[Samba] Strange Bind freezing

Andrew Bartlett abartlet at samba.org
Thu Dec 2 22:26:09 UTC 2021

On Thu, 2021-12-02 at 09:41 +0000, Rowland Penny via samba wrote:
> > > I wouldn't recommend using a separate Bind9 server, unless it
> > > forwards
> > > all AD dns to an AD DC.
> > What is the different if they are fully synced?
> All AD DC's are authoritative for the AD dns domain and have control
> over the dns records in AD. All methods of running a secondary dns
> server (except for a forwarding server) has caused problems in the
> past.

I strongly support this advise.  DNS is integral to AD, and just as you
can't/shouldn't run a non-AD KDC, LDAP server etc, you can't/shouldn't
run a non-AD DNS server for your Samba DNS zones.

Here be dragons.

Andrew Bartlett

Andrew Bartlett (he/him)       https://samba.org/~abartlet/
Samba Team Member (since 2001) https://samba.org
Samba Team Lead, Catalyst IT   https://catalyst.net.nz/services/samba

Samba Development and Support, Catalyst IT - Expert Open Source

More information about the samba mailing list