Re: rndc key for bind 9.3.0. catch-22?

This is a discussion on Re: rndc key for bind 9.3.0. catch-22? within the Bind Users forums, part of the DNS and Related Forums category; >>>>> "Christopher" == Christopher L Barnard <cbar44@tsg.cbot.com> writes: Christopher> ...


Go Back   Usenet Forums > DNS and Related Forums > Bind Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-06-2004
Jim Reid
 
Posts: n/a
Default Re: rndc key for bind 9.3.0. catch-22?

>>>>> "Christopher" == Christopher L Barnard <cbar44@tsg.cbot.com> writes:

Christopher> How do I generate a key for the /etc/rndc.conf file
Christopher> with bind version 9.3.0?

Well the man page for rndc.conf describes two ways of doing this:

[1] rndc-confgen
[2] throw any old rubbish at mmencode or anything else that generates
a valid base-64 encoded string

It's also possible to generate a suitable HMAC-MD5 key with
dnsssec-keygen. You used the wrong argument by insisting on a
ZONE key instead of a HOST key.

That said, there's no need to replace the rndc key whenever the name
server is upgraded. An existing key will work just fine, provided rndc
and named continue to support HMAC-MD5 style authentication. The only
thing that matters with rndc is that the key is kept secret: the
actual key can be anything (within reason). Since the name server and
rndc use the key for mutual authentication, it's important that the
key gets kept away from prying eyes. Unless of course someone thinks
unauthorised management of the name server is a Good Thing.


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:44 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0