Question about managed-keys-zone

2016-04-08 Thread Bhangui, Sandeep - BLS CTR
Hi I am trying to do a simple proof of concept test for DNSSEC signing for our organization. We are an agency under DOL and the plan is to use a DNSSECsigner appliance hosted at DOL to sign the zones so that we do not have to do DNSSEC key management. So basically the configuration is from ou

Re: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > '--enable-newstats' '--with-libxml2' '--enable-fullreport' 'CFLAGS=-O2 Unrelated to your problem, but the --enable-newstats configure switch is not used for BIND 9.10. > 1. Cannot seem to start named and it seems that it is looking for s

RE: Question about managed-keys-zone

2016-04-08 Thread Bhangui, Sandeep - BLS CTR
Thanks Jeremy Logging section from named.conf logging { channel "named-log" { file "/usr/local/named-jail9.10.3P4/var/adm/named.log" versions 3 size 30m; severity info; print-time yes; print-category yes; print-severity yes; };

RE: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > I know it using rndc is a good practice but is there an option to > specify in named.conf to disable it? It is disabled by default because there is no complete command channel configuration in the first place, but this will make it so it d

RE: Question about managed-keys-zone

2016-04-08 Thread Jeremy C. Reed
On Fri, 8 Apr 2016, Bhangui, Sandeep - BLS CTR wrote: > Thanks Jeremy > > > Logging section from named.conf > > logging { > channel "named-log" { > file "/usr/local/named-jail9.10.3P4/var/adm/named.log" > versions 3 size 30m; ... > category "general" { "named-

Re: Question about managed-keys-zone

2016-04-08 Thread Bjoern Kahl
Am 08.04.16 um 16:11 schrieb Bhangui, Sandeep - BLS CTR: > Thanks Jeremy > > > Logging section from named.conf > > logging { > channel "named-log" { > file "/usr/local/named-jail9.10.3P4/var/adm/named.log" > versions 3 size 30m; That is wrong, if your named runs in a c