Configuring zones to accept GSS-TSIG updates - BlueCat Integrity - 9.3.0

Address Manager Administration Guide

BlueCat Integrity

You must configure each subzones with the Update Policy deployment option.

For more information about the Update Policy DNS deployment option, refer to Update Policy DNS deployment option.

To configure subzones:

  1. Navigate to an AD subzone under default View> Top level zone (com)> Lower level zone (> Subzones (
  2. Click the Deployment Options tab.
  3. Under Deployment Options, click New and select DNS Option.
  4. Under General, set the following options and click Add.
    • Option—Update Policy
    • Privilege—grant
    • Identity—select Name and type a client name in the text field.
    • Nametype—subdomain
    • Name—enter the name of the current subzone (for example,
    • RR Types—ANY
  5. Under Server, select the server to which the option will apply.
  6. Under Change Control, add comments, if required.
  7. Click Add.
  8. Repeat this process for each of the AD subzones.
This completes all the necessary steps in Address Manager.
You need to deploy the configuration to a managed DNS Server. Perform a full DNS deployment to the DNS Server.