LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-07-2017, 03:44 PM   #1
Latitude
Member
 
Registered: Mar 2009
Posts: 65

Rep: Reputation: 16
DNSSEC Keys and Automatic Zone Resigning


I'm configuring a Master DNS server on RHEL 6.8 with BIND 9.8.2. BIND is being configured to operate chrooted in /var/named/chroot directory, so all the files and directories below are prepended (actually reside) within /var/named/chroot. I have one Master (authoritative) and one Slave server (recursive). I need to configure automatic key signing so the zones data files (/var/named/slaves/db.*) are resigned automatically. Ten (10) zone files are located in the /var/named/slaves/ directory.

Where in the (chrooted) directory tree I should execute the dnssec-keygen steps for the ten zone data files, and where *should* the DNSSEC keys reside in the system? The system I'm deploying currently has the /etc/keys/ directory where my colleague believes I should put the DNSSEC keys, but I don't yet know if DNSSEC will support the keys located in /etc/keys/. If I place the DNSSEC keys inside a file in the etc/keys/ directory separate from the zone data in the /var/named/slaves directory, can I configure DNSSEC automatic zone resigning to function?

I scanned through the BIND 9.8.2 Administrators Reference Manual ftp://ftp.isc.org/isc/bind9/9.8.2/doc/arm/Bv9ARM.pdf and it gives the example below for a zone statement but doesn't declare if zone resigning will function with the key-directory directory as "/etc/keys/dnssec-keys/db.<zone>" or similar:

Code:
zone example.net {
     type master;
     update-policy local;
     file "dynamic/example.net/example.net";
     key-directory "dynamic/example.net'
};
Any help/feedback is greatly appreciated!

Last edited by Latitude; 04-07-2017 at 03:46 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DNSSEC "passes" the test it should fail at dnssec-failed.org Latitude Linux - Security 2 02-02-2017 01:35 PM
dnssec-keygen doesnt generate tsig keys in centos 6.6 running bind 9.9.2 SarahGurung Linux - Security 1 03-19-2015 07:52 AM
Steve Ballmer resigning within the next 12 months H_TeXMeX_H General 9 08-24-2013 05:52 PM
Which zone bind dns work either in forward zone are reverse zone sanjay87 Linux - Server 2 06-05-2012 04:21 AM
Resigning RPMv3 packages in RPM v4 kenneho Linux - Software 5 06-20-2008 10:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration