tachtler:dns_isc_bind_centos_7
Unterschiede
Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
Beide Seiten der vorigen RevisionVorhergehende ÜberarbeitungNächste Überarbeitung | Vorhergehende ÜberarbeitungNächste ÜberarbeitungBeide Seiten der Revision | ||
tachtler:dns_isc_bind_centos_7 [2019/10/20 11:45] – [/etc/named.root.key] klaus | tachtler:dns_isc_bind_centos_7 [2019/10/29 05:25] – [/etc/named.conf] klaus | ||
---|---|---|---|
Zeile 1054: | Zeile 1054: | ||
// The pathname of a file to override the built-in trusted keys provided | // The pathname of a file to override the built-in trusted keys provided | ||
// by named. Path to ISC DLV key. | // by named. Path to ISC DLV key. | ||
- | bindkeys-file "/ | + | bindkeys-file "/ |
// The pathname of the file the server dumps security roots to when | // The pathname of the file the server dumps security roots to when | ||
// instructed. | // instructed. | ||
Zeile 1103: | Zeile 1103: | ||
// DLV domain and trust anchor will be used, along with a built-in key for | // DLV domain and trust anchor will be used, along with a built-in key for | ||
// validation. | // validation. | ||
- | dnssec-lookaside auto; | + | |
+ | //dnssec-lookaside auto; | ||
// Checks. --------------------------------------------------------------- | // Checks. --------------------------------------------------------------- | ||
Zeile 1395: | Zeile 1396: | ||
// Zone: localhost. ------------------------------------------------------- | // Zone: localhost. ------------------------------------------------------- | ||
include "/ | include "/ | ||
+ | include "/ | ||
// Zone: home.tachtler.net ------------------------------------------------ | // Zone: home.tachtler.net ------------------------------------------------ | ||
Zeile 1432: | Zeile 1434: | ||
// Zone: localhost. ------------------------------------------------------- | // Zone: localhost. ------------------------------------------------------- | ||
include "/ | include "/ | ||
+ | include "/ | ||
// Zone: home.tachtler.net ------------------------------------------------ | // Zone: home.tachtler.net ------------------------------------------------ | ||
Zeile 1491: | Zeile 1494: | ||
// Zone: localhost. ------------------------------------------------------- | // Zone: localhost. ------------------------------------------------------- | ||
include "/ | include "/ | ||
+ | include "/ | ||
// Zone: edmz.tachtler.net ------------------------------------------------ | // Zone: edmz.tachtler.net ------------------------------------------------ | ||
Zeile 1536: | Zeile 1540: | ||
// Zone: localhost. ------------------------------------------------------- | // Zone: localhost. ------------------------------------------------------- | ||
include "/ | include "/ | ||
+ | include "/ | ||
// Zone: tachtler.net (PDMZ) ---------------------------------------------- | // Zone: tachtler.net (PDMZ) ---------------------------------------------- | ||
Zeile 1552: | Zeile 1557: | ||
// Includes. | // Includes. | ||
// ================================================================================ | // ================================================================================ | ||
- | include "/ | ||
</ | </ | ||
Zeile 2506: | Zeile 2510: | ||
<code ini> | <code ini> | ||
allow-update { key " | allow-update { key " | ||
+ | </ | ||
+ | |||
+ | Für den Inhalt des jeweiligen Zonen-Schlüssels, | ||
+ | <code ini> | ||
+ | # cat / | ||
+ | Private-key-format: | ||
+ | Algorithm: 157 (HMAC_MD5) | ||
+ | Key: K3EaOD3IysiC/ | ||
+ | Bits: AAA= | ||
+ | Created: 20160217132139 | ||
+ | Publish: 20160217132139 | ||
+ | Activate: 20160217132139 | ||
+ | </ | ||
+ | |||
+ | Der Inhalt der Datei sollte dann wie folgt **erweitert** werden: | ||
+ | |||
+ | (**Nur relevanter Ausschnitt**) | ||
+ | <code ini> | ||
+ | ... | ||
+ | // ================================================================================ | ||
+ | // Includes. | ||
+ | // ================================================================================ | ||
+ | |||
+ | key " | ||
+ | algorithm hmac-md5; | ||
+ | secret " | ||
+ | }; | ||
+ | </ | ||
+ | |||
+ | Neu ist hier der Bereich: | ||
+ | <code ini> | ||
+ | key " | ||
+ | algorithm hmac-md5; | ||
+ | secret " | ||
+ | }; | ||
</ | </ | ||
tachtler/dns_isc_bind_centos_7.txt · Zuletzt geändert: 2021/11/14 14:51 von klaus