Bug 202012 - rndc.conf change breaks working bind config
rndc.conf change breaks working bind config
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: bind (Show other bugs)
All Linux
medium Severity high
: ---
: ---
Assigned To: Martin Stransky
Ben Levenson
: 208237 (view as bug list)
Depends On:
Blocks: 203070
  Show dependency treegraph
Reported: 2006-08-10 07:58 EDT by Tom G. Christensen
Modified: 2007-11-16 20:14 EST (History)
1 user (show)

See Also:
Fixed In Version: RHSA-2007-0044
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-02-06 13:46:39 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
proposed patch (1.74 KB, patch)
2006-08-18 06:05 EDT, Martin Stransky
no flags Details | Diff

  None (edit)
Description Tom G. Christensen 2006-08-10 07:58:59 EDT
Description of problem:
A custom named.conf contains include "/etc/rndc.key"
rndc.conf prior to the U8 update also contained include "/etc/rndc.key"
The U8 update changes rndc.conf to include a hardcoded key statement instead of
This results in rndc nolonger being able to authenticate itself to named.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Existing named.conf must contain include "/etc/rndc.key"
2. Existing /etc/rndc.conf must be unmodified (so it will be updated during the
3. Upgrade from 9.2.4-7_EL3 to 9.2.4-14_EL3
4. service named status
Actual results:
rndc: connection to remote host closed
This may indicate that the remote server is using an older version of 
the command protocol, this host is not authorized to connect,
or the key is invalid.

Expected results:
rndc status output

Additional info:
Checking a clean install of bind-9.2.4_14_EL3 on a pristine machine that's never
seen bind before also produces a non-working config. That is one where the
default named.conf includes /etc/rndc.key but /etc/rndc.conf hardcodes a
different key.
Comment 1 Martin Stransky 2006-08-10 08:10:30 EDT
Thanks for the report.
Comment 2 Tuomo Soini 2006-08-16 03:19:19 EDT
from bind.spec file:

#%patch1 -p1 -b .key
# This patch now in 'bind-9.2.4-5.backport.patch'

This might be true but there is no bind-9.2.4-5.backport.patch in spec.

There is: Patch9: bind-9.2.4-5_backport.patch

which doesn't include necessary bits for rndc.conf patching.

Enabling Patch1 again fixes this problem.
Comment 3 Tuomo Soini 2006-08-16 03:22:53 EDT
Oh. and this same bug affects rhel-4U4 users.
Comment 4 Martin Stransky 2006-08-18 06:05:19 EDT
Created attachment 134430 [details]
proposed patch

bind-9.2.1-key.patch really fixes this problem, unfortunately it isn't included

in 4.4
Comment 5 Martin Stransky 2006-10-04 08:39:22 EDT
*** Bug 208237 has been marked as a duplicate of this bug. ***
Comment 8 Red Hat Bugzilla 2007-02-06 13:46:39 EST
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.


Note You need to log in before you can comment on or make changes to this bug.