Discussion:
[Samba] WERR_DNS_ERROR_RCODE_REFUSED
Carlos A. P. Cunha
2016-06-28 20:37:06 UTC
Permalink
Hello!
I have Samba 4.3.3 with Windows Server 2008 R2 SP1, I cm problems in
DNS, which in windows can not create dns entries:


Windows = 192.168.200.66
Samba = 192.168.200.90

Error trying to create samba-tool:

samba-tool dns add 192.168.200.66 _msdcs.local.domain
9e0c71b8-36e0-4269-a69e-1a03bdab4841 CNAME WIN2008.local.domain
-Uadministrator
Password is [LOCAL \ administrator]
ERROR (runtime): uncaught exception - (9005, 'WERR_DNS_ERROR_RCODE_REFUSED')
File "/opt/samba/lib/python2.7/site-packages/samba/netcmd/__init__.py",
line 175, in _run
self.run return (* args, ** kwargs)
File "/opt/samba/lib/python2.7/site-packages/samba/netcmd/dns.py", line
1073, in run
0, server, zone, name, add_rec_buf, None)
root @ samba: /opt/samba_src/samba-4.3.3#



Samba 4 logs:

Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction on
zone local.domain
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 59830:
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction on
zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction on
zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of signer
= Win2008 \ $ \ @ LOCAL.DOMAIN name = WIN2008.local.domain tcpaddr =
type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of signer
= Win2008 \ $ \ @ LOCAL.DOMAIN name = WIN2008.local.domain tcpaddr =
type = A key = 996-ms-7.3-37764d. e5b44e60-3d6e-11e6-02b3-080027f8e516 /
160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of signer
= Win2008 \ $ \ @ LOCAL.DOMAIN name = WIN2008.local.domain tcpaddr =
type = A key = 996-ms-7.3-37764d. e5b44e60-3d6e-11e6-02b3-080027f8e516 /
160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 / key
Win2008 \ $ \ @ LOCAL.DOMAIN: updating zone 'local.domain / NONE':
deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 / key
Win2008 \ $ \ @ LOCAL.DOMAIN: updating zone 'local.domain / NONE':
deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A #
011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 / key
Win2008 \ $ \ @ LOCAL.DOMAIN: updating zone 'local.domain / NONE':
adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A #
011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted local.domain
rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction on
zone local.domain

Any idea ?

Thank you
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-28 22:42:24 UTC
Permalink
Hello!

Yes, Windows dns too, my dns in samba is Bind!!!


I dont understande -> "where does Bind store the zone info ? *"

:-|


Thanks
Post by Carlos A. P. Cunha
Hello!
I have Samba 4.3.3 with Windows Server 2008 R2 SP1, I cm problems in
Windows = 192.168.200.66
Samba = 192.168.200.90
samba-tool dns add 192.168.200.66 _msdcs.local.domain
9e0c71b8-36e0-4269-a69e-1a03bdab4841 CNAME WIN2008.local.domain
-Uadministrator
Password is [LOCAL \ administrator]
ERROR (runtime): uncaught exception - (9005,
'WERR_DNS_ERROR_RCODE_REFUSED')
It looks like the windows DC flatly refused the update
Post by Carlos A. P. Cunha
File
"/opt/samba/lib/python2.7/site-packages/samba/netcmd/__init__.py",
line 175, in _run
self.run return (* args, ** kwargs)
File "/opt/samba/lib/python2.7/site-packages/samba/netcmd/dns.py",
line 1073, in run
0, server, zone, name, add_rec_buf, None)
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A
# 011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A #
011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted
local.domain rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction
on zone local.domain
This log fragment is only showing the DC updating its own record on a
Samba DC, you will need to look in the logs on the windows DC.
I take it that the windows DC is running a DNS server, I think you
said in an earlier post that this is Bind DNS server, if this is the
case *where does Bind store the zone info ? *
Rowland
Post by Carlos A. P. Cunha
Any idea ?
Thank you
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-28 23:24:18 UTC
Permalink
My bind is version

ii bind9 1:9.10.3.dfsg.P4-8 amd64 Internet Domain
Name Server

Deb Recompilation with option:

tamps/configure: stamps/prepare
dh_testdir
rm -rf build
mkdir -p build
cd build && ../configure --prefix=/usr \
--mandir=\$${prefix}/share/man \
--libdir=\$${prefix}/lib/$(DEB_HOST_MULTIARCH) \
--infodir=\$${prefix}/share/info \
--sysconfdir=/etc/bind \
--localstatedir=/ \
--enable-threads \
--enable-largefile \
--with-libtool \
--enable-shared \
--enable-static \
--with-openssl=/usr \
--with-gssapi=/usr \
--with-gnu-ld \
--with-geoip=/usr \
--with-atf=no \
--enable-ipv6 \
--enable-rrl \
--enable-filter-aaaa \
--enable-native-pkcs11 \
--with-pkcs11=\$${prefix}/lib/$(DEB_HOST_MULTIARCH)/softhsm/libsofthsm2.so \
--with-dlz-postgres=no \
--with-dlz-mysql=no \
--with-dlz-bdb=yes \
--with-dlz-filesystem=yes \
--with-dlz-ldap=yes \
--with-dlz-stub=yes \
--with-dlopen=yes \
$(EXTRA_FEATURES)
Post by Carlos A. P. Cunha
Hello!
Yes, Windows dns too, my dns in samba is Bind!!!
I dont understande -> "where does Bind store the zone info ? *"
:-|
Thanks
Post by Carlos A. P. Cunha
Hello!
I have Samba 4.3.3 with Windows Server 2008 R2 SP1, I cm problems in
Windows = 192.168.200.66
Samba = 192.168.200.90
samba-tool dns add 192.168.200.66 _msdcs.local.domain
9e0c71b8-36e0-4269-a69e-1a03bdab4841 CNAME WIN2008.local.domain
-Uadministrator
Password is [LOCAL \ administrator]
ERROR (runtime): uncaught exception - (9005,
'WERR_DNS_ERROR_RCODE_REFUSED')
It looks like the windows DC flatly refused the update
Post by Carlos A. P. Cunha
File
"/opt/samba/lib/python2.7/site-packages/samba/netcmd/__init__.py",
line 175, in _run
self.run return (* args, ** kwargs)
File "/opt/samba/lib/python2.7/site-packages/samba/netcmd/dns.py",
line 1073, in run
0, server, zone, name, add_rec_buf, None)
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A
# 011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A
# 011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted
local.domain rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction
on zone local.domain
This log fragment is only showing the DC updating its own record on a
Samba DC, you will need to look in the logs on the windows DC.
I take it that the windows DC is running a DNS server, I think you
said in an earlier post that this is Bind DNS server, if this is the
case *where does Bind store the zone info ? *
Rowland
Post by Carlos A. P. Cunha
Any idea ?
Thank you
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-29 13:48:12 UTC
Permalink
Hello!


What DNS server is running on the DC windows?

Yes, to join him in Dominio, select the two options (equal in imegm wiki
samba), amnos roadando as 2008 R2

Have you looked at the logs on the DC windows?

Yes

If you have looked in the logs on the DC windows, have you found
anything relevant?

Nothing appears, so identified

Does the windows DC have a fixed ipaddress?

It has fixed IP in the same samba DC network.


Note: Samba my main DC with FSMO and added Windows




Thanks
Post by Carlos A. P. Cunha
Hello!
Yes, Windows dns too, my dns in samba is Bind!!!
I dont understande -> "where does Bind store the zone info ? *"
:-|
Thanks
Post by Carlos A. P. Cunha
Hello!
I have Samba 4.3.3 with Windows Server 2008 R2 SP1, I cm problems
Windows = 192.168.200.66
Samba = 192.168.200.90
samba-tool dns add 192.168.200.66 _msdcs.local.domain
9e0c71b8-36e0-4269-a69e-1a03bdab4841 CNAME WIN2008.local.domain
-Uadministrator
Password is [LOCAL \ administrator]
ERROR (runtime): uncaught exception - (9005,
'WERR_DNS_ERROR_RCODE_REFUSED')
It looks like the windows DC flatly refused the update
Post by Carlos A. P. Cunha
File
"/opt/samba/lib/python2.7/site-packages/samba/netcmd/__init__.py",
line 175, in _run
self.run return (* args, ** kwargs)
File "/opt/samba/lib/python2.7/site-packages/samba/netcmd/dns.py",
line 1073, in run
0, server, zone, name, add_rec_buf, None)
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling
transaction on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN #
011A # 011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A
# 011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted
local.domain rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed
transaction on zone local.domain
This log fragment is only showing the DC updating its own record on
a Samba DC, you will need to look in the logs on the windows DC.
I take it that the windows DC is running a DNS server, I think you
said in an earlier post that this is Bind DNS server, if this is the
case *where does Bind store the zone info ? *
Rowland
Post by Carlos A. P. Cunha
Any idea ?
Thank you
What DNS server is running on the windows DC ?
Have you looked at the logs on the windows DC ?
If you have looked in the logs on the windows DC, have you found
anything relevant ?
Does the windows DC have a fixed ipaddress ?
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-29 20:01:49 UTC
Permalink
I'm running DNS on Windows too, as it receives the update, and delete it
it it also erases the Samba, Windows so I could see are not leaving this
I create new entries.
Entries in samba via command or RSAT are working.


Thanks
Post by Carlos A. P. Cunha
Hello!
What DNS server is running on the DC windows?
Yes, to join him in Dominio, select the two options (equal in imegm
wiki samba), amnos roadando as 2008 R2
I think that means you are not running a DNS server on the windows DC,
at least that is what the wiki page seems to show.
Try running the command in your first post again, but this time
replace '192.168.200.66' with '192.168.200.90' and see what happens.
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-29 21:52:06 UTC
Permalink
Is running, so that request DNS request to Windos server it answers, it
can delete DNS entries and it Windows, receives new coming Samba (Master
FSMO)


Thanks
Post by Carlos A. P. Cunha
Post by Carlos A. P. Cunha
I'm running DNS on Windows too, as it receives the update, and delete
it it it also erases the Samba, Windows so I could see are not
leaving this I create new entries.
Entries in samba via command or RSAT are working.
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction on
zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction on
zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A #
011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A #
011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted
local.domain rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction
on zone local.domain
This is not your windows server dns being updated, it appears to be
your windows server record being updated on a Samba AD DC running Bind9.
So, I ask again, WHAT DNS SERVER IS RUNNING ON THE WINDOWS DC!
Note: the above is not shouting, it is for emphasis.
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-30 00:28:04 UTC
Permalink
Event View


The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly. The
extended error debug information (which may be empty) is "". The event
data contains the error.

But my dns is Ok,


My test is other linux(not samba)

Windows -> 192.168.200.66


host local.domain 192.168.200.66
Using domain server:
Name: 192.168.200.66
Address: 192.168.200.66#53
Aliases:

local.domain has address 192.168.200.90
local.domain has address 192.168.200.66


Thanks
Post by Carlos A. P. Cunha
Is running, so that request DNS request to Windos server it answers,
it can delete DNS entries and it Windows, receives new coming Samba
(Master FSMO)
Thanks
Post by Carlos A. P. Cunha
Post by Carlos A. P. Cunha
I'm running DNS on Windows too, as it receives the update, and
delete it it it also erases the Samba, Windows so I could see are
not leaving this I create new entries.
Entries in samba via command or RSAT are working.
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A
# 011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A #
011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted
local.domain rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction
on zone local.domain
This is not your windows server dns being updated, it appears to be
your windows server record being updated on a Samba AD DC running Bind9.
So, I ask again, WHAT DNS SERVER IS RUNNING ON THE WINDOWS DC!
Note: the above is not shouting, it is for emphasis.
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-06-30 17:44:44 UTC
Permalink
Hello!

something else?


Thanks
Post by Carlos A. P. Cunha
Event View
The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly.
The extended error debug information (which may be empty) is "". The
event data contains the error.
But my dns is Ok,
My test is other linux(not samba)
Windows -> 192.168.200.66
host local.domain 192.168.200.66
Name: 192.168.200.66
Address: 192.168.200.66#53
local.domain has address 192.168.200.90
local.domain has address 192.168.200.66
Thanks
Post by Carlos A. P. Cunha
Is running, so that request DNS request to Windos server it answers,
it can delete DNS entries and it Windows, receives new coming Samba
(Master FSMO)
Thanks
Post by Carlos A. P. Cunha
Post by Carlos A. P. Cunha
I'm running DNS on Windows too, as it receives the update, and
delete it it it also erases the Samba, Windows so I could see are
not leaving this I create new entries.
Entries in samba via command or RSAT are working.
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction
on zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = AAAA key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
tcpaddr = type = A key = 996-ms-7.3-37764d.
e5b44e60-3d6e-11e6-02b3-080027f8e516 / 160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': deleting RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A
# 011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 /
NONE': adding an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A
# 011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted
local.domain rdataset 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain. hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction
on zone local.domain
This is not your windows server dns being updated, it appears to be
your windows server record being updated on a Samba AD DC running Bind9.
So, I ask again, WHAT DNS SERVER IS RUNNING ON THE WINDOWS DC!
Note: the above is not shouting, it is for emphasis.
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
mathias dufresne
2016-07-01 09:52:43 UTC
Permalink
To debug DNS updates: edit samba_dnsupdate and comment line (411 here)
"os.unlink(tmpfile)".
This edition will make next run of command 'samba_dnsupdate' will not
remove temporary files in /tmp.

Then you use one of these files to push update using nsupdate:
nsupdate -g /tmp/<some samba_dnsupdate tmp file>

-g means "use kerberos auth". For that works you must first perform a kinit
to get a valid ticket. Start with a kinit administrator as it the one with
the greater power facing AD. With that account if the update is not
successful it should be because the account as not sufficient permissions.
The you could try using dns-<your dc> account and dns.keytab in private
directory to retry with the user used by your Bind to authenticate against
AD.

If this works, DNS updates are working. And for now I have no idea from
your could come.

cheers,
m.
Post by Carlos A. P. Cunha
Hello!
something else?
Thanks
Post by Carlos A. P. Cunha
Event View
The DNS server has encountered a critical error from the Active
Directory. Check that the Active Directory is functioning properly. The
extended error debug information (which may be empty) is "". The event data
contains the error.
But my dns is Ok,
My test is other linux(not samba)
Windows -> 192.168.200.66
host local.domain 192.168.200.66
Name: 192.168.200.66
Address: 192.168.200.66#53
local.domain has address 192.168.200.90
local.domain has address 192.168.200.66
Thanks
Post by Carlos A. P. Cunha
Is running, so that request DNS request to Windos server it answers, it
can delete DNS entries and it Windows, receives new coming Samba (Master
FSMO)
Thanks
Post by Carlos A. P. Cunha
Post by Carlos A. P. Cunha
I'm running DNS on Windows too, as it receives the update, and delete
it it it also erases the Samba, Windows so I could see are not leaving this
I create new entries.
Entries in samba via command or RSAT are working.
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction on
zone local.domain
update 'local.domain / IN' denied
Jun 28 17:28:40 samba named [8988]: samba_dlz: canceling transaction on
zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: starting transaction on
zone local.domain
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
type = AAAA key = 996-ms-7.3-37764d. e5b44e60-3d6e-11e6-02b3-080027f8e516 /
160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
type = A key = 996-ms-7.3-37764d. e5b44e60-3d6e-11e6-02b3-080027f8e516 /
160/0
Jun 28 17:28:40 samba named [8988]: samba_dlz: Allowing update of
type = A key = 996-ms-7.3-37764d. e5b44e60-3d6e-11e6-02b3-080027f8e516 /
160/0
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 / key
RRset at 'WIN2008.local.domain' YYYY
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 / key
RRset at 'WIN2008.local.domain' THE
Jun 28 17:28:40 samba named [8988]: samba_dlz: subtracted rdataset
WIN2008.local.domain '. WIN2008.local.domain # 011900 # 011IN # 011A #
011192.168.200.66'
Jun 28 17:28:40 samba named [8988]: client 192.168.200.66 # 50239 / key
an RR at 'WIN2008.local.domain 'The 192.168.200.66
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
WIN2008.local.domain 'WIN2008.local.domain # 0111200 # 011IN # 011A #
011192.168.200.66.'
Jun 28 17:28:40 samba named [8988]: samba_dlz:. Subtracted local.domain
rdataset 'local.domain # 0113600 # # 011SOA 011IN # 011samba.local.domain.
hostmaster.local.domain. 5900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: added rdataset
local.domain 'local.domain # 0113600 # # 011SOA 011IN #
011samba.local.domain.. hostmaster.local.domain. 6900600 86400 3600 '
Jun 28 17:28:40 samba named [8988]: samba_dlz: committed transaction on
zone local.domain
This is not your windows server dns being updated, it appears to be
your windows server record being updated on a Samba AD DC running Bind9.
So, I ask again, WHAT DNS SERVER IS RUNNING ON THE WINDOWS DC!
Note: the above is not shouting, it is for emphasis.
Rowland
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Carlos A. P. Cunha
2016-07-01 12:21:01 UTC
Permalink
Hello!
Samba update for AD are working for what I identified the problem and
creating newstarting AD, is that the problem is that Samba has FSMO and
AD is being join the field

Thank you
Post by mathias dufresne
To debug DNS updates: edit samba_dnsupdate and comment line (411 here)
"os.unlink(tmpfile)".
This edition will make next run of command 'samba_dnsupdate' will not
remove temporary files in /tmp.
nsupdate -g /tmp/<some samba_dnsupdate tmp file>
-g means "use kerberos auth". For that works you must first perform a
kinit to get a valid ticket. Start with a kinit administrator as it
the one with the greater power facing AD. With that account if the
update is not successful it should be because the account as not
sufficient permissions. The you could try using dns-<your dc> account
and dns.keytab in private directory to retry with the user used by
your Bind to authenticate against AD.
If this works, DNS updates are working. And for now I have no idea
from your could come.
cheers,
m.
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Loading...