Dynamic Update

Route 53 ๋‚˜ google domain๋“ฑ์—์„œ๋Š” api๋ฅผ ์ด์šฉํ•˜์—ฌ ๋™์ ์œผ๋กœ ๋„๋ฉ”์ธ์„ ๋“ฑ๋กํ•˜๊ฑฐ๋‚˜ ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ ๋ฆฌ๋ˆ…์Šค์—์„œ ์ง€์›ํ•˜๋Š” bind์—์„œ๋Š” ์ด๊ฒŒ ์•ˆ๋˜๋Š”์ค„ ์•Œ๊ณ  ์žˆ์—‡์Šต๋‹ˆ๋‹ค. ํ™•์ธํ•ด๋ณด๋‹ˆ ์ง€์›์ด ๋ฉ๋‹ˆ๋‹ค.

rfc2136 ์—์„œ ์ •์˜๋ฅผ ํ•ด๋‘๊ณ  ์žˆ๋„ค์š”.

Bind9์—์„œ Dynamic Update๋ฅผ ์‚ฌ์šฉํ•ด๋ณด๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

prerequisites

๊ธฐ๋ณธ์ ์œผ๋กœ bind9์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋‹ค๊ณ  ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท์— ๋‚ด์šฉ์ด ๋งŽ์œผ๋‹ˆ ๊ธˆ๋ฐฉ ๊ฒ€์ƒ‰ ๋ ๊ฒ๋‹ˆ๋‹ค.

ํ‚ค๋ฅผ ์ƒ์„ฑ

dns์„œ๋ฒ„์—์„œ ํ‚ค๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

๋„๋ฉ”์ธ์€ teamsmiley.dev๋ฅผ ๊ธฐ์ค€์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค.

dnssec-keygen -r /dev/urandom -a HMAC-SHA512 -b 512 -n HOST teamsmiley-dev-secret

์œ„ ํ˜•ํƒœ๋กœ key์™€ private๊ฐ€ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

ํ™•์ธํ•ด๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

cat Kteamsmiley-dev-secret.+157+39736.private

Private-key-format: v1.3
Algorithm: 165 (HMAC_SHA512)
Key: KzqRA3OnnSxx3Awp9m8Pt
Bits: AAA=
Created: 20220209130648
Publish: 20220209130648
Activate: 20220209130648

named.conf์— ์ถ”๊ฐ€

vi named.conf

## ์ˆ˜์ •
zone "teamsmiley.dev"{
        type master;
        file "teamsmiley.dev";
		....
        allow-update { key "teamsmiley-dev-secret"; }; # ์ถ”๊ฐ€
};

## ๋‹ค์Œ ์ถ”๊ฐ€
key "teamsmiley-dev-secret" {
    algorithm hmac-sha256;
    secret "KzqRA3Onxxx";
};

named ์žฌ์‹œ์ž‘

/etc/init.d/named restart

๋™์ž‘ํ™•์ธ

nsupdate ํˆด์„ ์ด์šฉํ•˜์—ฌ ํ…Œ์ŠคํŠธํ•˜๊ธฐ๋กœ ํ•œ๋‹ค.

nsupdate -y hmac-md5:teamsmiley-dev-secret:KzqRA3Onnxxx

update add teamsmiley.dev 60 txt testing

send

์‹คํŒจ

ํ˜น์‹œ ์‹คํŒจํ•œ๋‹ค๋ฉด named ํด๋”์˜ ๊ทธ๋ฃน์— write๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ด์ฃผ์„ธ์š”.

chmod 775 /var/named/chroot/var/named/

/etc/init.d/named restart

๋‹ค์‹œ ํ…Œ์ŠคํŠธํ•ด๋ณธ๋‹ค.

update-policy

allow-update ๋ณด๋‹ค๋Š” update-policy๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค. ์ž์„ธํ•œ ์ปจํŠธ๋กค์ด ๊ฐ€๋Šฅ

zone "teamsmiley.dev"{
        type master;
        file "teamsmiley.dev";
        #allow-update { key "xxxx-com-secret"; };
        update-policy {
          grant xxxx-com-secret name _acme-challenge.teamsmiley.dev. txt;
        };
};

Last updated

Was this helpful?