mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
SOA serial autoincrement is a requirement for major DNS features, e.g. zone transfers or DNSSEC. Enable it by default in named.conf both for new and upgraded installations. Name of the bind-dyndb-ldap option is "serial_autoincrement". From now on, idnsSOAserial attribute also has to be put to replication agreement exclude list as serial will be incremented on each DNS server separately and won't be shared. Exclude list has to be updated both for new replication agreements and the current ones. Minimum number of connections for bind-dyndb-ldap has been rised to 4 connections, the setting will be updated during package upgrade. https://fedorahosted.org/freeipa/ticket/2554
51 lines
1.2 KiB
Plaintext
51 lines
1.2 KiB
Plaintext
options {
|
|
// turns on IPv6 for port 53, IPv4 is on by default for all ifaces
|
|
listen-on-v6 {any;};
|
|
|
|
// Put files that named is allowed to write in the data/ directory:
|
|
directory "/var/named"; // the default
|
|
dump-file "data/cache_dump.db";
|
|
statistics-file "data/named_stats.txt";
|
|
memstatistics-file "data/named_mem_stats.txt";
|
|
|
|
forward first;
|
|
forwarders {$FORWARDERS};
|
|
|
|
// Any host is permitted to issue recursive queries
|
|
allow-recursion { any; };
|
|
|
|
tkey-gssapi-credential "DNS/$FQDN";
|
|
tkey-domain "$REALM";
|
|
};
|
|
|
|
/* If you want to enable debugging, eg. using the 'rndc trace' command,
|
|
* By default, SELinux policy does not allow named to modify the /var/named directory,
|
|
* so put the default debug log file in data/ :
|
|
*/
|
|
logging {
|
|
channel default_debug {
|
|
file "data/named.run";
|
|
severity dynamic;
|
|
};
|
|
};
|
|
|
|
zone "." IN {
|
|
type hint;
|
|
file "named.ca";
|
|
};
|
|
|
|
include "/etc/named.rfc1912.zones";
|
|
|
|
dynamic-db "ipa" {
|
|
library "ldap.so";
|
|
arg "uri ldapi://%2fvar%2frun%2fslapd-$SERVER_ID.socket";
|
|
arg "base cn=dns, $SUFFIX";
|
|
arg "fake_mname $FQDN.";
|
|
arg "auth_method sasl";
|
|
arg "sasl_mech GSSAPI";
|
|
arg "sasl_user DNS/$FQDN";
|
|
arg "zone_refresh $ZONE_REFRESH";
|
|
arg "psearch $PERSISTENT_SEARCH";
|
|
arg "serial_autoincrement $SERIAL_AUTOINCREMENT";
|
|
};
|