Configuring zones to accept GSS-TSIG updates - BlueCat Integrity - 26.1.0

Address Manager Administration Guide

ft:locale
en-US
Product name
BlueCat Integrity
Version
26.1.0

You must configure each subzones with the Update Policy deployment option.

For more information about the Update Policy DNS deployment option, refer to Update Policy DNS deployment option.

To configure subzones:

  1. Select the DNS tab in the sidebar, then select Views.
  2. Navigate to an AD subzone under default View > Top level zone (com) > Lower level zone (example.com) > Subzones (_msdcs.example.com).
  3. Select the Deployment options tab.
  4. Select New > DNS option.
  5. Under General, set the following option parameters:
    • Name—Update Policy(38)
    • Privilege—grant
    • Nametype—subdomain
    • Name—enter the name of the current subzone (for example, _msdcs.example.com)
    • Identity type—Name
    • Identity— enter a client name.
    • Resource record type—any
  6. Select Add to table.
  7. On the Servers tab, select the server to which the option will apply.
  8. In the Change control section, add comments if required.
  9. Select Create or Create and add another.
  10. Repeat this process for each of the AD subzones.
This completes all the necessary steps in Address Manager.
You need to deploy the configuration to a managed DNS Server. Perform a full DNS deployment to the DNS Server.