Solved

How to configure CentOS BIND as slave with Windows Server 2008 master using GSS-TSIG

Posted on 2011-03-23
2
2,478 Views
Last Modified: 2012-05-11
Hello 'Experts',

We are trying to configure a DNS service using Microsoft Windows Server 2008 R2 as the primary master DNS server and CentOS 5.5 running BIND 9.7.3 as the secondary slave. We have been successful in getting this running with the master transferring the zone data to the slave in an 'insecure' build. Our next step is to 'harden' the build by implementing GSS-TSIG to secure the zone tranfers between the master and slave servers. We referred to the following good article written by Patrick H Piper:

http://www.netlinxinc.com/netlinx-blog/45-dns/136-how-to-implement-gss-tsig-on-isc-bind.html

However, this article specifically refers to the Linux server as the master. We want to configure the Linux server as slave. When we applied the recommended configuration to our named.conf file, this broke the named service [i.e. we were not able to start the service]. The error message reported that you cannot use the 'update-policy' directive with a slave server.

Our question is how do we configure named.conf as a slave to use GSS-TSIG to secure zone transfers between the Windows based DNS master server and the CentOS based DNS slave?

Many thanks in advance.
0
Comment
Question by:Link-HRSystems
2 Comments
 
LVL 3

Accepted Solution

by:
dsexton18 earned 500 total points
ID: 35219265
0
 

Author Closing Comment

by:Link-HRSystems
ID: 35365262
This solution didn't actually reference my particular requirements, using Microsoft Windows Server 2008 R2 as the primary master DNS server and CentOS 5.5 running BIND 9.7.3 as the secondary slave as a consequence I have changed my solution, to using CentOS 5.5 running BIND 9.7 as the primary master DNS server and CentOS 5.5 running BIND 9.7.3 as the secondary slave , the article suggested by 'dsexton18' is for this solution.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
spf record 8 55
Mimecast Bounce 3 28
a free alternative to cpanel? 1 37
Linux as a middle box 7 18
Introduction We as admins face situation where we need to redirect websites to another. This may be required as a part of an upgrade keeping the old URL but website should be served from new URL. This document would brief you on different ways ca…
I. Introduction There's an interesting discussion going on now in an Experts Exchange Group — Attachments with no extension (http://www.experts-exchange.com/discussions/210281/Attachments-with-no-extension.html). This reminded me of questions tha…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now