How to get DNS replication working properly?

Kai Blin kai at
Mon Jun 25 02:02:14 MDT 2012

On 2012-06-24 13:01, Andrew Bartlett wrote:

Hi Andrew,

> The reason that the secondary DC isn't enrolled in DNS is that the
> internal DNS server does not support dynamic updates (yet, Kai is still
> working on it). 

That's almost correct. The internal DNS server does not support
cryptographically signed updates yet, and thus updates are turned off by

If you don't need that on your network, you can allow unsigned updates
and things should just work (tm). With all the implications of allowing
clients to mess with DNS records, of course.

Still, it's not as if dns updates didn't work at all. I wish people
would stop confusing that.


Kai Blin
Worldforge developer
Wine developer
Samba team member

More information about the samba-technical mailing list