[Samba] DNS Zone Transfers are Enabled

Eben Victor eben.victor at gmail.com
Tue Nov 10 08:20:49 UTC 2020

Hi Rowland,


Do you know if any progress has been made on this issue?







From: Eben Victor <eben.victor at gmail.com>
Date: Monday, 22 July 2019 at 9:47 AM
To: Rowland penny <rpenny at samba.org>
Cc: <samba at lists.samba.org>
Subject: Re: [Samba] DNS Zone Transfers are Enabled


Thanks Roland,

You are correct. Our Bind9 DLZ is version 9.9.4.

I'll have to check if I will be able to upgrade to a newer version of Bind, these are on our production servers.


On Mon, Jul 22, 2019 at 9:40 AM Rowland penny via samba <samba at lists.samba.org> wrote:

On 22/07/2019 08:24, Eben Victor via samba wrote:
> Hello All,
> I hope someone might be able to assist me.
> Env:
> RHEL 7
> Samba 4.10
> Bind9 DLZ 9.4
> I have tried everything to disable 'DNS Zone Transfers' when using Bind9
> DLZ with Samba ADDC.
> I'm using below line , and I have tried different acl's as well, but
> nothing seems to work.
> allow-transfer {"none";};
> Can someone please advise on how to disable  'DNS Zone Transfers' when
> using Bind9 DLZ with Samba.
> Thank you
> Kind regards
We have a bug for this: https://bugzilla.samba.org/show_bug.cgi?id=9634

Which has a gitlab page: 

It looks like there is a fix there, but it looks like your Bind9 version 
(which I take it is actually 9.9.4) will be too old.


To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


Eben Victor

More information about the samba mailing list