Project

General

Profile

Scénario #31999

Revoir les options du template /etc/bind/named.conf.options Samba DLZ

Added by Gilles Grandgérard 6 months ago. Updated 5 months ago.

Status:
Terminé (Sprint)
Priority:
Normal
Assigned To:
Category:
-
Start date:
04/06/2021
Due date:
04/23/2021
% Done:

100%

Story points:
1.0
Remaining (hours):
0.00 hour
Velocity based estimate:
Release:
Release relationship:
Auto

Description

Vérifier le contenu du template.

cf.: https://wiki.samba.org/index.php/Setting_up_a_BIND_DNS_Server

Voir:
- auth-nxdomain yes
- notify no;
- empty-zones-enable no;
- dnssec-enable ?
- dnssec-lookaside no;
- listen-on-v6 { any; }; // on n'a pas de IPv6 !

* which nsupdate
/usr/bin/nsupdate
nsupdate 9.16.1-Ubuntu
===============================================
* named-checkconf
/etc/bind/named.conf.options:21: option 'dnssec-enable' is obsolete and should be removed

Voir : https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/active-directory-replication-event-id-2087


Subtasks

Tâche #32204: Revoir les options BindFerméEmmanuel GARETTE


Related issues

Related to Distribution EOLE - Tâche #32083: Valider le scénario Revoir les options du template /etc/bind/named.conf.options Samba DLZ Fermé 04/08/2021

History

#1 Updated by Gilles Grandgérard 6 months ago

  • Description updated (diff)

#2 Updated by Gilles Grandgérard 6 months ago

  • Due date set to 04/23/2021
  • Target version set to sprint 2021 14-16 Equipe MENSR
  • Start date set to 04/06/2021
  • Story points set to 1.0

#3 Updated by Gilles Grandgérard 6 months ago

  • Target version changed from sprint 2021 14-16 Equipe MENSR to Prestation Cadoles MEN 2021 14-16

#4 Updated by Emmanuel GARETTE 6 months ago

  • Assigned To set to Philippe Caseiro

#5 Updated by Joël Cuissinat 5 months ago

  • Related to Tâche #32083: Valider le scénario Revoir les options du template /etc/bind/named.conf.options Samba DLZ added

#6 Updated by Emmanuel GARETTE 5 months ago

Documentation :

auth-nxdomain
    If yes, then the AA bit is always set on NXDOMAIN responses, even if the server is not actually authoritative. The default is no.
notify

    If set to yes (the default), DNS NOTIFY messages are sent when a zone the server is authoritative for changes; see Notify. The messages are sent to the servers listed in the zone’s NS records (except the primary server identified in the SOA MNAME field), and to any servers listed in the also-notify option.

    If set to primary-only (or the older keyword master-only), notifies are only sent for primary zones. If set to explicit, notifies are sent only to servers explicitly listed using also-notify. If set to no, no notifies are sent.

    The notify option may also be specified in the zone statement, in which case it overrides the options notify statement. It would only be necessary to turn off this option if it caused secondary zones to crash.
empty-zones-enable
    This enables or disables all empty zones. By default, they are enabled.

#7 Updated by Emmanuel GARETTE 5 months ago

  • Status changed from Nouveau to Résolu

#8 Updated by Daniel Dehennin 5 months ago

  • Release set to EOLE 2.8.1

#9 Updated by Daniel Dehennin 5 months ago

  • Status changed from Résolu to Terminé (Sprint)

Also available in: Atom PDF