LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS
User Name
Password
CentOS This forum is for the discussion of CentOS Linux. Note: This forum does not have any official participation.

Notices


Reply
  Search this Thread
Old 04-15-2015, 11:10 PM   #1
Sum1
Member
 
Registered: Jul 2007
Distribution: Fedora, CentOS, and would like to get back to Gentoo
Posts: 332

Rep: Reputation: 30
Install Bind with gss-spnego enabled


CentOS 7.1503 installed.
Installed Samba 4 from sernet: Version 4.1.17-SerNet-RedHat-11.el7 (to be configured).

Problem:

The samba wiki Readme First page states, "Some distributions like . . . Red Hat Enterprise Linux (and clones), ship BIND9 packages with disabled GSS-SPNEGO option, which is required for signed DNS updates when using BIND as DNS backend on your Samba DC. This circumstance requires to self compile BIND9."

Is there any way to use a yum command to install Bind9 with gss-spnego enabled?

I'm worried about installing from source and creating future problems when trying to update other CentOS packages that may be affected by the source install of Bind9. Is it safe to obtain a bind9 source tarball for install on an rpm-based CentOS 7 server?

If anyone has installed Bind for use with Samba 4 on CentOS 7, please let me know what worked.

Thanks for your time and patience.
 
Old 04-17-2015, 10:22 AM   #2
Sum1
Member
 
Registered: Jul 2007
Distribution: Fedora, CentOS, and would like to get back to Gentoo
Posts: 332

Original Poster
Rep: Reputation: 30
Based on assistance received on the CentOS mailing list, it appears the Samba Wiki Readme First page needs to be updated since the 7.1503 release.

I installed bind-9.9.4 package from the CentOS repo. --- latest ver. available as of 04/16/2015.

named -V on the installed package produces:
Code:
BIND 9.9.4-RedHat-9.9.4-18.el7_1.1 (Extended Support Version) <id:8f9657aa> built with '--build=x86_64-redhat-linux-gnu' '--host=x86_64-redhat-linux-gnu' '--program-prefix=' '--disable-dependency-tracking' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc'

<<<SNIP>>>

'--with-gssapi=yes' '--disable-isc-spnego'

using OpenSSL version: OpenSSL 1.0.1e 11 Feb 2013
using libxml2 version: 2.9.1
END
Apparently, the problem in the kerberos libraries was resolved and gss now functions in coordination with kerberos without the need for compiling in support for spnego.
"It wasn't the bind package directly but rather an issue with the libkrb5 libraries."

The breakage issue and bug are explained here:
https://bugzilla.redhat.com/show_bug.cgi?id=1087068
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
script for testing gss-api denial of service vulnerability in openssh pk_563 Linux - Security 1 02-01-2012 10:04 AM
script for testing openssh denial of service via gss-api pk_563 Linux - Newbie 2 02-01-2012 10:04 AM
script for testing gss-api denial of service vulnerability in openssh pk_563 Linux - Security 0 02-01-2012 03:14 AM
SELINUX -- Enabled means BIND not working Why so?? anishkumarv Linux - Newbie 3 07-27-2011 06:23 PM
Bind problem: config files are missing after re-install bind 9.5 on Fedora Core 8 elvisious Linux - Software 1 07-15-2008 07:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > CentOS

All times are GMT -5. The time now is 12:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration