Jump to content
Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble

RNDC procedure explained

Recommended Posts

Why does rndc log warning key file ... exists, but using default configuration file (rndc.conf)?
Author: Cathy Almond Reference Number: AA-00722 Views: 24969 Created: 2012-07-18 15:04 Last Updated: 2017-09-18 04:44 0 Rating/ Voters ico-rating-g.gifico-rating-g.gifico-rating-g.gifico-rating-g.gifico-rating-g.gif
After upgrading BIND to a current version, you might be surprised to see this warning when using rndc commands (although the command should still work as before, unless you've made other configuration changes):
WARNING: key file (rndc.key) exists, but using default configuration file (rndc.conf)

Both named and rndc can operate with explicit or automatic control configuration.  They do this by looking for the file rndc.key in the default configuration files directory.

If there is no explicit configuration (the controls statement in named.conf for named, or the existence of the file rndc.conf for rndc), then the key in the rndc.key file will be used instead (if it exists). 

The rndc.key file isn't created automatically on installation

Use "rndc-confgen -a" to create the rndc.key file

Unfortunately, in the situation where there is both an explicit configuration, and the file rndc.key exists, it can sometimes be confusing for troubleshooting to know which configuration option is in use, particularly if there are problems with issuing rndc commands.  So from BIND 9.7.0, the warning was added so that the choice made by rndc was clearly indicated to the operator.

Administrators who have made use of the include functionality of named.conf and rndc.conf to import an independently-generated rndc.key file will see this new warning, but can safely ignore it.


Getting rid of the warning message

There is no need to make any configuration changes if rndc commands are not failing, but administrators might prefer to ensure that any ambiguity is removed.  Options include:

  • Removing the rndc.key file
  • Keeping rndc.key, but removing the controls statements from named.conf and deleting rndc.conf
  • If using include for rndc.key, you could put the file elsewhere and import it from there



© 2001-2018 Internet Systems Consortium

For assistance with problems and questions for which you have not been able to find an answer in our Knowledge Base, we recommend searching our community mailing list archivesand/or posting your question there (you will need to register there first for your posts to be accepted). The bind-users and the dhcp-users lists particularly have a long-standing and active membership.

ISC relies on the financial support of the community to fund the development of its open source software products. If you would like to support future product evolution and maintenance as well having peace of mind knowing that our team of experts are poised to provide you with individual technical assistance whenever you call upon them, then please consider our Professional Subscription Support services - details can be found on our main website.




Share this post

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.