Re: Unix client and secure DNS updates



"Herofish" <Herofish@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:2D56124E-034D-42C5-9338-E5DB1D4BA46E@xxxxxxxxxxxxxxxx
Here's my environment: Windows 2000 AD integrated DNS, with secure updates
only. I have a couple of Solaris 9 hosts which need to update their DNS
entries. How to do this dynamic update from a Solaris host?

You (probably) don't.

Since you require secure updates (a good thing),
the registering machine must be authenticated.

[There is a (at least theoretical) possibility to authenticate
with Samba (but I know little about that.) ]


Here is a good article which explains how Windows 2000 DNS secure updates
happen, and that it is TSIG compliant, etc.

http://www.microsoft.com/technet/prodtechnol/windows2000serv/plan/w2kdns2.mspx

According to my understanding, theoretically it should be possible for the
Unix client to authenticate to AD using Kerberos, then perform a DNS
update.

At least theoretically BUT there are two easier ways...

Is this true? More importantly, how exactly is this implemented on the
Unix
host??

Research some (e.g., Samba) AD authenticating client OR
try it through direct Kerberos V5 authentication (which
probably isn't worth the trouble.)

Two easier ways:

1) Static machines -- register them manually.

2) DHCP clients -- let the DHCP server do it.



--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


Thanks.



.



Relevant Pages

  • Re: Web Site Mystery
    ... host our own web site at this location. ... So in our DNS setup, there is a pointer to the ip address of the ... Run an ipconfig /all on your server and you'll see the ... www.europacrown.com don't work from our corporate network. ...
    (microsoft.public.windows.server.general)
  • Windows cannot connect to the domain & Event ID 3210 5722 - Lots of Details!
    ... domain controller for domain DOMAIN, ... This inability to authenticate might be caused by ... password for this computer account is not recognized. ... DNS addresses and there is only one network card in the computer. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Underscore in IIS 6 Host Header definition
    ... The RFC that you referenced does not define the standard for the DNS ... An underscore is not valid in a host. ...
    (microsoft.public.inetserver.iis)
  • Re: Retardedness
    ... have not written any reverse DNS code. ... Begins an asynchronous request for IPHostEntry ... information about the specified DNS host name. ... GetHostAddresses: Returns the Internet Protocol addresses for ...
    (alt.os.windows-xp)
  • Re: Unable to sentd email to certain domains...
    ... Think of reverse DNS this way. ... When you ping a host by name ... they often don't have a reverse DNS set up. ... provider should be able to set this up no problem. ...
    (microsoft.public.exchange.admin)