Jump to content

BIND TSIG Question.

wjlakner's Photo
Posted Mar 01 2010 04:45 PM
4824 Views

Hello, we are implementing a DNSSEC signing appliance for use by master name servers in our enterprise. We have one existing implementation that uses TSIG between a visible master and secondary name servers at an ISP. The connection to the signing appliance is over a private network and we do not desire to use TSIG to communicate between the master and the signing appliance. My question is whether we can choose what slaves that we want to use TSIG with the master?

Tags:
0 Subscribe


1 Reply

0
  zerosvsones's Photo
Posted Jun 30 2010 02:43 AM

You can even choose which zones will be transferred using TSIG keys, and which not. You can setup ext and int views as well. My "5 cents" on how I use TSIG with RHEL/CentOS in rootjail is here http://itblogspot.ne...-bind-with-tsig