Bug 14535 - dns.keytab not created in /var/lib/samba/bind-dns
Summary: dns.keytab not created in /var/lib/samba/bind-dns
Status: NEW
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: Other (show other bugs)
Version: 4.12.8
Hardware: All All
: P5 normal (vote)
Target Milestone: ---
Assignee: Samba QA Contact
QA Contact: Samba QA Contact
Depends on:
Reported: 2020-10-19 12:06 UTC by Stefan Kania
Modified: 2020-10-24 12:53 UTC (History)
1 user (show)

See Also:


Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Kania 2020-10-19 12:06:24 UTC
Setting up a single DC there is a dns.keytab in /var/lib/samba/bind-dns and all the permissions in /var/lib/samba/bind-dns are correctly set. 

Installing the next DC there is no /var/lib/samba/bind-dns/dns.keytab file, the only place to find this file is /var/lib/samba/private. The user "bind" has no permission to dns.keytab file in this place. So bind9 will not start.

Then the permission for /var/lib/samba/bind-dns/ are wrong:

root@addc-02:/etc/bind# ls -ld /var/lib/samba/bind-dns/
drwxr-x--- 3 root root 4096 Okt 19 13:50 /var/lib/samba/bind-dns/

Must be:

root@addc-01:~# ls -ld /var/lib/samba/bind-dns/
drwxrwx--- 3 root bind 4096 Okt 19 13:23 /var/lib/samba/bind-dns/

The permissions on the first DC are set correctly.
Comment 1 Chris Smith 2020-10-19 17:29:32 UTC
title of bug report needs correction (may not be found on a search)

typo: dns.kytab instead of dns.keytab