patches to make bind9 with TKEY/GSS updates easier to configure

Michael Graff mgraff at
Thu Dec 2 21:26:31 UTC 2010

Hash: SHA1

On 2010-12-02 2:46 PM, tridge at wrote:
> Hi Michael,
> ok, this is a good opportunity for us to improve the debug messages
> when tkey-gssapi fails :-)

Great!  More usability fixes.  Want a list of other places to touch?  :)

> My first guess is that the tests are still dependent on something in
> /etc/krb5.conf. If you could send me your krb5.conf, and also send me
> the test output with "-L 3 -D -d" added to the $NSUPDATE call in
> bin/tests/system/tsiggss/ A copy of
> bin/tests/system/tsiggss/ns1/ after the failure might also
> help.

> I'll also build and test it on a FreeBSD machine and see if I can
> reproduce the failure. I don't have a NetBSD machine handy, but I can
> install it in a VM if FreeBSD doesn't reproduce the problem.

I can give you an account on my box too if you like.

> I assume you were testing with current CVS plus my patches? Do you
> have MIT or Heimdal kerberos libs installed?

Yep, that's it.  I am using the standard Kerberos, which is NetBSD's
version of heimdal.

- --Michael
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla -


More information about the bind-workers mailing list