• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

bind package 9.16_12 reads from /cf/named, but changes in the GUI are written to /var/etc/named

Scheduled Pinned Locked Moved pfSense Packages
20 Posts 8 Posters 3.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tbahn @riso
    last edited by Mar 9, 2022, 10:52 AM

    @riso I had to check this "off-time": Yes, it still runs after reboot, but it takes minutes for the named service to start.

    I couldn't find anything in the logs, but I assume, it could be the same attempts and timeouts as when I updated the package.

    R 1 Reply Last reply Mar 9, 2022, 1:14 PM Reply Quote 0
    • T
      tbahn @BlankMan
      last edited by tbahn Mar 9, 2022, 11:51 AM Mar 9, 2022, 11:50 AM

      @blankman Where you select "All": the field is labeled "Backup Area". :-)

      I'm no specialist by any means for "bind on pfSense", more a self-educated practitioner. Perhaps someone with more systematic knowledge can aid you further.

      I exclusively used the Bind GUI to setup bind with ACLs, views and some zones. So, it's doable.

      As far as I understand now, this configuration is stored elsewhere and the configuration files under /cf/named are generated, when you save the zones.

      One thing I discovered: You seem to have to save twice: one time in the zone itself, one time in the list of zones. At least, only with this second save (in the table of zones page), the changes are propagated to other DNS servers with slave copies of the zones.

      1 Reply Last reply Reply Quote 0
      • V
        viktor_g Netgate
        last edited by Mar 9, 2022, 1:11 PM

        the fix will be in the next BIND version (soon):
        https://redmine.pfsense.org/issues/12869#note-7

        T 1 Reply Last reply Mar 9, 2022, 1:59 PM Reply Quote 2
        • R
          riso @tbahn
          last edited by Mar 9, 2022, 1:14 PM

          @tbahn thank you
          in my case, this workaround did not survive the server restart, I had to do it again
          @viktor_g thanks for the quick fix :)

          1 Reply Last reply Reply Quote 0
          • T
            tbahn @viktor_g
            last edited by Mar 9, 2022, 1:59 PM

            @viktor_g Thank you for fixing and notifying us.

            1 Reply Last reply Reply Quote 0
            • J
              jaltman
              last edited by Mar 9, 2022, 7:04 PM

              I can confirm that 9.16_13 fixes the problem.
              Thank you.

              1 Reply Last reply Reply Quote 0
              • D
                dld_r00f
                last edited by dld_r00f Mar 27, 2022, 8:04 AM Mar 27, 2022, 7:49 AM

                I have inverted situation with BIND.
                pfSense 2.6.0 with BIND 9.16_12 (10 zones with DNSSEC Inline Signing and Backup Keys flags) work as usual.
                After upgrading to 9.16_13 it stopped signing DNSSEC. New BIND try to find keys at /var/etc/named/etc/namedb/keys istead of /cf/named/etc/namedb/keys.

                Stupid situation: I have a working backup with a previous package version. But this is completely useless with the new version of the package. So I can’t just reinstall the system, it won’t work, because the current version of the package is broken.

                And insanely long BIND loading of course (link).

                D B 2 Replies Last reply Mar 27, 2022, 7:58 AM Reply Quote 0
                • D
                  dld_r00f @dld_r00f
                  last edited by Mar 27, 2022, 7:58 AM

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • B
                    bingo600 @dld_r00f
                    last edited by Mar 27, 2022, 11:46 AM

                    @dld_r00f

                    Wouldn't a "quick & ugly" hack be to make a symlink of the existing file to the "wanted file" ??

                    ln -s <existing> <wanted>

                    If you find my answer useful - Please give the post a 👍 - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    D 1 Reply Last reply Mar 27, 2022, 2:06 PM Reply Quote 0
                    • D
                      dld_r00f @bingo600
                      last edited by Mar 27, 2022, 2:06 PM

                      @bingo600
                      If you know the problem, then there are many ways to solve it :)
                      I just copied all my dnssec keys to /var/etc/named/etc/namedb/keys. I think the symlink worked too.
                      In my case, I spent about 4 hours to figure out what was causing the problem.

                      1 Reply Last reply Reply Quote 0
                      • V
                        viktor_g Netgate
                        last edited by Mar 30, 2022, 3:21 PM

                        Redmine issue created:
                        https://redmine.pfsense.org/issues/13002

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          [[user:consent.lead]]
                          [[user:consent.not_received]]