Problem upgranding from 9.4.1 to 9.4.1-P1

c0re dumped ez.c0re at gmail.com
Thu Jul 26 20:05:37 UTC 2007


Solved.

It seems that views doesnt work anymore on 9.4.1-P1 version.

Using 'allow-query' and 'allow-recursion' options works anyway.

TIA.

2007/7/26, c0re dumped <ez.c0re at gmail.com>:
> Hello guys,
>
> I've upgraded my BIND version from 9.4.1 to 9.4.1-P1.
>
> I did it via FreeBSD ports, and all upgrading process worked fine.
> However when I started my brand new named daemon and my clients tryied
> to query some host names on a zone which  this nameserver is
> authoritative, bind returned an error:
>
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: UDP request
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside:
> using view 'inside'
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside:
> request is not signed
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view
> inside:recursion not available
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside: query
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside:
> ns_client_attach: ref = 1
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside:
> query (cache) 'www.XYZ..br/A/IN' denied
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside: error
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside: send
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside: sendto
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside: senddone
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view inside: next
> 26-Jul-2007 13:54:23.014 client 200.181.67.71#57623: view
> inside:ns_client_detach: ref = 0
> 26-Jul-2007 13:54:23.014 client 200.XXX.XXX.XXX#57623: view interna: endrequest
> 26-Jul-2007 13:54:23.014 client @0x829d000: udprecv
>
> This server is athoritative to XYZ.br zone.
>
> The inside view is the one which allows recursion to my LAN clients.
>
> The views were correctly configured since they were working before
> (version 9.4.1).
>
> DNSSEC is enabled on this server.
>
> What's the problem ?
>
> TIA
>
>
> --
> http://www.webcrunchers.com/crunch/
>


-- 
No stupid signatures here.

http://www.webcrunchers.com/crunch/



More information about the bind-users mailing list