session.key and managed-keys

Emil Natan shlyoko at
Sun Jul 10 09:30:47 UTC 2011


I have few boxes running BIND 9.7.3-P3. I do not use DNSSEC (for now) and
dynamic updates (at all) and I have them explicitly disabled in named.conf
(dnssec-enable   no; dnssec-validation no; allow-update    { none; };) but I
see named still searching for managed-keys.bind file and trying to create
session.key file. In the general case it fails with file not found and
permission denied which I know how to correct. My question is why BIND is
forced to create files and especially the session.key? Is there a way to
change that behavior?

