Found some time to work on it again and it seams I did something wrong
last time as ms-subdomain now works!
Thanks for your help!!
I did notice one strange thing when turning on trace mode of named:
Whenever an update request occurs I see a lot of messages like:
-
I already tried ms-self and ms-subdomain. Unfortunately that doesn't
seem to make any difference.
Nico
On Tue, 2008-12-30 at 13:44 -0500, Rob Austein wrote:
> At Tue, 30 Dec 2008 16:05:10 +0100, Nico De Ranter wrote:
> >
> > update-policy {
> >
type master;
file "test.net.zone";
update-policy {
grant TEST.NET krb5-subdomain * A;
};
};
}
But it doesn't seem to help.
Nico
--
With kind regards,
Nico De Ranter
Senior System Adminis
2008 10:51:08.373 client 10.10.10.101#1054: view internal: next
30-Dec-2008 10:51:08.373 client 10.10.10.101#1054: view internal:
ns_client_detach: ref = 0
30-Dec-2008 10:51:08.373 client 10.10.10.101#1054: view internal:
endrequest
30-Dec-2008 10:51:08.373 client @0xb604b008: udprecv
On Fri, 2
to run fine. I didn't see any error messages related to
gssapi (configure finds the libraries and header files without
problems.)
named runs fine as long as I don't use the 'tkey' options.
Any idea what might be wrong?
Thanks in advance,
Nico
On Wed, 2008-12-24 at 09:10 +010
Thank you very much for your very detailed instructions. I'm going to
try it right away.
Nico
On Tue, 2008-12-23 at 17:41 -0500, Rob Austein wrote:
> Four things must be done to allow Bind 9 to support GSS-TKEY:
>
> * kinit must work on the host which will run BIND 9. This means
> kr
plenty of info about that but my binds are running just fine on
linux. The main issue is getting secure dynamic updates working.
Thanks in advance,
Nico
--
With kind regards,
Nico De Ranter
Senior System Administrator
Sony Techsoft Centre
The Corporate Village · Da Vincilaan 7-D1 · B-1935 Zav
7 matches
Mail list logo