Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - dwalker

Pages: [1]
1
If I make a AD change on the Zentyal BDC the change does not get sync'd to the Windows PDC, but it does sync to another Samba 4 BDC I have set up at another site.  Very odd, any ideas?

2
I posted this as a ticked, but I probably should have posted it here first. (I googled and it was showing me tickets so I just added a new one.) Anyway, Samba fails to start because /etc/init.d/bind9 restart fails.  Here is the info from the ticket:

 From zentyal.log:


 {{{
 2013/11/03 19:25:47 INFO> Service.pm:986
 EBox::Module::Service::restartService - Restarting service for module:
 samba
 2013/11/03 19:25:48 INFO> Provision.pm:818
 EBox::Samba::Provision::checkAddress - Resolving sentinel.xxx.xxx to an IP
 address
 2013/11/03 19:25:48 INFO> Provision.pm:838
 EBox::Samba::Provision::checkAddress - The DC sentinel.xxx.xxx has been
 resolved to 192.168.2.3
 2013/11/03 19:25:48 INFO> Provision.pm:841
 EBox::Samba::Provision::checkAddress - Checking reverse DNS resolution of
 '192.168.2.3'...
 2013/11/03 19:25:48 INFO> Provision.pm:865
 EBox::Samba::Provision::checkAddress - The IP address 192.168.2.3 does not
 have associated PTR record
 2013/11/03 19:25:48 INFO> Provision.pm:764
 EBox::Samba::Provision::checkServerReachable - Checking if AD server
 '192.168.2.3' is online...
 2013/11/03 19:25:48 INFO> Provision.pm:874
 EBox::Samba::Provision::checkFunctionalLevels - Checking forest and domain
 functional levels...
 2013/11/03 19:25:48 INFO> Provision.pm:783
 EBox::Samba::Provision::checkLocalRealmAndDomain - Checking local domain
 and realm...
 2013/11/03 19:25:48 INFO> Provision.pm:942
 EBox::Samba::Provision::__ANON__ - Checking clock skew with AD server...
 2013/11/03 19:25:48 INFO> Provision.pm:963
 EBox::Samba::Provision::checkClockSkew - Clock skew below two minutes,
 should be enought.
 2013/11/03 19:25:48 INFO> Provision.pm:683
 EBox::Samba::Provision::checkDnsZonesInMainPartition - Checking for old
 DNS zones stored in main domain partition...
 2013/11/03 19:25:48 INFO> Provision.pm:730
 EBox::Samba::Provision::checkForestDomains - Checking number of domains
 inside forest...
 2013/11/03 19:25:48 INFO> Provision.pm:902
 EBox::Samba::Provision::checkTrustDomainObjects - Checking for domain
 trust relationships...
 2013/11/03 19:25:48 INFO> Provision.pm:1004
 EBox::Samba::Provision::checkADServerSite - Checking the site where the
 specified server is located
 2013/11/03 19:25:48 INFO> Provision.pm:1012
 EBox::Samba::Provision::checkADServerSite - The specified server has been
 located at site named Default-First-Site-Name
 2013/11/03 19:25:48 INFO> Provision.pm:1029
 EBox::Samba::Provision::checkADNebiosName - Checking domain netbios
 name...
 2013/11/03 19:25:48 INFO> Provision.pm:1252
 EBox::Samba::Provision::__ANON__ - Joining to domain 'xxx.xxx' as DC
 2013/11/03 19:25:48 INFO> Provision.pm:1265
 EBox::Samba::Provision::__ANON__ - Trying to get a kerberos ticket for
 principal 'Administrator@XXX.XXX'
 2013/11/03 19:25:49 INFO> Provision.pm:1274
 EBox::Samba::Provision::__ANON__ - Executing domain join
 2013/11/03 19:26:36 INFO> Provision.pm:283
 EBox::Samba::Provision::setupDNS - Setting up DNS
 2013/11/03 19:26:36 INFO> Base.pm:229 EBox::Module::Base::save -
 Restarting service for module: dns
 2013/11/03 19:26:39 ERROR> Sudo.pm:231 EBox::Sudo::_rootError - root
 command /etc/init.d/bind9 restart failed.
 Error output:
 Command output:  * Stopping domain name service... bind9
  waiting for pid 3488 to die
     ...done.
   * Starting domain name service... bind9
     ...fail!
 .
 Exit value: 1 at /usr/share/perl5/Error.pm line 182
         Error::throw('EBox::Exceptions::Sudo::Command', 'cmd',
 '/etc/init.d/bind9 restart', 'output', 'ARRAY(0x7f3a1a6754e8)', 'error',
 'ARRAY(0x7f3a158db410)', 'exitValue', 1, ...) called at
 /usr/share/perl5/EBox/Sudo.pm line 231
         EBox::Sudo::_rootError('/usr/bin/sudo -p sudo:
 /var/lib/zentyal/tmp/Y5AErDfv1e.cmd 2>...', '/etc/init.d/bind9 restart',
 256, 'ARRAY(0x7f3a1a6754e8)', 'ARRAY(0x7f3a158db410)') called at
 /usr/share/perl5/EBox/Sudo.pm line 201
         EBox::Sudo::_root(1, '/etc/init.d/bind9 restart') called at
 /usr/share/perl5/EBox/Sudo.pm line 152
         EBox::Sudo::root('/etc/init.d/bind9 restart') called at
 /usr/share/perl5/EBox/Module/Service.pm line 757
 EBox::Module::Service::_startDaemon('EBox::DNS=HASH(0x7f3a19067988)',
 'HASH(0x7f3a1a6f4cf8)') called at /usr/share/perl5/EBox/Module/Service.pm
 line 796
 EBox::Module::Service::_manageService('EBox::DNS=HASH(0x7f3a19067988)',
 'start') called at /usr/share/perl5/EBox/Module/Service.pm line 821
 EBox::Module::Service::_startService('EBox::DNS=HASH(0x7f3a19067988)')
 called at /usr/share/perl5/EBox/Module/Service.pm line 1017
 EBox::Module::Service::_enforceServiceState('EBox::DNS=HASH(0x7f3a19067988)')
 called at /usr/share/perl5/EBox/Module/Service.pm line 968
 EBox::Module::Service::_regenConfig('EBox::DNS=HASH(0x7f3a19067988)')
 called at /usr/share/perl5/EBox/Module/Base.pm line 232
         EBox::Module::Base::save('EBox::DNS=HASH(0x7f3a19067988)') called
 at /usr/share/perl5/EBox/Samba/Provision.pm line 296
 EBox::Samba::Provision::setupDNS('EBox::Samba::Provision=HASH(0x7f3a1a4519e0)')
 called at /usr/share/perl5/EBox/Samba/Provision.pm line 1296
 EBox::Samba::Provision::provisionADC('EBox::Samba::Provision=HASH(0x7f3a1a4519e0)')
 called at /usr/share/perl5/EBox/Samba/Provision.pm line 340
 EBox::Samba::Provision::provision('EBox::Samba::Provision=HASH(0x7f3a1a4519e0)')
 called at /usr/share/perl5/EBox/Samba.pm line 1050
         EBox::Samba::_setConf('EBox::Samba=HASH(0x7f3a168d1a88)',
 'restart', 1) called at /usr/share/perl5/EBox/Module/Base.pm line 977
 EBox::Module::Base::_regenConfig('EBox::Samba=HASH(0x7f3a168d1a88)',
 'restart', 1) called at /usr/share/perl5/EBox/Module/Service.pm line 961
 EBox::Module::Service::_regenConfig('EBox::Samba=HASH(0x7f3a168d1a88)',
 'restart', 1) called at /usr/share/perl5/EBox/Module/Service.pm line 988
 EBox::Module::Service::restartService('EBox::Samba=HASH(0x7f3a168d1a88)')
 called at /usr/share/perl5/EBox/SysInfo/CGI/RestartService.pm line 55
 EBox::SysInfo::CGI::RestartService::_process('EBox::SysInfo::CGI::RestartService=HASH(0x7f3a1a464638)')
 called at /usr/share/perl5/EBox/CGI/Base.pm line 279
 EBox::CGI::Base::run('EBox::SysInfo::CGI::RestartService=HASH(0x7f3a1a464638)')
 called at /usr/share/perl5/EBox/CGI/Run.pm line 85
         EBox::CGI::Run::run('EBox::CGI::Run', 'SysInfo/RestartService')
 called at /usr/share/zentyal/cgi/ebox.cgi line 36
 ModPerl::ROOT::ModPerl::Registry::usr_share_zentyal_cgi_ebox_2ecgi::handler('Apache2::RequestRec=SCALAR(0x7f3a1a464848)')
 called at /usr/lib/perl5/ModPerl/RegistryCooker.pm line 204
         eval {...} called at /usr/lib/perl5/ModPerl/RegistryCooker.pm line
 204
 ModPerl::RegistryCooker::run('ModPerl::Registry=HASH(0x7f3a1a441988)')
 called at /usr/lib/perl5/ModPerl/RegistryCooker.pm line 170
 ModPerl::RegistryCooker::default_handler('ModPerl::Registry=HASH(0x7f3a1a441988)')
 called at /usr/lib/perl5/ModPerl/Registry.pm line 31
         ModPerl::Registry::handler('ModPerl::Registry',
 'Apache2::RequestRec=SCALAR(0x7f3a1a464848)') called at -e line 0
         eval {...} called at -e line 0
 2013/11/03 19:26:39 INFO> Provision.pm:283
 EBox::Samba::Provision::setupDNS - Setting up DNS
 2013/11/03 19:26:39 INFO> Base.pm:229 EBox::Module::Base::save -
 Restarting service for module: dns
 2013/11/03 19:26:42 ERROR> Service.pm:991 EBox::Module::Service::__ANON__
 - Error restarting service: root command /etc/init.d/bind9 restart failed.
 Error output:
 Command output:  * Stopping domain name service... bind9
  waiting for pid 3488 to die
     ...done.
   * Starting domain name service... bind9
     ...fail!
 .
 Exit value: 1
 2013/11/03 19:26:42 ERROR> RestartService.pm:67
 EBox::SysInfo::CGI::RestartService::__ANON__ - Restart of File Sharing
 from dashboard failed: root command /etc/init.d/bind9 restart failed.
 Error output:
 Command output:  * Stopping domain name service... bind9
  waiting for pid 3488 to die
     ...done.
   * Starting domain name service... bind9
     ...fail!
 .
 Exit value: 1
 }}}

 Not sure what's going on.  I've tried everything I can think of.  Removing
 and adding modules, adding it as a DC (works) then changing it to an
 additional. Reinstalling.  Stopping and starting things from the command
 line, rebooting, etc.  Can't figure out what's going wrong.
 /etc/init.d/bind9 restart just fails from the script, but not if I issue
 that same command from the CLI.  But that doesn't get the Domain Services
 started.   What's going on?

 Here is the relevant output from egrep bind syslog


 {{{
 Nov  3 19:26:38 testdc named[6275]: starting BIND 9.8.1-P1 -u bind -4
 Nov  3 19:26:38 testdc named[6275]: built with '--prefix=/usr' '--
 mandir=/usr/share/man' '--infodir=/usr/share/info' '--
 sysconfdir=/etc/bind' '--localstatedir=/var' '--enable-threads' '--enable-
 largefile' '--with-libtool' '--enable-shared' '--enable-static' '--with-
 openssl=/usr' '--with-gssapi=/usr' '--with-gnu-ld' '--with-geoip=/usr'
 '--enable-ipv6' 'CFLAGS=-fno-strict-aliasing -DDIG_SIGCHASE -O2'
 'LDFLAGS=-Wl,-Bsymbolic-functions -Wl,-z,relro'
 'CPPFLAGS=-D_FORTIFY_SOURCE=2'
 Nov  3 19:26:38 testdc named[6275]: loading configuration from
 '/etc/bind/named.conf'
 Nov  3 19:26:38 testdc named[6275]: reading built-in trusted keys from
 file '/etc/bind/bind.keys'
 Nov  3 19:26:38 testdc named[6275]: samba_dlz: loading keys from file
 '/etc/bin /keys'
 Nov  3 19:26:39 testdc named[6371]: starting BIND 9.8.1-P1 -u bind -4
 Nov  3 19:26:39 testdc named[6371]: built with '--prefix=/usr' '--
 mandir=/usr/share/man' '--infodir=/usr/share/info' '--
 sysconfdir=/etc/bind' '--localstatedir=/var' '--enable-threads' '--enable-
 largefile' '--with-libtool' '--enable-shared' '--enable-static' '--with-
 openssl=/usr' '--with-gssapi=/usr' '--with-gnu-ld' '--with-geoip=/usr'
 '--enable-ipv6' 'CFLAGS=-fno-strict-aliasing -DDIG_SIGCHASE -O2'
 'LDFLAGS=-Wl,-Bsymbolic-functions -Wl,-z,relro'
 'CPPFLAGS=-D_FORTIFY_SOURCE=2'
 Nov  3 19:26:39 testdc named[6371]: loading configuration from
 '/etc/bind/named.conf'
 Nov  3 19:26:39 testdc named[6371]: reading built-in trusted keys from
 file '/etc/bind/bind.keys'
 Nov  3 19:26:39 testdc named[6371]: set up managed keys zone for view
 _default, file 'managed-keys.bind'

 }}}

 this is what I get in the syslog when I run the /etc/init.d/bind9 restart
 command from the CLI:


 {{{
 Nov  3 19:47:33 testdc named[8635]: received control channel command 'stop
 -p'
 Nov  3 19:47:33 testdc named[8635]: shutting down: flushing changes
 Nov  3 19:47:33 testdc named[8635]: stopping command channel on
 127.0.0.1#953
 Nov  3 19:47:33 testdc named[8635]: no longer listening on 127.0.0.1#53
 Nov  3 19:47:33 testdc named[8635]: no longer listening on 127.0.1.1#53
 Nov  3 19:47:33 testdc named[8635]: no longer listening on 192.168.2.50#53
 Nov  3 19:47:33 testdc named[8635]: exiting
 Nov  3 19:47:34 testdc named[8784]: starting BIND 9.8.1-P1 -u bind -4
 Nov  3 19:47:34 testdc named[8784]: built with '--prefix=/usr' '--
 mandir=/usr/share/man' '--infodir=/usr/share/info' '--
 sysconfdir=/etc/bind' '--localstatedir=/var' '--enable-threads' '--enable-
 largefile' '--with-libtool' '--enable-shared' '--enable-static' '--with-
 openssl=/usr' '--with-gssapi=/usr' '--with-gnu-ld' '--with-geoip=/usr'
 '--enable-ipv6' 'CFLAGS=-fno-strict-aliasing -DDIG_SIGCHASE -O2'
 'LDFLAGS=-Wl,-Bsymbolic-functions -Wl,-z,relro'
 'CPPFLAGS=-D_FORTIFY_SOURCE=2'
 Nov  3 19:47:34 testdc named[8784]: adjusted limit on open files from 4096
 to 1048576
 Nov  3 19:47:34 testdc named[8784]: found 2 CPUs, using 2 worker threads
 Nov  3 19:47:34 testdc named[8784]: using up to 4096 sockets
 Nov  3 19:47:34 testdc named[8784]: loading configuration from
 '/etc/bind/named.conf'
 Nov  3 19:47:34 testdc named[8784]: reading built-in trusted keys from
 file '/etc/bind/bind.keys'
 Nov  3 19:47:34 testdc named[8784]: using default UDP/IPv4 port range:
 [1024, 65535]
 Nov  3 19:47:34 testdc named[8784]: using default UDP/IPv6 port range:
 [1024, 65535]
 Nov  3 19:47:34 testdc named[8784]: no IPv6 interfaces found
 Nov  3 19:47:34 testdc named[8784]: listening on IPv4 interface lo,
 127.0.0.1#53
 Nov  3 19:47:34 testdc named[8784]: listening on IPv4 interface lo,
 127.0.1.1#53
 Nov  3 19:47:34 testdc named[8784]: listening on IPv4 interface eth0,
 192.168.2.50#53
 Nov  3 19:47:34 testdc named[8784]: generating session key for dynamic DNS
 Nov  3 19:47:34 testdc named[8784]: sizing zone task pool based on 25
 zones
 Nov  3 19:47:34 testdc named[8784]: set up managed keys zone for view
 _default, file 'managed-keys.bind'
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 254.169.IN-
 ADDR.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 2.0.192.IN-
 ADDR.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 100.51.198.IN-
 ADDR.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 113.0.203.IN-
 ADDR.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 255.255.255.255
 .IN-ADDR.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone:
 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone:
 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: D.F.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 8.E.F.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: 9.E.F.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: A.E.F.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone: B.E.F.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: automatic empty zone:
 8.B.D.0.1.0.0.2.IP6.ARPA
 Nov  3 19:47:34 testdc named[8784]: command channel listening on
 127.0.0.1#953
 Nov  3 19:47:34 testdc named[8784]: zone 0.in-addr.arpa/IN: loaded serial
 1
 Nov  3 19:47:34 testdc named[8784]: zone 10.in-addr.arpa/IN: loaded serial
 1
 Nov  3 19:47:34 testdc named[8784]: zone 127.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 16.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 17.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 18.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 19.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 20.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 21.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 22.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 23.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 24.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 25.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 26.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 27.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 28.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 29.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 30.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 31.172.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 168.192.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone 2.168.192.in-addr.arpa/IN: loaded
 serial 2013110319
 Nov  3 19:47:34 testdc named[8784]: zone 255.in-addr.arpa/IN: loaded
 serial 1
 Nov  3 19:47:34 testdc named[8784]: zone xxx.xxx/IN: loaded serial
 2013110319
 Nov  3 19:47:34 testdc named[8784]: zone localhost/IN: loaded serial 2
 Nov  3 19:47:34 testdc named[8784]: managed-keys-zone ./IN: loaded serial
 3
 Nov  3 19:47:34 testdc named[8784]: running
 }}}

 Help

Pages: [1]