O'Reilly logo

Active Directory Cookbook by Robbie Allen

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

18.11. Using BIND for DNS

Problem

You’ve decided that you do not want to use Microsoft DNS for Active Directory and instead prefer to use BIND.

Solution

The two main requirements for supporting Active Directory DNS are SRV records and Dynamic DNS support. The first version of BIND to support SRV records was 8.2.2 patch 7. Hopefully you are running a much more recent version since that was released in 2000. You technically don’t have to use DDNS with Active Directory DNS records, but if you don’t, you end up doing a lot of work to manually maintain the Active Directory-related resource records.

Here is an example BIND 8 configuration to support the ad.rallencorp.com domain:

Options {
directory "/etc/namedb";
};
Zone "ad.rallencorp.com" IN {
type master;
file "db.ad.rallencorp.com";
allow-update { dc1.; dc2.; dc3.; };
check-names ignore;
};

The directory directive specifies where the zone files are stored. The type should be master, and the file directive is the name of the file to store the contents of the zone in. The allow-update directive indicates which servers (either by name or IP address) can dynamically update the zone. Finally, the check-names ignore directive tells BIND not to be restrictive about the names used in resource records. Without this setting, BIND would fail to respond to queries for records containing underscores used by Active Directory.

The BIND 9 configuration for the same zone would look exactly the same, except the check-names ignore line is not necessary. By ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required