[Samba] Domain member cannot authenticate when first domain controller is down

Rowland penny rpenny at samba.org
Fri Mar 5 20:46:35 UTC 2021

On 05/03/2021 20:22, Dale wrote:
>> I would add these:
>>     dnssec-enable no;
>>     dnssec-lookaside no;
> The reason I took those out is because named-checkconf (BIND 9.16.12) 
> tells me they are obsolete and should be removed.

And after checking, I have to agree, looks like ISC now thinks like I 
always did, DNSSEC is only any good if everyone uses it, only problem 
was, almost nobody used it. I will remove them from my bind setup.

>> Finally, what is in this:
>>     include "/etc/bind/named.conf.fwd";
> In true Debian fashion, I broke the forwarders out of the options file 
> and created their own file.  That allows me to create/change 
> forwarders once, then copy across the various DNS servers I have at 
> different locations, meaning I don't have to type it out multiple 
> times.  It is convenient for my needs and something most people would 
> not need or want.

I sort of thought that was what you were doing 😁


More information about the samba mailing list