Actualités Actualités

Warning for BIND and delegation-only users

Home > Observatory and resources > News > Warning for BIND and delegation-only users
06/11/2007

The AFNIC has recently slightly changed the .fr and .re DNS zones and would like to draw the server adminstrators’ attention on some configurations that might need adjustments.

Since May 23rd 2007, the AFNIC has transformed the .fr sub-domains that it handles directly (like huissier-justice.fr or veterinaire.fr). These sub-domains are now directly into the .fr zone and not in a separate zone anymore (.re was already changed earlier).

This does not change the ordinary use of these domain names. Only experts will notice some details like missing SOA or NS for these domain names or missing name servers in the Whois output.

But a problem can happen if a website uses BIND (given by the ISC) for its recursive name servers and if this BIND was configured with the delegation-only or root-delegation-only options (options not activated by default).
The options are documented at the following address: http://www.isc.org/index.pl?/sw/bind/delegation-only.php.

If the configuration includes a delegation-only for .fr and .re or if it includes a root-delegation-only and that .fr and .re are not in the list of exceptions, then, the names in the subdomains, until the next zone cut, will not resolve.
In that case BIND sends a “NXDOMAIN” without an AUTHORITY section and saves it in its log (the recommended tool for debug). So dupont.departement.huissier-justice.fr will work but not mail.huissier-justice.fr (this name is recommended for testing: you should be able to resolve it into an IPv4 address).

This is the reason why the AFNIC asks that you add .fr and .re in the list of exclusions if your are using BIND as a resolver and have configured the root-delegation-only option. If are using delegation-only, do not add .fr or .re in the list.

We would like to inform you that the AFNIC is commited not to insert wildcards in the .fr and .re (see
L’AFNIC et les wildcards: www.afnic.fr/actu/nouvelles/international/NN20030918) and that this request should not have any negative consequences.

About the AFNIC

(Association Française pour le Nommage Internet en Coopération)

Non-profit organization, the AFNIC is in charge of the administrative and technical management of the .fr (France) and .re (Reunion Island) Internet domain names.
The AFNIC brings together public and private members: representatives from the French government, Internet users and Internet Service Providers.
Further information.