[Samba] Horrible BIND9_DLZ DNS breakage after DC replaced and samba-tool domain demote --remove-other-dead-server

Alex Crow acrow at integrafin.co.uk
Sun Aug 14 20:52:43 UTC 2016

> I am fairly sure this is your problem, it should be able to find the
> KDC on its own DC. Have you checked /etc/krb5.conf, /etc/hosts
> and /etc/resolv.conf ?

With the BIND server not running, and this krb5.conf:

        default_realm = SAMBA.IFA.NET
        dns_lookup_realm = false
        dns_lookup_kdc = true

samba_dnsupdate cannot find the KDC. Even if I add:


it still complains about not finding a KDC and does not complete.

Oddly if I can use the output to figure out the DNS entries I need to
add, so I thought "ah, cool, I'll use samba-tool dns" to add them back
in. To my great surprise, when I try to add each entry that
samba_dnsupdate says is missing, samba-tool tells me it already exists!!

/etc/hosts on the new DC:     samba4-dc-2.samba.ifa.net samba4-dc-2


[root at samba4-dc-2 ~]# hostname -f


search samba.ifa.net. ifa.net.

>> I've done the dnsupdate on both DCs before turning off the first, and
>> it completes fine with after a couple of restarts of samba and bind.
>> I'm still not sure what I should turn off bind on the newer DC as it's
>> surely a requirement for the domain to function?
> Yes it is, I was just making sure.
> Rowland

Feels a bit chicken-and-egg at the moment. Is there a definitive
procedure documented for neophytes to, post-classicupgrade:

1) add an new BIND9_DLZ based DC properly
2) remove all traces of the DC used for the classicupgrade


Luckily I did take a VM snapshot of me 2nd DC before the DNS borked
itself this time, so I have a working domain for now.



This message is intended only for the addressee and may contain
confidential information. Unless you are that person, you may not
disclose its contents or use it in any way and are requested to delete
the message along with any attachments and notify us immediately.
This email is not intended to, nor should it be taken to, constitute advice.
The information provided is correct to our knowledge & belief and must not
be used as a substitute for obtaining tax, regulatory, investment, legal or
any other appropriate advice.

"Transact" is operated by Integrated Financial Arrangements Ltd.
29 Clement's Lane, London EC4N 7AE. Tel: (020) 7608 4900 Fax: (020) 7608 5300.
(Registered office: as above; Registered in England and Wales under
number: 3727592). Authorised and regulated by the Financial Conduct
Authority (entered on the Financial Services Register; no. 190856).

More information about the samba mailing list