W2K AD and BIND 8

Tim Maestas tmaestas at dnsconsultants.com
Sat Jan 6 01:34:29 UTC 2001





	You need check-names ignore on your domain.com zone, or
	on your _msdcs.domain.com zone if you have created that,
	to allow hostnames with underscores in them.

-Tim

On Fri, 5 Jan 2001, News Account wrote:

> Hi there,
> I have used the recommendations of several sources to get this more or less
> working.  One last hurdle, however.
> I keep getting this error:
> 
> Security Violations
> =-=-=-=-=-=-=-=-=-=
> Jan  5 15:34:47 xxx named[7148]: owner name "gc._msdcs.domain.com" IN
> (primary) is invalid - rejecting
> Jan  5 15:34:47 xxx named[7148]: error processing update packet (REFUSED) id
> 430 from [192.168.1.12].2902
> 
> I saw a BIND FAQ that suggested creating a zone like this:
> zone "_msdcs.example.com" {
>             type master;
>             file "_msdcs.example.db";
>             check-names ignore;
>             allow-update {localnets;};
> };
> 
> Okay, that was done and I am still getting the error above.  So my question
> after all of this is why does gc._msdcs.domain.com get rejected as invalid?
> 
> TIA
> 
> 
> 
> 
> 
> 




More information about the bind-users mailing list