BIND9 dyndb

Andrew Bartlett abartlet at samba.org
Fri Jan 30 22:13:33 UTC 2026


On Sat, 2026-01-31 at 11:08 +1300, Douglas Bagnall via samba-technical
wrote:
> On 30/01/2026 10:32 pm, Andrew Bartlett wrote:
> > On Fri, 2026-01-30 at 06:50 +0200, Alexander Bokovoy via samba-technical wrote:
> 
> > > bind-dyndb-ldap is hosted at https://pagure.io/bind-dyndb-ldap <https://pagure.io/bind-dyndb-ldap>. Github
> > > mirror was used for some CI experiments. Pagure itself is going to be
> > > decomissioned so recently we started moving from it to codeberg:
> > > https://codeberg.org/freeipa/bind-dyndb-ldap <https://codeberg.org/freeipa/bind-dyndb-ldap>. This move is not complete
> > > yet.
> 
> I can't work out how I managed to miss that!
> 
> > I don't think that ACL model is going to work for Samba, so I wonder if we just sunset BIND9 support with DLZ?  
> > 
> > The internal server has proven itself pretty well over the years, and we can continue to recommend folks put a real DNS
> > server in front of it with a conditional forward to Samba.
> 
> Yes, though DNS does like to present new subtleties (this week:
> https://bugzilla.samba.org/show_bug.cgi?id=15988).

Yeah,  was long opposed to us taking on this protocol, but the BIND9
DLZ has had its own issues.

> I will try to find out if ISC have a timeline.

We should also tell them we don't really have an alternative, they may
not know we can't 'just' use the new interface.

Andrew Bartlett

-- 
Andrew Bartlett (he/him) https://samba.org/~abartlet/
Samba Team Member (since 2001) https://samba.org



More information about the samba-technical mailing list