RE: GSS-TSIG update-policy clarification

2018-03-23 Thread Darcy Kevin (FCA)
. - Kevin -Original Message- From: bind-users [mailto:bind-users-boun...@lists.isc.org] On Behalf Of Nicholas Miller Sent: Friday, March 23, 2018 4:16 PM To: bind-users@lists.isc.org Subject: Re: GSS-TSIG update-policy clarification Thats well and good for an organization that controls

Re: GSS-TSIG update-policy clarification

2018-03-23 Thread Nicholas Miller
Thats well and good for an organization that controls ALL of the end points. In a university that isn’t possible. _ Nicholas Miller, OIT, University of Colorado at Boulder > On Mar 23, 2018, at 2:04 PM, Mark Andrews wrote: > > If you don’

Re: GSS-TSIG update-policy clarification

2018-03-23 Thread Mark Andrews
If you don’t want 6to4 addresses stop the machine configuring them. Not everything should be done at the DNS level. -- Mark Andrews > On 24 Mar 2018, at 01:07, Nicholas Miller > wrote: > > As a followup, is there a way to stop Windows systems from adding their > 6-to-4 record? I see li

Re: GSS-TSIG update-policy clarification

2018-03-23 Thread Nicholas Miller
As a followup, is there a way to stop Windows systems from adding their 6-to-4 record? I see little point in adding these records to a domain. _ Nicholas Miller, OIT, University of Colorado at Boulder > On Mar 22, 2018, at 12:13 PM, Mar

Re: GSS-TSIG update-policy clarification

2018-03-22 Thread Mark Andrews
This was noted in the release notes and in CHANGES. 4885. [security] update-policy rules that otherwise ignore the name field now require that it be set to "." to ensure that any type list present is properly interpreted.

GSS-TSIG update-policy clarification

2018-03-22 Thread Nicholas Miller
With the latest update to bind our named.conf started reporting errors. I have figured it out but wanted to get clarification about the syntax. We had been using: deny DOMAIN.EDU krb5-subdomain DOMAIN.EDU CNAME MX SRV TXT; We are now using: deny DOMAIN.EDU krb5-subdomain . CNAM