -- vim:syntax=lua: -- Refer to
> manual:
>
http://knot-resolver.readthedocs.org/en/latest/daemon.html#configuration
> -- Load useful modules modules = { 'policy', -- Block
> queries to local zones/bad sites 'hints > iterate', -- Load
> /etc/hosts and allow custom root hints 'stats', -- Track
> internal statistics 'predict', -- Prefetch
> expiring/frequent records }
> -- See kresd.systemd(7) about configuring network interfaces when
> using systemd -- Listen on localhost (default) -- net = {
> '127.0.0.1', '::1'}
> -- Enable DNSSEC validation -- trust_anchors.file =
> '/etc/knot-resolver/root.keys'
> hints.root_file = '/etc/knot-resolver/root.hints'
> -- Cache size cache.size = 100 * MB
> After start I can see following errors in journal
> Nov 08 22:49:43 skriatok systemd[1]: Starting Knot Resolver
> daemon... Nov 08 22:49:43 skriatok systemd[1]: Started Knot
> Resolver daemon. Nov 08 22:49:53 skriatok kresd[9012]: [priming]
> cannot resolve address 'b.root- servers.net.', type: 1 Nov 08
> 22:49:53 skriatok kresd[9012]: [priming] cannot resolve address
> 'b.root- servers.net.', type: 28 Nov 08 22:49:53 skriatok
> kresd[9012]: [priming] cannot resolve address 'h.root-
> servers.net.', type: 28 Nov 08 22:49:53 skriatok kresd[9012]:
> [priming] cannot resolve address 'j.root- servers.net.', type: 1
> Nov 08 22:49:53 skriatok kresd[9012]: [priming] cannot resolve
> address 'm.root- servers.net.', type: 1 Nov 08 22:49:53 skriatok
> kresd[9012]: [priming] cannot resolve address 'l.root-
> servers.net.', type: 1 Nov 08 22:49:53 skriatok kresd[9012]:
> [priming] cannot resolve address 'j.root- servers.net.', type: 28
> Nov 08 22:49:53 skriatok kresd[9012]: [priming] cannot resolve
> address 'i.root- servers.net.', type: 28 Nov 08 22:49:53 skriatok
> kresd[9012]: [priming] cannot resolve address 'g.root-
> servers.net.', type: 28 Nov 08 22:49:53 skriatok kresd[9012]:
> [priming] cannot resolve address 'f.root- servers.net.', type: 28
> Nov 08 22:49:53 skriatok kresd[9012]: [priming] cannot resolve
> address 'e.root- servers.net.', type: 28 Nov 08 22:49:53 skriatok
> kresd[9012]: [priming] cannot resolve address 'd.root-
> servers.net.', type: 28 Nov 08 22:49:53 skriatok kresd[9012]:
> [priming] cannot resolve address 'a.root- servers.net.', type: 28
> Nov 08 22:49:53 skriatok kresd[9012]: [priming] cannot resolve
> address 'h.root- servers.net.', type: 1 Nov 08 22:49:53 skriatok
> kresd[9012]: [priming] cannot resolve address 'c.root-
> servers.net.', type: 1 Nov 08 22:49:53 skriatok kresd[9012]:
> [priming] cannot resolve address 'k.root- servers.net.', type: 1
> Nov 08 22:49:53 skriatok kresd[9012]: [priming] cannot resolve
> address 'e.root- servers.net.', type: 1 Nov 08 22:49:53 skriatok
> kresd[9012]: [priming] cannot resolve address 'f.root-
> servers.net.', type: 1 ...
> thank you for help