[Pdns-users] selected AXFR

Derrik Pates dpates at dsdk12.net
Fri May 21 14:49:03 UTC 2004


Martin Kuchar wrote:
> Hi,
> I'm new to PowerDNS. Just configure it as upgrade from Bind 9 and Tinydns on
> two of our servers. In Bind, i can select which another servers can AXFR
> selected zones from me.
> In powerDNS i see only option to allow AXFR from selected servers, but it
> applied to all served zones.
> 
> We are masters for cca 1000 domains and some (about 20) have his own slave
> nameservers. So we need to allow 1.2.3.4 to transfer only zones "foo.com"
> and "anotherfoo.com", but no another zones. In PowerDNS if i allow 1.2.3.4
> to transfer zones, 1.2.3.4 can get all our 1000 zones.
> 
> I thing it was not discussed here before. Can anybody point me to solution ?

There was a partial patch posted some time back to add ACL support to 
PowerDNS, so you could allow specific servers to AXFR specific zones 
from your server. I have that incorporated into a patch I use on our DNS 
servers, and it works well. I can either (a) break the stuff out just 
for that, or (b) send you the entire patch. Let me know which you prefer.


More information about the Pdns-users mailing list