Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Message from discussion Internal DNS - TTL enforcement for dynamic updates
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Dmitry Khromov  
View profile  
 More options Nov 1 2012, 4:20 pm
Newsgroups: linux.samba
From: Dmitry Khromov <icechr...@gmail.com>
Date: Thu, 01 Nov 2012 21:20:03 +0100
Local: Thurs, Nov 1 2012 4:20 pm
Subject: Re: [Samba] Internal DNS - TTL enforcement for dynamic updates

> According to the dump, Windows just doesn't try to send a signed update after receiveng TKEY. However, this host had succeded at least once today. Rebooted it, now no updates happen, but Samba started to say:
> [2012/11/01 14:32:30,  1] ../source4/dns_server/dns_server.c:150(dns_process_send)
>   Failed to verify TSIG!

Things get even more interesting. Looks like in fact there are two problems.
I have another two dumps, illustrating the original issue I was talking about. In dump 1 the host is just booted and the record from the previous boot exists. As you can see Samba says SERVFAIL. debug level = 1 says:
[2012/11/01 23:59:44,  1] ../source4/dns_server/dns_query.c:501(handle_tkey)
  Tkey handshake completed
[2012/11/01 23:59:48,  1] ../source4/dns_server/dns_update.c:672(handle_updates)
  update count is 3
[2012/11/01 23:59:48,  1] ../source4/dns_server/dns_update.c:672(handle_updates)
  update count is 3
[2012/11/01 23:59:48,  1] ../source4/dns_server/dns_update.c:672(handle_updates)
  update count is 3
[2012/11/01 23:59:48,  1] ../source4/dns_server/dns_update.c:672(handle_updates)
  update count is 3

In dump 2 I have just deleted the record. As you can see, only the first update succeeds, then - SERVFAIL again.

P.S. Just in case you're suprised with the updates frequency - it's what we really have in production on "parking" subnets, as a workaround for the Windows 7 DHCPINFORM on non-authoritative subnets problem.

--
Best regards,
Dmitry Khromov

--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.