Skip to main content

DNSONLY questions

Comments

5 comments

  • mtindor
    To be clear about my real questions... I don't see cp5 DNS zones in /var/named on cp4, and I don't see cp4 DNS zones in /var/named on cp5. That's great. I wouldn't expect to see that, and wouldn't want to see that. I also don't "care" that cp4 can see cp5's DNSs in cp4 WHM --> Edit DNS, and vice versa... as long as the actual DNS zones from cp4 aren't showing up in /var/named on cp5 and vice versa. 1. given the fact that (a) there is supposedly no reverse trust relationship set up and the DNSONLY server has NO server associations listed under "DNS Cluster", how in the world does every cpanel box have the permission / ability to see/edit DNS zones from other servers. Sounds like there is a reverse trust set up somewhere. NOTE: Even though I can log into cp4 WHM, go to "Edit DNS Zone" and see mydomain.com (which is on cp5), I cannot edit it. It says "Failed to fetch zone mydomain.com.db". So I guess that makes sense, since there is no reverse trust. I'm just baffled at why a list of all domains from the DNSONLY box end up showing up under "Edit DNS Zone" on individual machines. 2. If this is expected behavior, please help me to understand why individual CPANEL servers should be able to see a list of all of the domains on the DNSONLY box when logged into the local CPANEL server WHM - Edit DNS Zone. 3. And since I didn't set up a reverse trust relationship, I'm now wondering if I should. If i did set up a reverse trust relationship when adding the DNSONLY server to each CPANEL box under DNS Cluster, does that mean I would then (a) be able to see a list of all domains on the DNSONLY server AND (b) be able to successfully edit them? 4. How would cPanel recommend that this be done, knowing that: - cp1 through cp5 are at one location - DNSONLY is at another location - I'd like to use the DNSONLY for secondary nameservice for cp1 through cp5 I think I'm doing it the recommended way (given that I only have one DNSONLY box). But I am now curious about whether there should actually be a reverse trust. Thanks Mike
    0
  • sneader
    I completely agree with you... you should NEVER see cp5's zones anywhere on cp4 and vice versa. Just think if you had 10 cPanel servers clustered to your DNS Only box. If every cPanel server had 300 domains hosted (a low number for most dedicated boxes), that means when you edit DNS in WHM, you are now going to see a list of 3,000 domains. Confusing... and just silly. I'm subscribed to this thread and will be waiting to hear what the answer is (bug, intended feature, or misconfiguration) - Scott
    0
  • mtindor
    Should be interesting. As we discussed, not only does "Edit DNS" on any of the boxes show ALL zones on the DNSONLY box, but it doesn't differentiate between which ones are local and which ones are not. So unless you know every domain you host and on what server it is hosted off the top of your head, you have to actually click on a domain and attempt to edit it just to know whether it's local or not. If you can edit it, it's a zone from the local server. If you can't edit it, it's a zone from another server [but you dont know from which other server]. Mike
    0
  • cPanelMichael
    Hello :) This is discussed in the following feature request: Ownership and access control of zones in the dns server. Please feel free to vote and add your feedback to this feature request. Thank you.
    0
  • sneader
    Thanks, Michael. Voting!!! And I see I'm not alone :-) - Scott
    0

Please sign in to leave a comment.