Re: BIND rejecting key to update a zone

2018-06-11 Thread Michał Kępień
> Hi Michal, thanks for the reply and sorry for the delay on my end. > > I've started a fresh install here and started over and still having the > same issue, even when I crank the debug trace up to 5, I'm not seeing > anything additional in the logs: > > 08-Jun-2018 14:56:50.281 update-security:

Re: BIND rejecting key to update a zone

2018-06-10 Thread Matthew Pounsett
On 8 June 2018 at 11:01, Mark E. Jeftovic wrote: > I've started a fresh install here and started over and still having the > same issue, even when I crank the debug trace up to 5, I'm not seeing > anything additional in the logs: > > Another long shot... any chance there is an overlapping ACL in

Re: BIND rejecting key to update a zone

2018-06-08 Thread Mark E. Jeftovic
Hi Michal, thanks for the reply and sorry for the delay on my end. I've started a fresh install here and started over and still having the same issue, even when I crank the debug trace up to 5, I'm not seeing anything additional in the logs: 08-Jun-2018 14:56:50.281 update-security: info: client

Re: BIND rejecting key to update a zone

2018-06-04 Thread Michał Kępień
Hi Mark, > Jun  1 20:19:34 rpz0 named[30999]: client 127.0.0.1#64585/key > dns-update: signer "dns-update" denied > Jun  1 20:19:34 rpz0 named[30999]: client 127.0.0.1#64585/key > dns-update: update 'test.rpz/IN' denied > > What am I missing here?   Interesting, you do not seem to be missing any

BIND rejecting key to update a zone

2018-06-02 Thread Mark E. Jeftovic
I'm sure this is something obvious I'm overlooking while I futz around with setting up an RPZ (9.10.3-P4-Debian) BIND config has: key "dns-update" {     algorithm HMAC-SHA512;     secret "KEYREDACTED=="; }; and zone "test.rpz." {     type master;     allow-transfer { key "dns-ts