patches to make bind9 with TKEY/GSS updates easier to configure

Michael Graff mgraff at isc.org
Thu Dec 2 21:26:31 UTC 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 2010-12-02 2:46 PM, tridge at samba.org wrote:
> Hi Michael,
> 
> ok, this is a good opportunity for us to improve the debug messages
> when tkey-gssapi fails :-)

Great!  More usability fixes.  Want a list of other places to touch?  :)

> My first guess is that the tests are still dependent on something in
> /etc/krb5.conf. If you could send me your krb5.conf, and also send me
> the test output with "-L 3 -D -d" added to the $NSUPDATE call in
> bin/tests/system/tsiggss/tests.sh. A copy of
> bin/tests/system/tsiggss/ns1/named.run after the failure might also
> help.

http://www.flame.org/~explorer/rt22629/krb5.conf
http://www.flame.org/~explorer/rt22629/named.run

> I'll also build and test it on a FreeBSD machine and see if I can
> reproduce the failure. I don't have a NetBSD machine handy, but I can
> install it in a VM if FreeBSD doesn't reproduce the problem.

I can give you an account on my box too if you like.

> I assume you were testing with current CVS plus my patches? Do you
> have MIT or Heimdal kerberos libs installed?

Yep, that's it.  I am using the standard Kerberos, which is NetBSD's
version of heimdal.

- --Michael
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkz4DwcACgkQLdqv0r6eD6YQlQCfWBwLG2X+PeSi3iJyCZ9KIJ2L
8CMAn2IeK5VqfaoFnxBgVtx3xrVyorC1
=1ojk
-----END PGP SIGNATURE-----



More information about the bind-workers mailing list