Ah i see.. /usr/local/samba/private/dns.keytab Thats the "old" path.. Your using bind9 you should have: /usr/local/samba/bind-dns/dns.keytab dont forget to set the needed rights on bind-dns folder. On road, cant look deeper in it. Greetz, Louis> -----Oorspronkelijk bericht----- > Van: Rommel Rodriguez Toirac [mailto:rommelrt at nauta.cu] > Verzonden: vrijdag 20 november 2020 14:35 > Aan: L.P.H. van Belle > CC: Lista samba4 > Onderwerp: RE: [Samba] dnsupdate failed with TKEY is unaceptable > > El 20 de noviembre de 2020 2:22:45 GMT-05:00, "L.P.H. van > Belle" <belle at bazuin.nl> escribi?: > >I suggest you read : > >https://wiki.samba.org/index.php/Dns_tkey_negotiategss:_TKEY_ > is_unacceptable > > > > > Hello; > I read the URL sugessted. There exist a Kerberos principal; > there exist the bind AD account and the files permission in > /usr/local/samba/private/dns.keytab are correct. > > This are the result of commands suggested to run: > > > ?[root at gtmad1 samba]# klist -k /usr/local/samba/private/dns.keytab ? > Keytab name: FILE:/usr/local/samba/private/dns.keytab > KVNO Principal > ---- > -------------------------------------------------------------- > ------------ > ??1 DNS/gtmad1.gtm.onat.gob.cu at GTM.ONAT.GOB.CU > ??1 dns-gtmad1 at GTM.ONAT.GOB.CU > ??1 DNS/gtmad1.gtm.onat.gob.cu at GTM.ONAT.GOB.CU > ??1 dns-gtmad1 at GTM.ONAT.GOB.CU > ??1 DNS/gtmad1.gtm.onat.gob.cu at GTM.ONAT.GOB.CU > ??1 dns-gtmad1 at GTM.ONAT.GOB.CU > > > [root at gtmad1 samba]# ldbsearch -H > /usr/local/samba/private/sam.ldb 'cn=dns-GTMAD1' dn > # record 1 > dn: CN=dns-gtmad1,CN=Users,DC=gtm,DC=onat,DC=gob,DC=cu > > # Referral > ref: > ldap://gtm.onat.gob.cu/CN=Configuration,DC=gtm,DC=onat,DC=gob,DC=cu > > # Referral > ref: > ldap://gtm.onat.gob.cu/DC=DomainDnsZones,DC=gtm,DC=onat,DC=gob,DC=cu > > # Referral > ref: > ldap://gtm.onat.gob.cu/DC=ForestDnsZones,DC=gtm,DC=onat,DC=gob,DC=cu > > # returned 4 records > # 1 entries > # 3 referrals > > [root at gtmad1 samba]# ls -l /usr/local/samba/private/dns.keytab > -rw-r----- 2 root named 517 nov 17 15:09 > /usr/local/samba/private/dns.keytab > > > [root at gtmad1 samba]# cat /etc/named.conf > named.conf ??????named.conf_back ?? > [root at gtmad1 samba]# cat /etc/named.conf > # Global Configuration Options > options { > > ???auth-nxdomain yes; > ???version "Parametro no soportado"; > ???directory "/var/named"; > ???notify no; > ???empty-zones-enable no; > ???dnssec-validation no; > ???dnssec-enable no; > ???dnssec-lookaside no; > ???listen-on-v6 { none; }; > ???listen-on port 53 { 192.168.41.18; 127.0.0.1; }; > > ???# IP addresses and network ranges allowed to query the DNS server: > ???allow-query { > ???????127.0.0.1; > ???????192.168.41.0/24; > ???}; > ???allow-query-cache { > ???????127.0.0.1; > ???????192.168.41.0/24; > ???}; > > ???# IP addresses and network ranges allowed to run recursive queries: > ???# (Zones not served by this DNS server) > ???allow-recursion { > ???????127.0.0.1; > ???????192.168.41.0/24; > ???}; > > ???# Forward queries that can not be answered from own zones > ???# to these DNS servers: > ???forwarders { > ???????10.10.8.2; > ???}; > > ???# Disable zone transfers ? > ???allow-transfer { > ???????none; > ???}; > ??? > ??tkey-gssapi-keytab "/usr/local/samba/private/dns.keytab"; > ??minimal-responses yes; > > }; > > # Root Servers > # (Required for recursive DNS queries) > #zone "." { > # ??type hint; > # ??file "named.root"; > #}; > > # localhost zone > zone "localhost" { > ???type master; > ???file "master/localhost.zone"; > }; > > # 127.0.0. zone. > zone "0.0.127.in-addr.arpa" { > ???type master; > ???file "master/0.0.127.zone"; > }; > > include "/usr/local/samba/bind-dns/named.conf"; > > -- > Rommel Rodriguez Toirac > rommelrt at nauta.cu > >
On 20/11/2020 13:40, L.P.H. van Belle via samba wrote:> Ah i see.. > > /usr/local/samba/private/dns.keytab > Thats the "old" path.. > > Your using bind9 you should have: > /usr/local/samba/bind-dns/dns.keytab > > dont forget to set the needed rights on bind-dns folder. > On road, cant look deeper in it.I pointed all that out to the OP and advised him to move the keytab to the bind-dns dir, all of which he seemingly chose to ignore, so I gave up. Rowland
Rommel Rodriguez Toirac
2020-Nov-20 15:04 UTC
[Samba] dnsupdate failed with TKEY is unaceptable
El 20 de noviembre de 2020 8:58:17 GMT-05:00, Rowland penny via samba <samba at lists.samba.org> escribi?:>On 20/11/2020 13:40, L.P.H. van Belle via samba wrote: >> Ah i see.. >> >> /usr/local/samba/private/dns.keytab >> Thats the "old" path.. >> >> Your using bind9 you should have: >> /usr/local/samba/bind-dns/dns.keytab >> >> dont forget to set the needed rights on bind-dns folder. >> On road, cant look deeper in it. > >I pointed all that out to the OP and advised him to move the keytab to >the bind-dns dir, all of which he seemingly chose to ignore, so I gave >up. > >RowlandHello; ?Thanks for writeme back. I make the changes to the /etc/named.conf and work fine everything. In both directories there is the file dns.keytab (I wrote to the list saying so) [root at gtmad1 samba]# ls /usr/local/samba/bind-dns/ dns dns.keytab named.conf named.txt [root at gtmad1 samba]# ls /usr/local/samba/private/ dns.keytab dns_update_list hklm.ldb krb5.conf ldap_priv netlogon_creds_cli.tdb sam.ldb schannel_store.tdb secrets.ldb share.ldb spn_update_list dns_update_cache encrypted_secrets.key idmap.ldb ldapi msg.sock privilege.ldb sam.ldb.d secrets.keytab secrets.tdb smbd.tmp tls The content is the same. The file permissions are correct in both directories. [root at gtmad1 samba]# ls -l /usr/local/samba/private/dns.keytab -rw-r ----- 2 root named 517 Nov 17 3:09 PM /usr/local/samba/private/dns.keytab [root at gtmad1 samba]# ls -l /usr/local/samba/bind-dns/dns.keytab -rw-r ----- 2 root named 517 Nov 17 3:09 PM /usr/local/samba/bind-dns/dns.keytab ?But the directory permission are different, this was my problem. I?used the file from that directory (/usr/local/samba/private/) because it says so in https://wiki.samba.org/index.php/Dns_tkey_negotiategss:_TKEY_is_unacceptable ?I?apologize if I did not understand well what was suggested to me ?I change the parameter?tkey-gssapi-keytab "/usr/local/samba/private/dns.keytab" to "/usr/local/samba/bind-dns/dns.keytab"?in /etc/named.conf and samba 4.13.2 start correct. Make the test to the DNS to resolve the my domain and there is the two samba4 DC listed: [root at gtmad1 samba]# host -t A gtm.onat.gob.cu localhost Using domain server: Name: localhost Address: 127.0.0.1#53 Aliases: ? gtm.onat.gob.cu has address 192.168.41.18 gtm.onat.gob.cu has address 192.168.41.17 ?And the dnsupdate work fine too: [root at gtmad1 etc]# samba_dnsupdate --verbose --all-names IPs: ['192.168.41.18'] force update: A gtmad1.gtm.onat.gob.cu 192.168.41.18 force update: CNAME 03d9f4b0-72a5-47cd-b572-a33ae30b73ce._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu force update: NS gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu force update: NS _msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu force update: A gtm.onat.gob.cu 192.168.41.18 force update: SRV _ldap._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _ldap._tcp.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _ldap._tcp.40164216-0124-4ad9-9fd9-ef6fbf7cdb45.domains._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _kerberos._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 force update: SRV _kerberos._udp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 force update: SRV _kerberos._tcp.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 force update: SRV _kpasswd._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 464 force update: SRV _kpasswd._udp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 464 force update: SRV _ldap._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _kerberos._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 force update: SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 force update: A gc._msdcs.gtm.onat.gob.cu 192.168.41.18 force update: SRV _gc._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 force update: SRV _ldap._tcp.gc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 force update: SRV _gc._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 force update: SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 force update: A DomainDnsZones.gtm.onat.gob.cu 192.168.41.18 force update: SRV _ldap._tcp.DomainDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: A ForestDnsZones.gtm.onat.gob.cu 192.168.41.18 force update: SRV _ldap._tcp.ForestDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 force update: SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 28 DNS updates and 0 DNS deletes needed Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ update(nsupdate): A gtmad1.gtm.onat.gob.cu 192.168.41.18 Calling nsupdate for A gtmad1.gtm.onat.gob.cu 192.168.41.18 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: gtmad1.gtm.onat.gob.cu. 900 ????IN ?????A ??????192.168.41.18 ? update(nsupdate): CNAME 03d9f4b0-72a5-47cd-b572-a33ae30b73ce._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu Calling nsupdate for CNAME 03d9f4b0-72a5-47cd-b572-a33ae30b73ce._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: 03d9f4b0-72a5-47cd-b572-a33ae30b73ce._msdcs.gtm.onat.gob.cu. 900 IN CNAME gtmad1.gtm.onat.gob.cu. ? update(nsupdate): NS gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu Calling nsupdate for NS gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: gtm.onat.gob.cu. ???????900 ????IN ?????NS ?????gtmad1.gtm.onat.gob.cu. ? update(nsupdate): NS _msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu Calling nsupdate for NS _msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _msdcs.gtm.onat.gob.cu. 900 ????IN ?????NS ?????gtmad1.gtm.onat.gob.cu. ? update(nsupdate): A gtm.onat.gob.cu 192.168.41.18 Calling nsupdate for A gtm.onat.gob.cu 192.168.41.18 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: gtm.onat.gob.cu. ???????900 ????IN ?????A ??????192.168.41.18 ? update(nsupdate): SRV _ldap._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.gtm.onat.gob.cu. 900 IN ?????SRV ????0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.dc._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.40164216-0124-4ad9-9fd9-ef6fbf7cdb45.domains._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.40164216-0124-4ad9-9fd9-ef6fbf7cdb45.domains._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.40164216-0124-4ad9-9fd9-ef6fbf7cdb45.domains._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kerberos._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 Calling nsupdate for SRV _kerberos._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kerberos._tcp.gtm.onat.gob.cu. 900 IN ?SRV ????0 100 88 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kerberos._udp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 Calling nsupdate for SRV _kerberos._udp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kerberos._udp.gtm.onat.gob.cu. 900 IN ?SRV ????0 100 88 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kerberos._tcp.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 Calling nsupdate for SRV _kerberos._tcp.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kerberos._tcp.dc._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 88 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kpasswd._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 464 Calling nsupdate for SRV _kpasswd._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 464 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kpasswd._tcp.gtm.onat.gob.cu. 900 IN ??SRV ????0 100 464 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kpasswd._udp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 464 Calling nsupdate for SRV _kpasswd._udp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 464 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kpasswd._udp.gtm.onat.gob.cu. 900 IN ??SRV ????0 100 464 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kerberos._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 Calling nsupdate for SRV _kerberos._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kerberos._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu. 900 IN SRV 0 100 88 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 Calling nsupdate for SRV _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 88 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 88 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): A gc._msdcs.gtm.onat.gob.cu 192.168.41.18 Calling nsupdate for A gc._msdcs.gtm.onat.gob.cu 192.168.41.18 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: gc._msdcs.gtm.onat.gob.cu. 900 ?IN ?????A ??????192.168.41.18 ? update(nsupdate): SRV _gc._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 Calling nsupdate for SRV _gc._tcp.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _gc._tcp.gtm.onat.gob.cu. 900 ??IN ?????SRV ????0 100 3268 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.gc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 Calling nsupdate for SRV _ldap._tcp.gc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.gc._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 3268 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _gc._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 Calling nsupdate for SRV _gc._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _gc._tcp.Default-First-Site-Name._sites.gtm.onat.gob.cu. 900 IN SRV 0 100 3268 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 Calling nsupdate for SRV _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 3268 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.gtm.onat.gob.cu. 900 IN SRV 0 100 3268 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): A DomainDnsZones.gtm.onat.gob.cu 192.168.41.18 Calling nsupdate for A DomainDnsZones.gtm.onat.gob.cu 192.168.41.18 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: DomainDnsZones.gtm.onat.gob.cu. 900 IN ?A ??????192.168.41.18 ? update(nsupdate): SRV _ldap._tcp.DomainDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.DomainDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.DomainDnsZones.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): A ForestDnsZones.gtm.onat.gob.cu 192.168.41.18 Calling nsupdate for A ForestDnsZones.gtm.onat.gob.cu 192.168.41.18 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: ForestDnsZones.gtm.onat.gob.cu. 900 IN ?A ??????192.168.41.18 ? update(nsupdate): SRV _ldap._tcp.ForestDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.ForestDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.ForestDnsZones.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. ? update(nsupdate): SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 Calling nsupdate for SRV _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.gtm.onat.gob.cu gtmad1.gtm.onat.gob.cu 389 (add) Successfully obtained Kerberos ticket to DNS/gtmad1.gtm.onat.gob.cu as GTMAD1$ Outgoing update query: ;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: ?????0 ;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 ;; UPDATE SECTION: _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.gtm.onat.gob.cu. 900 IN SRV 0 100 389 gtmad1.gtm.onat.gob.cu. -- Rommel Rodriguez Toirac rommelrt at nauta.cu