[Samba] Why are ForeignSecurityPrincipals and Managed Service Accounts empty with no entries?

Turritopsis Dohrnii Teo En Ming ceo at teo-en-ming-corp.com
Wed Feb 19 13:24:01 UTC 2020

Hi Rowland,

I tried your suggested /etc/named.conf. ForeignSecurityPrincipals and Managed Service Accounts are still empty in Active Directory Users and Computers. Is it more of an integrated LDAP issue than a DNS issue??

I also noticed that Network Manager keeps overwriting my /etc/resolv.conf. Is there a way to solve this secondary issue?

Thank you.

From: samba <samba-bounces at lists.samba.org> on behalf of Rowland penny via samba <samba at lists.samba.org>
Sent: Wednesday, February 19, 2020 5:37 PM
To: sambalist <samba at lists.samba.org>
Subject: Re: [Samba] Why are ForeignSecurityPrincipals and Managed Service Accounts empty with no entries?

On 19/02/2020 00:07, Turritopsis Dohrnii Teo En Ming wrote:
> Hi Rowland,
> This is my full /etc/named.conf:
Try it like this:

options {
     directory "/var/named";
     notify no;
     empty-zones-enable no;
     allow-query {;; };
     allow-recursion {;; };
     forwarders {;; };
     allow-transfer { none; };
     dnssec-validation no;
     dnssec-enable no;
     dnssec-lookaside no;
     listen-on port 53 { any; };
     listen-on-v6 port 53 { any; };
     pid-file "/run/named/named.pid";
     tkey-gssapi-keytab "/usr/local/samba/bind-dns/dns.keytab";
     minimal-responses yes;

logging {
         channel default_debug {
                 file "data/named.run";
                 severity dynamic;

zone "." IN {
type hint;
file "named.ca";

include "/etc/named.rfc1912.zones";
include "/usr/local/samba/bind-dns/named.conf";

Replace '' with your networks address.

You may also want to change the forwarders.


