# External RFC2136 DNS without TSIG

**URL:** <https://forums.suse.com/t/external-rfc2136-dns-without-tsig/5097>\
**Category:** General\
**Created:** [January 5, 2017, 8:08am UTC](https://forums.suse.com/t/external-rfc2136-dns-without-tsig/5097 "2017-01-05T08:08:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nheinemans](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/nheinemans/32/2009_2.png) [@nheinemans](https://forums.suse.com/u/nheinemans)\
**Post date:** [January 5, 2017, 8:08am UTC](https://forums.suse.com/t/external-rfc2136-dns-without-tsig/5097/1 "2017-01-05T08:08:10Z")

</div>

I’m trying to configure the DNS update (RFC2136) service. However, I noticed the TSIG name and key are mandatory fields. In our setup, TSIG is not necessary. Would it be possible to make these fields optional?

---

<div class="post-metadata">

**Author:** ![broesch-dkk](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@broesch-dkk](https://forums.suse.com/u/broesch-dkk)\
**Post date:** [January 5, 2017, 9:37am UTC](https://forums.suse.com/t/external-rfc2136-dns-without-tsig/5097/2 "2017-01-05T09:37:43Z")

</div>

We were discussing the same topic here:

> [@DNS Update RFC2136 without security](http://forums.suse.com/t/dns-update-rfc2136-without-security/5082):
>
> I am trying to get the DNS Update Service to update DNS records in an Windows DNS Server. It is an internal Domain DNS Server, so there is no security (needed). The rancher server is running in the same domain. I can add DNS records using nsupdate from my local machine without TSIG. When I use DNS Update RFC2136 I get errors, because TSIG Key Name and TSIG Key are mandatory. I looked at the code [here](https://github.com/rancher/external-dns) and can’t see an easy way to send the request without TSIG. We plan to have several interna…

---

<div class="post-metadata">

**Author:** ![jgreat](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/jgreat/32/710_2.png) [@jgreat](https://forums.suse.com/u/jgreat)\
**Post date:** [January 6, 2017, 9:56pm UTC](https://forums.suse.com/t/external-rfc2136-dns-without-tsig/5097/3 "2017-01-06T21:56:23Z")

</div>

Looks like this is going to be officially resolved, but in the meantime,

I have a totally-not-at-all-supported, ymmv, you’re-on-your-own… docker image of the rancher-external-dns client we are using with tsig removed. We use it to talk directly to our AD DNS servers since I can’t find a go dns client that supports GSS-TSIG:

github: [https://github.com/jgreat/external-dns](https://github.com/jgreat/external-dns)  
docker: jgreat/rancher-external-dns:0.6.0-ad-1

docker-compose.yml

```auto
external-dns-ad:
  image: jgreat/rancher-external-dns:0.6.0-ad-1
  command: "-provider=ad"
  expose:
   - 1000
  environment:
    AD_HOST: ${AD_HOST}
    AD_PORT: 53
    ROOT_DOMAIN: ${ROOT_DOMAIN}
    TTL: ${TTL}
  labels:
    io.rancher.container.pull_image: always
    io.rancher.container.create_agent: "true"
    io.rancher.container.agent.role: "external-dns"

```

rancher-compose.yml

```auto
.catalog:
  name: "Rancher-External-DNS (Active Directory)"
  version: "0.6.0-ad-1"
  description: Rancher External DNS service publish to AD DNS.
  minimum_rancher_version: v0.44.0
  uuid: external-dns-ad:0.6.0-ad-1
  questions:
    - variable: AD_HOST
      label: DNS Server
      type: string
      required: true
    - variable: TTL
      label: TTL
      description: "The resource record cache time to live (TTL), in seconds"
      type: int
      default: 60
      required: false
    - variable: ROOT_DOMAIN
      label: Hosted zone name
      description: Hosted zone name (zone has to be pre-created). DNS entries will be created for <service>.<stack>.<environment>.<root zone>
      type: string
      required: true

external-dns-ad:
  health_check:
    port: 1000
    interval: 30000
    unhealthy_threshold: 3
    request_line: GET / HTTP/1.0
    healthy_threshold: 2
    response_timeout: 2000

```
