All the versions of this article: [English] [français]
Le 16/4/2007, 00:00 named zone sonntag.eu.org: refused notify from non-master
The trick & tips of the moment : we recently upgrade the secondary dns server of Lautre.Net. We are now using bind 9.3.
We has the following error message for all the hosted domains :
Apr 16 00:34:38 ns2 named[4586]: client 212.85.137.31#1293: received notify for zone 'sonntag.eu.org'
Apr 16 00:34:38 ns2 named[4586]: zone taous.net/IN: refused notify from non-master: 212.85.137.31#1293The server ip is 212.85.137.31. The problem is that when you start bind, it send a "notfiy" message to its own daemon to check if all the hosted zones are up-to-date. But since there is no authorization, it denies himself this request !
This can be solve easily by adding an explicit authorization in bind options (usually in named.conf ) as follow :
(since we are on debian etch, the options are in /etc/bind/named.conf.options)
options {
auth-nxdomain no; # conform to RFC1035
listen-on-v6 { any; };
allow-query { any; }; // This is the default
recursion no; // Do not provide recursive service
<font color="red">
// We add a manual authorization for bind own ip
allow-notify { 212.85.137.31; };
</font>
}Then, restart bind with /etc/init.d/bind9 restart and you’ll see the good news :
Apr 16 00:43:13 ns2 named[4973]: zone sonntag.eu.org/IN: sending notifies (serial 2004110621)
Apr 16 00:43:13 ns2 named[4973]: client 212.85.137.31#1295: received notify for zone 'sonntag.eu.org'
Apr 16 00:43:13 ns2 named[4973]: zone sonntag.eu.org/IN: notify from 212.85.137.31#1295: zone is up to dateBind sent a notify message to himself, received it and sent a SOA request to the master to check the zone serial number, to know if it has a up-to-date zone file...
Tags
[Geekland] - [Logiciels Libres] -
Who's there?
Welcome on Benjamin Sonntag's blog, web entrepreneur, Linux expert and free-software-savvy half-geek.
Here you will find geek tuff, tricks and tips and friendly ads, personal histories and a bunch of politics ...
On the same topic ...
- le 12 May 2010Nice style for forced form fields
- le 20 July 2010Arduino driver for Sure0832 led panel
- le 20 JanuaryDNS & AlternC - How does it work?
Chez Aline et ses Animfolies'
- 4 February – Encore 2 pages…
- 29 January – Ma page préférée
- 28 January – Encore 2 nouvelles pages …
- 26 January – 2 nouvelles pages
- 22 January – ABCdaire
In the Octopuce boat ...
- 17 November 2011 – Octopuce SARL recherche un développeur PHP/MySQL
- 23 October 2011 – Octopuce à Metz (Libre et Entreprises)
- 23 October 2011 – Octopuce à Metz (Libre et Entreprises)
- 19 January 2011 – Comment utiliser les hooks de GIT pour mettre à jour automatiquement un site de développement
- 18 January 2011 – Hébergement de dépôts GIT sur un serveur via Gitosis
La Quadrature du Net
- 2 February – ACTA : Le Commissaire De Gucht ment au Parlement européen
- 30 January – Démontage des mensonges de la Commission européenne sur ACTA
- 26 January – ACTA signé par l'UE. Ensemble, nous devons le vaincre !
- 23 January – Après SOPA et PIPA aux États-Unis, ACTA arrive au Parlement européen
- 20 January – MegaUpload : l'industrie du copyright en guerre contre les créatures qu'elle a enfantées
Old stuff ...
- 7 décembre 2009 – J’achète beaucoup de couteaux, je suis un tueur en série
- 8 janvier 2010 – Le Trou du Bon Chat : une perle chez Laurent Chemla
- 25 juin 2010 – Apple : service push notification HS
- 29 décembre 2009 – 26c3. Day 2 : Un panneau de LED sur Microcontrolleur !
- 25 January 2010 – Optical Fiber in France: How it work? Free vs Orange





