IPA DNS DNSSEC 导致全局转发无法工作
Issue
- IPA 全局 DNS 转发器没有解析
- 如何在 IdM 中禁用 DNSSEC
-
lame-servers.log 有
31-Jan-2023 20:59:58.279 info: no valid RRSIG resolving 'host.external.example.com/DS/IN': 10.0.0.2#53
31-Jan-2023 20:59:59.449 info: insecurity proof failed resolving 'external.example.com/DNSKEY/IN': 10.0.0.2#53
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Identity Management
- 不支持 DNSSEC 的外部 DNS 服务器被用作全局转发
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.