DNS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationDNS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 27th, 2012, 04:50 PM
gahmusic gahmusic is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2012
Posts: 2 gahmusic User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 31 m 7 sec
Reputation Power: 0
BIND DNS domain key corrupt, please help

Hi
I am currently running

BIND 9.8 on Windows 2008 server in a virtual environment online. I administer DNS through a Plesk 10.4 interface which I believe carries out a form of dynamic update to the BIND DNS server itself. I am running it as a Authoritative only Domain name server.
My supplier signed my zone for me and all was fine until I found that the Plesk panel would not allow me to create a SPF and the TXT equivalent in fact I found all it would do was create a TXT version of the SPF entry in the zone.
Anyway long story short I edited the zone file in the root of the BIND install and now my zone domain key sig is being reported as invalid so my question is how do i fix this is there a command to resign the zone simply or do I need to carry out the entire zone signing process again from BIND.

thanks, Gary

Reply With Quote
  #2  
Old February 27th, 2012, 05:24 PM
CaptPikel CaptPikel is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2010
Location: Florida
Posts: 248 CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 3 Days 15 h 26 m 11 sec
Reputation Power: 3
You need to resign the zone after any changes. You don't need to update or change the DS records unless the keys you use to sign with change. I'm not too familiar with Windows but BIND should have the command "nsupdate". This will allow you to modify the zone and it will resign it automatically. It can save you a lot of time. I usually deal with small zones so I prefer to modify the db directly and just resign it. The nsupdate tool makes me nervous. Even though you make successful changes, it doesn't show them to you until you reload anyways.

Reply With Quote
  #3  
Old February 29th, 2012, 11:10 AM
gahmusic gahmusic is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2012
Posts: 2 gahmusic User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 31 m 7 sec
Reputation Power: 0
Thumbs up

Thanks for your responce CaptPikel I apreciate it.
It turned out to be something else altogether that I was getting confused about. It was the domain-key that was corrupt not the DNSSEC key. I administer SmarterMail on server 2008 using a plesk panel 10.4 and it seems that the control for the email server to sign email on the plesk panel was conflicting with the control to sign email in Smartermail. It appears that when you tick sign all outgoing email in Pleask it tries to use a certificate that must be issued by plesk and not the certificate issued by Smartemail itself for the job so it was obviously failing as the keys didn't match, as soon as I turned off "sign all outgoing email" on the Plesk panel it started using the correct certificate and worked.
Not a DNS issue at all I know but I don't like to just leave a thread open and unfinished and I hope this info may help someone else.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationDNS > BIND DNS domain key corrupt, please help

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap