  • 1. "named" startup on Fedora Core 6 (/etc/init.d/named)
    [ rant: I'm not always a fan of complex startup scripting, and this is probably one good example... ] It appears /etc/init.d/named on Fedora Core 6 (and subsequently /etc/sysconfig/named) doesn't start up BIND in a way you might expect, even if you explicitly set OPTIONS in the sysconfig/named file -- it prevents named from writing it's slave files (yes, permissions/ownership are correct): OPTIONS="-u named -c /etc/named.conf" errors: Jan 18 08:35:18 ns named: _default/de-archive.domain.tld/IN: file not found (huh??) Jan 18 08:37:29 ns named: zone subdom.domain.tld/IN: loading master file slaves/subdom.domain.tld: file not found .. which can be fixed if I just "touch" the file (with the correct ownership). Alas, if I just start it up by hand: /usr/sbin/named -u named -c /etc/named.conf no problems... zones transferred. I wonder if someone knows what the issue is... Thanks.
  • 2. Cleaning up DNS zone files...
    I've inherited a slew of DNS zonefiles which need to be cleaned up - mostly formatting. I can use tools like dnslint to indentify errors; however, I wonder if someone has a slick hack (script, regex) that can be utilized to run through and reformat the zonefiles (forward and reverse) to get them in order and tidy. Thanks.
  • 3. Asymmetric keys with rndc-confgen?
    Every time I've seen rndc-conf generat an hmac-md5 key, the text of the key has been the same everywhere. Yesterday, using 9.3.3 (I believe), I got the following result (at the end of this). Is there some syntax that will cause a public/private key by default with rndc.confgen? Note: this is not the key I am using, the one I am using IS the same in both rndc.conf and the bind include file. (PS: Maybe asymetric is not the right word?) -Dan # Start of rndc.conf key "rndc-key" { algorithm hmac-md5; secret "NlUtbtQyzxVpfQ51W1jEu+UsBN0A3vXs4K2d5Ob0Tzs="; }; options { default-key "rndc-key"; default-server; default-port 953; }; # End of rndc.conf # Use with the following in named.conf, adjusting the allow list as needed: # key "rndc-key" { # algorithm hmac-md5; # secret "K5YfO1+dX5ku5sXjzSrJyw=="; # }; # # controls { # inet port 953 # allow {; } keys { "rndc-key"; }; # }; # End of named.conf

Postby Gilles Massen » Thu, 16 Nov 2006 19:22:17 GMT


I have a weird issue with a bind9 resolver: it fails to resolve a domainname 
that appears to be absolutely correctly configured (and which works correctly 
from another bind9 server). I even expect it to work after restarting Bind, 
but I don't want to do it yet in sake of finding what is wrong.

The host I cannot resolve is, returning no answer.
The domain is delegated to ns19 +  Both are reachable. From 
the nameserver:

ns:/usr/local/named-ns/var/log # dig @localhost

; <<>> DiG 9.3.2-P1 <<>> @localhost
; (2 servers found)
;; global options:  printcmd
;; connection timed out; no servers could be reached
ns:/usr/local/named-ns/var/log # dig

; <<>> DiG 9.3.2-P1 <<>>
; (1 server found)
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23910
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 0

;         IN      A

;; ANSWER SECTION:  7200    IN      A

;; AUTHORITY SECTION:      7200    IN      NS      7200    IN      NS

;; Query time: 111 msec
;; WHEN: Wed Nov 15 11:18:38 2006
;; MSG SIZE  rcvd: 102

Where could this go wrong? Our firewall isn't logging anything. Everyone is 
reachable, even through IPv6 (the only IPv6 addresses involved being those 
for a +

Any hint to what to try, before I have to restart bind, would be much 

Best regards,
Gilles Massen

Who is online

Users browsing this forum: No registered users and 17 guest