Re: DNSSEC/Log Spam for partially DNSSEC domain

From: Dimitry Andric <dim_at_FreeBSD.org>
Date: Sat, 30 Jun 2018 11:33:19 +0200
On 30 Jun 2018, at 04:03, Larry Rosenman <ler_at_FreeBSD.org> wrote:
> 
> I'm running Exim, with DNSSEC enabled, and my zone (lerctr.org) is
> DNSSEC signed, but my dyn.lerctr.org subdomain is NOT DNSSEC signed due
> to HE.net don't support DNSSEC.
> 
> I get a ton of:
> Jun 29 20:12:53 thebighonker exim[37649]: gethostby*.gethostanswer: asked for "borg.lerctr.org IN AAAA", got type "RRSIG"
> Jun 29 20:12:53 thebighonker exim[37649]: gethostby*.gethostanswer: asked for "borg.lerctr.org IN A", got type "RRSIG"
> 
> in my logs, which comes from libc:
> /usr/src/lib/libc/net/getaddrinfo.c:
>   2092 #ifdef DEBUG
>   2093                         if (type != T_KEY && type != T_SIG &&
>   2094                             type != ns_t_dname)
>   2095                                 syslog(LOG_NOTICE|LOG_AUTH,
>   2096                "gethostby*.getanswer: asked for \"%s %s %s\", got type \"%s\"",
>   2097                                        qname, p_class(C_IN), p_type(qtype),
>   2098                                        p_type(type));
>   2099 #endif
> 
> Is there an easy way to make this quieter?

I see this code is only included if DEBUG is defined.  Maybe undefine
DEBUG, for this particular file?  Or hack it so it has #undef DEBUG at
the top?

That said, I'm not sure if debug messages like this should be enabled by
default, and impossible to squelch without recompiling libc.  So maybe
we should #if 0 it, instead.

-Dimitry


Received on Sat Jun 30 2018 - 07:33:25 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:16 UTC