• Как починить обновление Bind9_DLZ в SAMBA4?

    nordz0r
    @nordz0r Автор вопроса
    На samba_internal

    samba_dnsupdate --verbose -d8

    1 DNS updates and 0 DNS deletes needed
    ldb_wrap open of secrets.ldb
    Received smb_krb5 packet of length 314
    Received smb_krb5 packet of length 177
    GENSEC backend 'gssapi_spnego' registered
    GENSEC backend 'gssapi_krb5' registered
    GENSEC backend 'gssapi_krb5_sasl' registered
    GENSEC backend 'spnego' registered
    GENSEC backend 'schannel' registered
    GENSEC backend 'naclrpc_as_system' registered
    GENSEC backend 'sasl-EXTERNAL' registered
    GENSEC backend 'ntlmssp' registered
    GENSEC backend 'ntlmssp_resume_ccache' registered
    GENSEC backend 'http_basic' registered
    GENSEC backend 'http_ntlm' registered
    GENSEC backend 'http_negotiate' registered
    GENSEC backend 'krb5' registered
    GENSEC backend 'fake_gssapi_krb5' registered
    Starting GENSEC mechanism gssapi_krb5_sasl
    Ticket in credentials cache for BELUGA$@domain.ru will expire in 36000 secs
    Successfully obtained Kerberos ticket to DNS/Beluga.domain.ru as BELUGA$
    update(nsupdate): SRV _ldap._tcp.dc._msdcs.domain.ru Beluga.domain.ru 389
    Calling nsupdate for SRV _ldap._tcp.dc._msdcs.domain.ru Beluga.domain.ru 389 (add)
    Starting GENSEC mechanism gssapi_krb5_sasl
    GSSAPI credentials for BELUGA$@domain.ru will expire in 36000 secs
    Successfully obtained Kerberos ticket to DNS/Beluga.domain.ru as BELUGA$
    Outgoing update query:
    ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0
    ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
    ;; UPDATE SECTION:
    _ldap._tcp.dc._msdcs.domain.ru. 900 IN SRV 0 100 389 Beluga.domain.ru.

    ; TSIG error with server: tsig indicates error
    update failed: NOTAUTH(BADSIG)
    Failed nsupdate: 2
    Failed update of 1 entries
    Ответ написан