[Samba] DNS Zone Transfers are Enabled

Eben Victor eben.victor at gmail.com
Tue Nov 10 08:20:49 UTC 2020


Hi Rowland,

 

Do you know if any progress has been made on this issue?

 

https://gitlab.com/samba-team/samba/merge_requests/169

https://bugzilla.samba.org/show_bug.cgi?id=9634

 

Regards

 

From: Eben Victor <eben.victor at gmail.com>
Date: Monday, 22 July 2019 at 9:47 AM
To: Rowland penny <rpenny at samba.org>
Cc: <samba at lists.samba.org>
Subject: Re: [Samba] DNS Zone Transfers are Enabled

 

Thanks Roland,

You are correct. Our Bind9 DLZ is version 9.9.4.

I'll have to check if I will be able to upgrade to a newer version of Bind, these are on our production servers.

 

On Mon, Jul 22, 2019 at 9:40 AM Rowland penny via samba <samba at lists.samba.org> wrote:

On 22/07/2019 08:24, Eben Victor via samba wrote:
> Hello All,
>
> I hope someone might be able to assist me.
>
> Env:
> RHEL 7
> Samba 4.10
> Bind9 DLZ 9.4
>
> I have tried everything to disable 'DNS Zone Transfers' when using Bind9
> DLZ with Samba ADDC.
>
> I'm using below line , and I have tried different acl's as well, but
> nothing seems to work.
>
> allow-transfer {"none";};
>
> Can someone please advise on how to disable  'DNS Zone Transfers' when
> using Bind9 DLZ with Samba.
>
> Thank you
> Kind regards
>
We have a bug for this: https://bugzilla.samba.org/show_bug.cgi?id=9634

Which has a gitlab page: 
https://gitlab.com/samba-team/samba/merge_requests/169

It looks like there is a fix there, but it looks like your Bind9 version 
(which I take it is actually 9.9.4) will be too old.

Rowland



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba



-- 

Eben Victor



More information about the samba mailing list