[Opendnssec-user] OpenDNSSEC in a hidden master setup
mefystofel at gmail.com
Tue Aug 26 08:08:40 UTC 2014
I'm sorry for a dumb question (I've just started working with OpenDNSSEC),
but in the following setup with three servers involved:
[Hidden master] <---> [OpenDNSSEC] <---> [Public slave]
do I need to run "traditional" DNS server on the OpenDNSSEC box to deal
with signed zones transfers to the slave?
I think I have a problem with getting the zone from the hidden master as
soon as I increase the serial.
All three servers are running FreeBSD 10-STABLE, with the latest NSD
(4.0.3) installed on the hidden master and the slave. OpenDNSSEC box
(version 1.4.6) doesn't have NSD installed.
My plan is to feed plain zones to OpenDNSSEC, sign them and transfer to the
Here is the snippet from nsd.conf from the hidden master (192.168.157.47 is
the IP of OpenDNSSEC):
notify: 192.168.157.47 tsig.sha256.signed
provide-xfr: 192.168.157.47 tsig.sha256.signed
addns.xml (192.168.157.46 is the hidden master and 192.168.163.86 is the
conf.xml is the default one, with one modification:
kasp.xml is the default one (I'm using default policy), with one change:
If I increase the serial, reload the zone on hidden master and do
ods-control stop/start on the OpenDNSSEC I see that the signed zone was
successfully transferred to the slave. Here is the log from the slave:
 nsd: info: notify for domain.org. from 192.168.157.47
 nsd: info: xfrd: zone domain.org committed "received
update to serial 2014082512 at 2014-08-25T21:20:35 from 192.168.157.47 TSIG
verified with key tsig.sha256.signed"
 nsd: info: rehash of zone domain.org. with parameters 1
0 5 e99189ffbae225cf
 nsd: info: zone domain.org. received update to serial
2014082512 at 2014-08-25T21:20:35 from 192.168.157.47 TSIG verified with
key tsig.sha256.signed of 3566 bytes in 0.000139 seconds
 nsd: info: Zone domain.org serial 2014082509 is updated
But if I just increase the serial and reload the zone on hidden master, I
get the following in the logs of OpenDNSSEC:
Aug 26 09:20:40 ns-sign ods-signerd: [xfrd] zone domain.org request
udp/ixfr=2014082511 to 192.168.157.46
and nothing happens after that. I see no errors on the hidden master or
Any hints would be greatly appreciated.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Opendnssec-user