Re: 9.7.0-P1 managed-keys.bind issues

2010-04-14 Thread Evan Hunt
> It would appear that these are all related. Allowing outbound DNS > queries fixed these messages. Thanks for the report. If you didn't want to allow outbound DNS queries, then just turn off dnssec-lookaside. What it's doing is trying to refresh the DNSSEC key for dlv.isc.org, but if you weren'

Re: 9.7.0-P1 managed-keys.bind issues

2010-04-14 Thread Hauke Lampe
Mark Watts wrote: > Apr 14 12:06:34 dns01 named[4911]: zone managed-keys.bind/IN/_meta: > sync_keyzone:dns_journal_open -> unexpected error Does named have permission to create files in the directory specified by "directory" in the options block? BIND uses an internal dynamic zone for RFC5011-u

Re: 9.7.0-P1 managed-keys.bind issues

2010-04-14 Thread Mark Watts
On Wed, 2010-04-14 at 13:10 +0100, Mark Watts wrote: > I'm trying to setup a new 9.7.0-P1 server in order to (initially) do > DNSSEC validation lookups. > I'm using the Fedora 13 SRPM, recompiled on CentOS 5.4. SELinux is Off > currently. > > when I add the following to my options {} section, I ge

9.7.0-P1 managed-keys.bind issues

2010-04-14 Thread Mark Watts
I'm trying to setup a new 9.7.0-P1 server in order to (initially) do DNSSEC validation lookups. I'm using the Fedora 13 SRPM, recompiled on CentOS 5.4. SELinux is Off currently. when I add the following to my options {} section, I get some log messages I don't understand... dnssec-enable