ALT Linux Bugzilla
– Attachment 19399 Details for
Bug 55687
alterator-auth: Ошибки gensec_gse_client_prepare_ccache/kinit при введении клиента в домен Samba DC с BIND9_DLZ DNS
New bug
|
Search
|
[?]
|
Help
Register
|
Log In
[x]
|
Forgot Password
Login:
[x]
|
EN
|
RU
examples.md
examples.md (text/markdown), 10.97 KB, created by
Artem Varaksa
on 2025-08-21 19:00:49 MSK
(
hide
)
Description:
examples.md
Filename:
MIME Type:
Creator:
Artem Varaksa
Created:
2025-08-21 19:00:49 MSK
Size:
10.97 KB
patch
obsolete
>ÐÑÐ¸Ð¼ÐµÑ 1 (p11+387440.10 / sisyphus): (2) gensec dc2, success >----------------------------------- > >Ðоманда запÑÑена в 13:22:18, завеÑÑена в 13:22:24: > >stderr: >> gensec_gse_client_prepare_ccache: Kinit for CLIENT$@samba.testdomain to access ldap/dc2.samba.testdomain failed: Client not found in Kerberos database: NT_STATUS_LOGON_FAILURE >> Successfully registered hostname with DNS > >stdout: >> Using short domain name -- SAMBA >> Joined 'CLIENT' to dns domain 'samba.testdomain' > > >ÐÑи ÑÑом на DC в journalctl в 13:22:24: > >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: starting transaction on zone samba.testdomain >> авг 21 13:22:24 dc.samba.testdomain named[1275]: client @0x7f305b9a4898 <client-ipv4>#39330: updating zone 'samba.testdomain/NONE': update unsuccessful: client.samba.testdomain/AAAA: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: cancelling transaction on zone samba.testdomain >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: spnego update failed >> авг 21 13:22:24 dc.samba.testdomain named[1275]: client @0x7f305b9a4898 <client-ipv4>#39330: updating zone 'samba.testdomain/NONE': update failed: rejected by secure update (REFUSED) >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: allowing update of signer=CLIENT\$\@SAMBA.TESTDOMAIN name=client.samba.testdomain tcpaddr=<client-ipv4> type=A key=6d6a34ea-cc49-4abc-83a5-ced0533dc28e/160/0 >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: allowing update of signer=CLIENT\$\@SAMBA.TESTDOMAIN name=client.samba.testdomain tcpaddr=<client-ipv4> type=AAAA key=6d6a34ea-cc49-4abc-83a5-ced0533dc28e/160/0 >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: starting transaction on zone samba.testdomain >> авг 21 13:22:24 dc.samba.testdomain named[1275]: client @0x7f305b9a4898 <client-ipv4>#39330/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': delete all rrsets from name 'client.samba.testdomain' >> авг 21 13:22:24 dc.samba.testdomain named[1275]: client @0x7f305b9a4898 <client-ipv4>#39330/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': adding an RR at 'client.samba.testdomain' A <client-ipv4> >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: added rdataset client.samba.testdomain 'client.samba.testdomain. 3600 IN A <client-ipv4>' >> авг 21 13:22:24 dc.samba.testdomain named[1275]: client @0x7f305b9a4898 <client-ipv4>#39330/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': adding an RR at 'client.samba.testdomain' AAAA <client-ipv6> >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: added rdataset client.samba.testdomain 'client.samba.testdomain. 3600 IN AAAA <client-ipv6>' >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: subtracted rdataset samba.testdomain 'samba.testdomain. 3600 IN SOA dc.samba.testdomain. hostmaster.samba.testdomain. 28 900 600 86400 3600' >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: added rdataset samba.testdomain 'samba.testdomain. 3600 IN SOA dc.samba.testdomain. hostmaster.samba.testdomain. 29 900 600 86400 3600' >> авг 21 13:22:24 dc.samba.testdomain named[1275]: samba_dlz: committed transaction on zone samba.testdomain > > >Ðа DC2 пÑи ÑÑом в journalctl ниÑего. > > >ÐÑÐ¸Ð¼ÐµÑ 2 (p11+387440.10 / sisyphus): (2) gensec dc, success >----------------------------------- > >Ðоманда запÑÑена в 12:54:03, завеÑÑена в 12:54:08: > >stderr: >> gensec_gse_client_prepare_ccache: Kinit for CLIENT$@samba.testdomain to access ldap/dc.samba.testdomain failed: Client not found in Kerberos database: NT_STATUS_LOGON_FAILURE >> Successfully registered hostname with DNS > >stdout: >> Using short domain name -- SAMBA >> Joined 'CLIENT' to dns domain 'samba.testdomain' > > >ÐÑи ÑÑом на DC в journalctl в 12:54:07-08: > >> авг 21 12:54:07 dc.samba.testdomain named[1089]: samba_dlz: starting transaction on zone samba.testdomain >> авг 21 12:54:07 dc.samba.testdomain named[1089]: client @0x7fc40224cc98 <client-ipv4>#38638: updating zone 'samba.testdomain/NONE': update unsuccessful: client.samba.testdomain/AAAA: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) >> авг 21 12:54:07 dc.samba.testdomain named[1089]: samba_dlz: cancelling transaction on zone samba.testdomain >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: spnego update failed >> авг 21 12:54:08 dc.samba.testdomain named[1089]: client @0x7fc40224cc98 <client-ipv4>#38638: updating zone 'samba.testdomain/NONE': update failed: rejected by secure update (REFUSED) >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: allowing update of signer=CLIENT\$\@SAMBA.TESTDOMAIN name=client.samba.testdomain tcpaddr=<client-ipv4> type=A key=8004e2c1-bd43-471d-8968-7b7676578d24/160/0 >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: allowing update of signer=CLIENT\$\@SAMBA.TESTDOMAIN name=client.samba.testdomain tcpaddr=<client-ipv4> type=AAAA key=8004e2c1-bd43-471d-8968-7b7676578d24/160/0 >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: starting transaction on zone samba.testdomain >> авг 21 12:54:08 dc.samba.testdomain named[1089]: client @0x7fc40224cc98 <client-ipv4>#38638/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': delete all rrsets from name 'client.samba.testdomain' >> авг 21 12:54:08 dc.samba.testdomain named[1089]: client @0x7fc40224cc98 <client-ipv4>#38638/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': adding an RR at 'client.samba.testdomain' A <client-ipv4> >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: added rdataset client.samba.testdomain 'client.samba.testdomain. 3600 IN A <client-ipv4>' >> авг 21 12:54:08 dc.samba.testdomain named[1089]: client @0x7fc40224cc98 <client-ipv4>#38638/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': adding an RR at 'client.samba.testdomain' AAAA <client-ipv6> >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: added rdataset client.samba.testdomain 'client.samba.testdomain. 3600 IN AAAA <client-ipv6>' >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: subtracted rdataset samba.testdomain 'samba.testdomain. 3600 IN SOA dc.samba.testdomain. hostmaster.samba.testdomain. 25 900 600 86400 3600' >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: added rdataset samba.testdomain 'samba.testdomain. 3600 IN SOA dc.samba.testdomain. hostmaster.samba.testdomain. 26 900 600 86400 3600' >> авг 21 12:54:08 dc.samba.testdomain named[1089]: samba_dlz: committed transaction on zone samba.testdomain > >Ðа DC2 пÑи ÑÑом в journalctl ниÑего. > > >ÐÑÐ¸Ð¼ÐµÑ 3 (p11+387440.10 / sisyphus): (2) gensec dc2 + (1) kinit, fail >----------------------------------- > >Ðоманда запÑÑена в 13:22:05, завеÑÑена в 13:22:09: > >stderr: >> gensec_gse_client_prepare_ccache: Kinit for CLIENT$@samba.testdomain to access ldap/dc2.samba.testdomain failed: Client not found in Kerberos database: NT_STATUS_LOGON_FAILURE > >stdout: >> Using short domain name -- SAMBA >> Joined 'CLIENT' to dns domain 'samba.testdomain' >> kinit: Client ''CLIENT$@SAMBA.TESTDOMAIN'' not found in Kerberos database while getting initial credentials > >Ðа DC пÑи ÑÑом в journalctl ниÑего пÑо ÑÑого клиенÑа. >Ðа DC2 в journalctl Ñоже ниÑего. > > >ÐÑÐ¸Ð¼ÐµÑ 4 (p11): (1) kinit, fail >-------------- > >Ðоманда запÑÑена в 12:55:47, завеÑÑена в 12:55:52: > >stderr: >(ниÑего) > >stdout: >> Using short domain name -- SAMBA >> Joined 'CLIENT' to dns domain 'samba.testdomain' >> kinit: Client ''CLIENT$@SAMBA.TESTDOMAIN'' not found in Kerberos database while getting initial credentials > > >ÐÑи ÑÑом на DC в journalctl в 12:55:46: > >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: starting transaction on zone samba.testdomain >> авг 21 12:55:46 dc.samba.testdomain named[1070]: client @0x7f0559ffac98 <client-ipv4>#51022: updating zone 'samba.testdomain/NONE': update unsuccessful: client.samba.testdomain/AAAA: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: cancelling transaction on zone samba.testdomain >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: spnego update failed >> авг 21 12:55:46 dc.samba.testdomain named[1070]: client @0x7f0559ffac98 <client-ipv4>#51022: updating zone 'samba.testdomain/NONE': update failed: rejected by secure update (REFUSED) >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: allowing update of signer=CLIENT\$\@SAMBA.TESTDOMAIN name=client.samba.testdomain tcpaddr=<client-ipv4> type=A key=734928df-c15d-48ef-8236-3f70c44cf587/160/0 >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: allowing update of signer=CLIENT\$\@SAMBA.TESTDOMAIN name=client.samba.testdomain tcpaddr=<client-ipv4> type=AAAA key=734928df-c15d-48ef-8236-3f70c44cf587/160/0 >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: starting transaction on zone samba.testdomain >> авг 21 12:55:46 dc.samba.testdomain named[1070]: client @0x7f0559ffac98 <client-ipv4>#51022/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': delete all rrsets from name 'client.samba.testdomain' >> авг 21 12:55:46 dc.samba.testdomain named[1070]: client @0x7f0559ffac98 <client-ipv4>#51022/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': adding an RR at 'client.samba.testdomain' A <client-ipv4> >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: added rdataset client.samba.testdomain 'client.samba.testdomain. 3600 IN A <client-ipv4>' >> авг 21 12:55:46 dc.samba.testdomain named[1070]: client @0x7f0559ffac98 <client-ipv4>#51022/key CLIENT\$\@SAMBA.TESTDOMAIN: updating zone 'samba.testdomain/NONE': adding an RR at 'client.samba.testdomain' AAAA <client-ipv6> >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: added rdataset client.samba.testdomain 'client.samba.testdomain. 3600 IN AAAA <client-ipv6>' >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: subtracted rdataset samba.testdomain 'samba.testdomain. 3600 IN SOA dc.samba.testdomain. hostmaster.samba.testdomain. 23 900 600 86400 3600' >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: added rdataset samba.testdomain 'samba.testdomain. 3600 IN SOA dc.samba.testdomain. hostmaster.samba.testdomain. 24 900 600 86400 3600' >> авг 21 12:55:46 dc.samba.testdomain named[1070]: samba_dlz: committed transaction on zone samba.testdomain > >Ðа DC2 пÑи ÑÑом в journalctl ниÑего.
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 55687
: 19399