<div dir="ltr">Running the command displays no output.<br><div><br>Here is the config file output:<br><br># This file is sourced by dirsrv upon startup to set<br># the default environment for all directory server instances.<br># To set instance specific defaults, use the file in the same<br># directory called dirsrv-instance where "instance"<br># is the name of your directory server instance e.g.<br># dirsrv-localhost for the slapd-localhost instance.<br><br># This file is in systemd EnvironmentFile format - see man systemd.exec<br><br># In order to make more file descriptors available<br># to the directory server, first make sure the system<br># hard limits are raised, then use ulimit - uncomment<br># out the following line and change the value to the<br># desired value<br># ulimit -n 8192<br># note - if using systemd, ulimit won't work - you must edit<br># the systemd unit file for directory server to add the<br># LimitNOFILE option - see man systemd.exec for more info<br><br># A per instance keytab does not make much sense for servers.<br># Kerberos clients use the machine FQDN to obtain a ticket like ldap/FQDN, there<br># is nothing that can make a client understand how to get a per-instance ticket.<br># Therefore by default a keytab should be considered a per server option.<br><br># Also this file is sourced for all instances, so again all<br># instances would ultimately get the same keytab.<br><br># Finally a keytab is normally named either krb5.keytab or <service>.keytab<br><br># In order to use SASL/GSSAPI (Kerberos) the directory<br># server needs to know where to find its keytab<br># file - uncomment the following line and set<br># the path and filename appropriately<br># if using systemd, omit the "; export VARNAME" at the end<br><br># how many seconds to wait for the startpid file to show<br># up before we assume there is a problem and fail to start<br># if using systemd, omit the "; export VARNAME" at the end<br>#STARTPID_TIME=10 ; export STARTPID_TIME<br># how many seconds to wait for the pid file to show<br># up before we assume there is a problem and fail to start<br># if using systemd, omit the "; export VARNAME" at the end<br>#PID_TIME=600 ; export PID_TIME<br>KRB5CCNAME=/tmp/krb5cc_389<br>KRB5_KTNAME=/etc/dirsrv/ds.keytab<br><br></div><div>I tried reinstalling with ipa-dns-install and it failed with errors. From the logs it looks like it sets resolve.conf to 127.0.0.1 and then tries to do lookups and fails. Here are selections from the logs:<br><br>2017-01-05T13:13:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:47Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:47Z DEBUG [4/8]: setting up kerberos principal<br>2017-01-05T13:13:47Z DEBUG Starting external process<br>2017-01-05T13:13:47Z DEBUG args=kadmin.local -q addprinc -randkey DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> -x ipa-setup-override-restrictions<br>2017-01-05T13:13:47Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:47Z DEBUG stdout=Authenticating as principal admin/<a href="mailto:admin@INTERNAL.EMERLYN.COM">admin@INTERNAL.EMERLYN.COM</a> with password.<br><br>2017-01-05T13:13:47Z DEBUG stderr=WARNING: no policy specified for DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a>; defaulting to no policy<br>add_principal: Principal or policy already exists while creating "DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a>".<br><br>2017-01-05T13:13:47Z DEBUG Backing up system configuration file '/etc/named.keytab'<br>2017-01-05T13:13:47Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index'<br>2017-01-05T13:13:47Z DEBUG Starting external process<br>2017-01-05T13:13:47Z DEBUG args=kadmin.local -q ktadd -k /etc/named.keytab DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> -x ipa-setup-override-restrictions<br>2017-01-05T13:13:47Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:47Z DEBUG stdout=Authenticating as principal admin/<a href="mailto:admin@INTERNAL.EMERLYN.COM">admin@INTERNAL.EMERLYN.COM</a> with password.<br>Entry for principal DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab.<br>Entry for principal DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab.<br>Entry for principal DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/named.keytab.<br>Entry for principal DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type arcfour-hmac added to keytab WRFILE:/etc/named.keytab.<br>Entry for principal DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/named.keytab.<br>Entry for principal DNS/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/named.keytab.<br><br>2017-01-05T13:13:47Z DEBUG stderr=<br>2017-01-05T13:13:47Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:47Z DEBUG [5/8]: setting up named.conf<br>2017-01-05T13:13:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'<br>2017-01-05T13:13:47Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'<br>2017-01-05T13:13:47Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state'<br>2017-01-05T13:13:47Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:47Z DEBUG [6/8]: setting up server configuration<br>2017-01-05T13:13:47Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket from SchemaCache<br>2017-01-05T13:13:47Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x4c48440><br>2017-01-05T13:13:48Z DEBUG raw: dnsserver_add(u'<a href="http://id-management-2.internal.emerlyn.com">id-management-2.internal.emerlyn.com</a>', idnssoamname=<DNS name <a href="http://id-management-2.internal.emerlyn.com">id-management-2.internal.emerlyn.com</a>.>, version=u'2.213')<br>2017-01-05T13:13:48Z DEBUG dnsserver_add(u'<a href="http://id-management-2.internal.emerlyn.com">id-management-2.internal.emerlyn.com</a>', idnssoamname=<DNS name <a href="http://id-management-2.internal.emerlyn.com">id-management-2.internal.emerlyn.com</a>.>, all=False, raw=False, version=u'2.213')<br>2017-01-05T13:13:48Z DEBUG raw: dnsserver_mod(u'<a href="http://id-management-2.internal.emerlyn.com">id-management-2.internal.emerlyn.com</a>', idnsforwarders=[u'10.72.100.16'], idnsforwardpolicy=u'only', version=u'2.213')<br>2017-01-05T13:13:48Z DEBUG dnsserver_mod(u'<a href="http://id-management-2.internal.emerlyn.com">id-management-2.internal.emerlyn.com</a>', idnsforwarders=(u'10.72.100.16',), idnsforwardpolicy=u'only', rights=False, all=False, raw=False, version=u'2.213')<br>2017-01-05T13:13:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state'<br>2017-01-05T13:13:48Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state'<br>2017-01-05T13:13:48Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:48Z DEBUG [7/8]: configuring named to start on boot<br>2017-01-05T13:13:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:48Z DEBUG Starting external process<br>2017-01-05T13:13:48Z DEBUG args=/bin/systemctl disable named-pkcs11.service<br>2017-01-05T13:13:48Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:48Z DEBUG stdout=<br>2017-01-05T13:13:48Z DEBUG stderr=<br>2017-01-05T13:13:48Z DEBUG service DNS startup entry already enabled<br>2017-01-05T13:13:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:48Z DEBUG Starting external process<br>2017-01-05T13:13:48Z DEBUG args=/bin/systemctl stop named.service<br>2017-01-05T13:13:48Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:48Z DEBUG stdout=<br>2017-01-05T13:13:48Z DEBUG stderr=<br>2017-01-05T13:13:48Z DEBUG Starting external process<br>2017-01-05T13:13:48Z DEBUG args=/bin/systemctl mask named.service<br>2017-01-05T13:13:48Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:48Z DEBUG stdout=<br>2017-01-05T13:13:48Z DEBUG stderr=Created symlink from /etc/systemd/system/named.service to /dev/null.<br><br>2017-01-05T13:13:48Z DEBUG duration: 0 seconds<br><span style="color:rgb(255,0,0)">2017-01-05T13:13:48Z DEBUG [8/8]: changing resolv.conf to point to ourselves</span><br>2017-01-05T13:13:48Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:48Z DEBUG Done configuring DNS (named).<br>2017-01-05T13:13:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:48Z DEBUG Starting external process<br>2017-01-05T13:13:48Z DEBUG args=/bin/systemctl stop ipa-dnskeysyncd.service<br>2017-01-05T13:13:48Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:48Z DEBUG stdout=<br>2017-01-05T13:13:48Z DEBUG stderr=<br>2017-01-05T13:13:48Z DEBUG Configuring DNS key synchronization service (ipa-dnskeysyncd)<br>2017-01-05T13:13:48Z DEBUG [1/7]: checking status<br>2017-01-05T13:13:48Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket from SchemaCache<br>2017-01-05T13:13:48Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x4eb2c20><br>2017-01-05T13:13:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:48Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:48Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:48Z DEBUG [2/7]: setting up bind-dyndb-ldap working directory<br>2017-01-05T13:13:48Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:48Z DEBUG [3/7]: setting up kerberos principal<br>2017-01-05T13:13:48Z DEBUG Removing service keytab: /etc/ipa/dnssec/ipa-dnskeysyncd.keytab<br>2017-01-05T13:13:48Z DEBUG Starting external process<br>2017-01-05T13:13:48Z DEBUG args=kadmin.local -q addprinc -randkey ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> -x ipa-setup-override-restrictions<br>2017-01-05T13:13:48Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:48Z DEBUG stdout=Authenticating as principal admin/<a href="mailto:admin@INTERNAL.EMERLYN.COM">admin@INTERNAL.EMERLYN.COM</a> with password.<br><br>2017-01-05T13:13:48Z DEBUG stderr=WARNING: no policy specified for ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a>; defaulting to no policy<br>add_principal: Principal or policy already exists while creating "ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a>".<br><br>2017-01-05T13:13:48Z DEBUG Starting external process<br>2017-01-05T13:13:48Z DEBUG args=kadmin.local -q ktadd -k /etc/ipa/dnssec/ipa-dnskeysyncd.keytab ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> -x ipa-setup-override-restrictions<br>2017-01-05T13:13:49Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:49Z DEBUG stdout=Authenticating as principal admin/<a href="mailto:admin@INTERNAL.EMERLYN.COM">admin@INTERNAL.EMERLYN.COM</a> with password.<br>Entry for principal ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab.<br>Entry for principal ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab.<br>Entry for principal ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab.<br>Entry for principal ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type arcfour-hmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab.<br>Entry for principal ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab.<br>Entry for principal ipa-dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM">id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM</a> with kvno 7, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab.<br><br>2017-01-05T13:13:49Z DEBUG stderr=<br>2017-01-05T13:13:49Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:49Z DEBUG [4/7]: setting up SoftHSM<br>2017-01-05T13:13:49Z DEBUG Creating new softhsm config file<br>2017-01-05T13:13:49Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:49Z DEBUG [5/7]: adding DNSSEC containers<br>2017-01-05T13:13:49Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket from SchemaCache<br>2017-01-05T13:13:49Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x4ec9998><br>2017-01-05T13:13:49Z INFO DNSSEC container exists (step skipped)<br>2017-01-05T13:13:49Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:49Z DEBUG [6/7]: creating replica keys<br>2017-01-05T13:13:49Z DEBUG Creating replica's key pair<br>2017-01-05T13:13:49Z DEBUG Storing replica public key to LDAP, ipk11UniqueId=autogenerate,cn=keys,cn=sec,cn=dns,dc=internal,dc=emerlyn,dc=com<br>2017-01-05T13:13:49Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket from SchemaCache<br>2017-01-05T13:13:49Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-INTERNAL-EMERLYN-COM.socket conn=<ldap.ldapobject.SimpleLDAPObject instance at 0x4eb2830><br>2017-01-05T13:13:50Z DEBUG Replica public key stored<br>2017-01-05T13:13:50Z DEBUG Setting CKA_WRAP=False for old replica keys<br>2017-01-05T13:13:50Z DEBUG Changing ownership of token files<br>2017-01-05T13:13:50Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:50Z DEBUG [7/7]: configuring ipa-dnskeysyncd to start on boot<br>2017-01-05T13:13:50Z DEBUG Starting external process<br>2017-01-05T13:13:50Z DEBUG args=/bin/systemctl disable ipa-dnskeysyncd.service<br>2017-01-05T13:13:50Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:50Z DEBUG stdout=<br>2017-01-05T13:13:50Z DEBUG stderr=<br>2017-01-05T13:13:50Z DEBUG service DNSKeySync startup entry already enabled<br>2017-01-05T13:13:50Z DEBUG duration: 0 seconds<br>2017-01-05T13:13:50Z DEBUG Done configuring DNS key synchronization service (ipa-dnskeysyncd).<br>2017-01-05T13:13:50Z DEBUG Starting external process<br>2017-01-05T13:13:50Z DEBUG args=/bin/systemctl restart ipa-dnskeysyncd.service<br>2017-01-05T13:13:50Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:50Z DEBUG stdout=<br>2017-01-05T13:13:50Z DEBUG stderr=<br>2017-01-05T13:13:50Z DEBUG Starting external process<br>2017-01-05T13:13:50Z DEBUG args=/bin/systemctl is-active ipa-dnskeysyncd.service<br>2017-01-05T13:13:50Z DEBUG Process finished, return code=0<br>2017-01-05T13:13:50Z DEBUG stdout=active<br><br>2017-01-05T13:13:50Z DEBUG stderr=<br>2017-01-05T13:13:50Z DEBUG Restarting named<br>2017-01-05T13:13:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state'<br>2017-01-05T13:13:50Z DEBUG Starting external process<br>2017-01-05T13:13:50Z DEBUG args=/bin/systemctl restart named-pkcs11.service<br>2017-01-05T13:13:50Z DEBUG Process finished, return code=1<br>2017-01-05T13:13:50Z DEBUG stdout=<br>2017-01-05T13:13:50Z DEBUG stderr=Job for named-pkcs11.service failed because the control process exited with error code. See "systemctl status named-pkcs11.service" and "journalctl -xe" for details.<br><br></div><div>It looks to me like the change in resolve.conf is causing all subsequent lookups to fail.<br><br></div><div>Jeff<br></div><div><br><br></div><div><br></div><div><br><br></div><div><br><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jan 5, 2017 at 3:43 AM, Martin Basti <span dir="ltr"><<a href="mailto:mbasti@redhat.com" target="_blank">mbasti@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div bgcolor="#FFFFFF">
<p><br>
</p>
<br>
<div class="gmail-m_-7480147556481762824moz-cite-prefix">On 04.01.2017 22:21, Jeff Goddard
wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr">
<div>
<div>
<div>
<div>
<div>I don't want to hijack someone else's thread but
I'm having what appears to be the same problem and
have not seen a solution presented yet.<br>
<br>
Here is the output of journalctl -xe after having
tried to start named: <br>
<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: loading configuration from
'/etc/named.conf'<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: reading built-in trusted keys from
file '/etc/named.iscdlv.key'<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: using default UDP/IPv4 port range:
[1024, 65535]<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: using default UDP/IPv6 port range:
[1024, 65535]<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: listening on IPv6 interfaces, port
53<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: listening on IPv4 interface lo,
127.0.0.1#53<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: listening on IPv4 interface ens32,
10.73.100.31#53<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: generating session key for dynamic
DNS<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: sizing zone task pool based on 6
zones<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: set up managed keys zone for view
_default, file '/var/named/dynamic/managed-ke<wbr>ys.bind'<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: bind-dyndb-ldap version 10.0
compiled at 18:06:06 Nov 11 2016, compiler 4.8.5
20150623 (Red Hat 4.8.5-11)<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: option 'serial_autoincrement' is
not supported, ignoring<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: GSSAPI client step 1<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: GSSAPI client step 1<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
ns-slapd[2596]: GSSAPI server step 1<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: GSSAPI client step 1<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
ns-slapd[2596]: GSSAPI server step 2<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: GSSAPI client step 2<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
ns-slapd[2596]: GSSAPI server step 3<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: LDAP error: Invalid credentials:
bind to LDAP server failed<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: couldn't establish connection in
LDAP connection pool: permission denied<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: dynamic database 'ipa'
configuration failed: permission denied<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: loading configuration: permission
denied<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
named-pkcs11[3948]: exiting (due to fatal error)<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
systemd[1]: named-pkcs11.service: control process
exited, code=exited status=1<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
systemd[1]: Failed to start Berkeley Internet Name
Domain (DNS) with native PKCS#11.<br>
-- Subject: Unit named-pkcs11.service has failed<br>
-- Defined-By: systemd<br>
-- Support: <a href="http://lists.freedesktop.org/mailman/listinfo/systemd-devel" target="_blank">http://lists.freedesktop.org/m<wbr>ailman/listinfo/systemd-devel</a><br>
--<br>
-- Unit named-pkcs11.service has failed.<br>
--<br>
-- The result is failed.<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
systemd[1]: Unit named-pkcs11.service entered failed
state.<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
systemd[1]: named-pkcs11.service failed.<br>
Jan 04 15:48:42 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.emerl<wbr>yn.com</a>
polkitd[949]: Unregistered Authentication Agent for
unix-process:3936:380486 (system bus name :1.59,
object path /org/freedesktop/Policy<br>
<br>
</div>
Here are the last four entries of
/var/log/dirsrv/slapd-*/access |grep ipa-dnskeysyncdcat:<br>
<br>
[04/Jan/2017:15:28:37.<wbr>463224739 -0500] conn=5 op=1129
SRCH base="dc=internal,dc=emerlyn,<wbr>dc=com" scope=2
filter="(&(|(objectClass=<wbr>krbprincipalaux)(objectClass=<wbr>krbprincipal)(objectClass=<wbr>ipakrbprincipal))(|(<wbr>ipaKrbPrincipalAlias=ipa-<wbr>dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM" target="_blank">id-management-2.<wbr>internal.emerlyn.com@INTERNAL.<wbr>EMERLYN.COM</a>)(krbPrincipalName:<wbr>caseIgnoreIA5Match:=ipa-<wbr>dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM" target="_blank">id-management-2.<wbr>internal.emerlyn.com@INTERNAL.<wbr>EMERLYN.COM</a>)))"
attrs="krbPrincipalName krbCanonicalName krbUPEnabled
krbPrincipalKey krbTicketPolicyReference
krbPrincipalExpiration krbPasswordExpiration
krbPwdPolicyReference krbPrincipalType krbPwdHistory
krbLastPwdChange krbPrincipalAliases
krbLastSuccessfulAuth krbLastFailedAuth
krbLoginFailedCount krbPrincipalAuthInd krbExtraData
krbLastAdminUnlock krbObjectReferences krbTicketFlags
krbMaxTicketLife krbMaxRenewableAge nsAccountLock
passwordHistory ipaKrbAuthzData ipaUserAuthType
ipatokenRadiusConfigLink objectClass"<br>
[04/Jan/2017:15:28:37.<wbr>464739661 -0500] conn=5 op=1133
SRCH base="krbprincipalname=ipa-<wbr>dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM" target="_blank">id-management-2.<wbr>internal.emerlyn.com@INTERNAL.<wbr>EMERLYN.COM</a>,cn=services,cn=<wbr>accounts,dc=internal,dc=<wbr>emerlyn,dc=com"
scope=0 filter="(objectClass=*)" attrs="objectClass uid
cn fqdn gidNumber krbPrincipalName krbCanonicalName
krbTicketPolicyReference krbPrincipalExpiration
krbPasswordExpiration krbPwdPolicyReference
krbPrincipalType krbLastPwdChange krbPrincipalAliases
krbLastSuccessfulAuth krbLastFailedAuth
krbLoginFailedCount krbLastAdminUnlock krbTicketFlags
ipaNTSecurityIdentifier ipaNTLogonScript
ipaNTProfilePath ipaNTHomeDirectory
ipaNTHomeDirectoryDrive"<br>
[04/Jan/2017:15:28:37.<wbr>465851372 -0500] conn=5 op=1134
MOD dn="krbprincipalname=ipa-<wbr>dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM" target="_blank">id-management-2.<wbr>internal.emerlyn.com@INTERNAL.<wbr>EMERLYN.COM</a>,cn=services,cn=<wbr>accounts,dc=internal,dc=<wbr>emerlyn,dc=com"<br>
[04/Jan/2017:15:28:37.<wbr>474974775 -0500] conn=6 op=1372
SRCH base="dc=internal,dc=emerlyn,<wbr>dc=com" scope=2
filter="(&(|(objectClass=<wbr>krbprincipalaux)(objectClass=<wbr>krbprincipal))(<wbr>krbPrincipalName=ipa-<wbr>dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@INTERNAL.EMERLYN.COM" target="_blank">id-management-2.<wbr>internal.emerlyn.com@INTERNAL.<wbr>EMERLYN.COM</a>))"
attrs="krbPrincipalName krbCanonicalName krbUPEnabled
krbPrincipalKey krbTicketPolicyReference
krbPrincipalExpiration krbPasswordExpiration
krbPwdPolicyReference krbPrincipalType krbPwdHistory
krbLastPwdChange krbPrincipalAliases
krbLastSuccessfulAuth krbLastFailedAuth
krbLoginFailedCount krbPrincipalAuthInd krbExtraData
krbLastAdminUnlock krbObjectReferences krbTicketFlags
krbMaxTicketLife krbMaxRenewableAge nsAccountLock
passwordHistory ipaKrbAuthzData ipaUserAuthType
ipatokenRadiusConfigLink objectClass"<br>
[04/Jan/2017:15:28:37.<wbr>482436172 -0500] conn=281 op=2
RESULT err=0 tag=97 nentries=0 etime=0
dn="krbprincipalname=ipa-<wbr>dnskeysyncd/<a href="mailto:id-management-2.internal.emerlyn.com@internal.emerlyn.com" target="_blank">id-management-2.<wbr>internal.emerlyn.com@internal.<wbr>emerlyn.com</a>,cn=services,cn=<wbr>accounts,dc=internal,dc=<wbr>emerlyn,dc=com"<br>
<br>
</div>
My environment:<br>
</div>
Freeipa 4.2.0<br>
</div>
OS is Centos 7.2<br>
<br>
</div>
<div>This is a secondary replica (master) and the other replica
can be pinged but nslookup and dig fail to provide results
even though the values are in the /etc/hosts file:<br>
<br>
127.0.0.1 localhost localhost.localdomain localhost4
localhost4.localdomain4<br>
::1 localhost localhost.localdomain localhost6
localhost6.localdomain6<br>
10.72.100.16 <a href="http://id-management-1.internal.emerlyn.com" target="_blank">id-management-1.internal.<wbr>emerlyn.com</a><br>
10.73.100.31 <a href="http://id-management-2.internal.emerlyn.com" target="_blank">id-management-2.internal.<wbr>emerlyn.com</a><br>
<br>
</div>
<div><br>
</div>
<div>Any assistance is in solving this would be greatly
appreciated and thanks for both the great product and the
support already provided.<br>
<br>
</div>
<div>Jeff<br>
</div>
<div><br>
</div>
</div>
<br>
<fieldset class="gmail-m_-7480147556481762824mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<br>
Hello,<br>
<br>
what contains the /etc/sysconfig/dirsrv file<br>
<br>
can you kinit as DNS?<br>
<br>
kinit -kt /etc/named.keytab DNS/$HOSTNAME<br>
<br>
Martin^2<br>
<br>
</div>
</blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div><br></div><br></div></div>
</div></div></div>