Disallowing DDNS in BIND 9.2.1

Barry Finkel b19141 at achilles.ctd.anl.gov
Wed Jun 26 12:40:56 UTC 2002


I upgraded from 8.2.5-REL to 9.2.1 on my master DNS yesterday, and I
am seeing messages like this:

     Jun 25 20:09:59 dns0.anl.gov named[21131]: client
       146.137.226.10#3004: updating zone 'md.anl.gov/IN':
       update failed: 'RRset exists (value dependent)'
       prerequisite not satisfied (NXRRSET)

With BIND 8.2.5-REL the messages were like this one:

     Jun 23 04:07:29 puck.ctd.anl.gov named[4598]:
       denied update from [146.137.226.10].3937 for "md.anl.gov" IN

The 8.2.5 message clearly states that I denied the update; I do not
allow DDNS on the master.  The 9.2.1 message implies that I would have
allowed the update if the pre-req condition(s) had been satisfied.

Is this the case?  I made no changes to my named.conf file for 9.2.1
except for adding the "key" and "controls" statement.  I have no

     allow-update

line in that file.
----------------------------------------------------------------------
Barry S. Finkel
Electronics and Computing Technologies Division
Argonne National Laboratory          Phone:    +1 (630) 252-7277
9700 South Cass Avenue               Facsimile:+1 (630) 252-4601
Building 222, Room D209              Internet: BSFinkel at anl.gov
Argonne, IL   60439-4828             IBMMAIL:  I1004994



More information about the bind-users mailing list