DNS TSIG updates need to check ACLs

Kai Blin kai at samba.org
Thu Sep 6 05:27:00 MDT 2012

On 2012-09-06 11:18, Rowland Penny wrote:

Hi Rowland,

> Yes I am using 'net ads join' and no, I provisioned as per the samba 4
> howto
>  /usr/local/samba/sbin/provision \
>    --realm=samdom.example.com --domain=SAMDOM \
>    --adminpass=SOMEPASSWORD --server-role=dc
> Should I be specifying the DNS backend? there is no mention of it in the
> howto, or if there is I missed it.

the smb.conf option about allowing updates is only for the internal dns
server, and you'll be running the BIND_DLZ plugin. So it's not related
to the smb.conf option.


Kai Blin
Worldforge developer http://www.worldforge.org/
Wine developer http://wiki.winehq.org/KaiBlin
Samba team member http://www.samba.org/samba/team/

More information about the samba-technical mailing list