Uploaded image for project: 'OpenDNSSEC'
  1. OpenDNSSEC
  2. OPENDNSSEC-159

Unable to do TSIG against BIND

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Won't Fix
    • Affects Version/s: None
    • Fix Version/s: 1.4.0b2
    • Component/s: Signer
    • Labels:

      Description

      I have tried hmac-md5, hmac-sha1, and hmac-sha256 against a BIND name server. All of them are failing with this message:

      Nov 29 08:49:41 ubuntu named[28931]: client 127.0.0.1#35001: transfer of 'bellgrim.se/IN': AXFR started: TSIG bellgrim.se
      Nov 29 08:49:41 ubuntu ods-signerd: [xfrd] unable to process tsig: xfr zone bellgrim.se from 127.0.0.1 has bad tsig signature
      Nov 29 08:49:41 ubuntu ods-signerd: [xfrd] dropped packet: zone bellgrim.se received bad tsig from 127.0.0.1
      Nov 29 08:49:41 ubuntu named[28931]: client 127.0.0.1#35000: transfer of 'bellgrim.se/IN': AXFR ended

        Attachments

          Activity

            People

            Assignee:
            matthijs Matthijs Mekking
            Reporter:
            rickard Rickard Bellgrim
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: