Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

How to configure CentOS BIND as slave with Windows Server 2008 master using GSS-TSIG

Posted on 2011-03-23
Last Modified: 2012-05-11
Hello 'Experts',

We are trying to configure a DNS service using Microsoft Windows Server 2008 R2 as the primary master DNS server and CentOS 5.5 running BIND 9.7.3 as the secondary slave. We have been successful in getting this running with the master transferring the zone data to the slave in an 'insecure' build. Our next step is to 'harden' the build by implementing GSS-TSIG to secure the zone tranfers between the master and slave servers. We referred to the following good article written by Patrick H Piper:


However, this article specifically refers to the Linux server as the master. We want to configure the Linux server as slave. When we applied the recommended configuration to our named.conf file, this broke the named service [i.e. we were not able to start the service]. The error message reported that you cannot use the 'update-policy' directive with a slave server.

Our question is how do we configure named.conf as a slave to use GSS-TSIG to secure zone transfers between the Windows based DNS master server and the CentOS based DNS slave?

Many thanks in advance.
Question by:Link-HRSystems

Accepted Solution

dsexton18 earned 500 total points
ID: 35219265

Author Closing Comment

ID: 35365262
This solution didn't actually reference my particular requirements, using Microsoft Windows Server 2008 R2 as the primary master DNS server and CentOS 5.5 running BIND 9.7.3 as the secondary slave as a consequence I have changed my solution, to using CentOS 5.5 running BIND 9.7 as the primary master DNS server and CentOS 5.5 running BIND 9.7.3 as the secondary slave , the article suggested by 'dsexton18' is for this solution.

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CENTOS DHCP Server / PXE/TFTP 14 152
Bash script - Exit out of choice loop 2 43
DNS issues after a power outage 3 43
Domain forwarding 4 21
INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question