
17th July 2006, 22:48
|
|
Member
|
|
Join Date: Aug 2005
Location: Switzerland
Posts: 91
Thanks: 10
Thanked 0 Times in 0 Posts
|
|
Primary & secondary DNS-Server Problems: permission denied
Hi 2gether
I tried to set up my DNS primary and slave server for my domain pasco.ch. So far it looked good. It has already functioned, more or less. But there still seems to be a big problem with my slave DNS server.
If I check var/log/messages from my secondary DNS Server there are following error messages:
Jul 17 22:26:15 tom named[31488]: transfer of 'pasco.ch/IN' from 217.162.76.43#53: connected using 192.168.100.2#56190
Jul 17 22:26:16 tom named[31488]: dumping master file: tmp-TKR1FpouaN: open: permission denied
Jul 17 22:26:16 tom named[31488]: transfer of 'pasco.ch/IN' from 217.162.76.43#53: failed while receiving responses: permission denied
Jul 17 22:26:16 tom named[31488]: transfer of 'pasco.ch/IN' from 217.162.76.43#53: end of transfer
What do I wrong? If I check my nameservers with dnsreport.com I get following (main) errors:
All nameservers report identical NS records WARNING: At least one of your nameservers did not return your NS records (it reported 0 answers). This could be because of a referral, if you have a lame nameserver (which would need to be fixed).
84.75.88.120 returns 0 answers (may be a referral)
and
FAIL Lame nameservers ERROR: You have one or more lame nameservers. These are nameservers that do NOT answer authoritatively for your domain. This is bad; for example, these nameservers may never get updated. The following nameservers are lame:
84.75.88.120
I guess, these two errors are the result of the above mentioned permission denied message? What do I wrong?
Thanks for your advice.
P@sco
|

18th July 2006, 01:09
|
|
Moderator
|
|
Join Date: Dec 2005
Location: The Netherlands
Posts: 2,010
Thanks: 254
Thanked 134 Times in 120 Posts
|
|
Did you open port 53 TCP and UDP for the DNS?
|

18th July 2006, 07:18
|
|
Member
|
|
Join Date: Aug 2005
Location: Switzerland
Posts: 91
Thanks: 10
Thanked 0 Times in 0 Posts
|
|
yes
Yes I did. In fact, the primary DNS Server seems to be able to communicate with the secondary DNS Server and in reverse too.
|

18th July 2006, 08:21
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
|
|
[quote]
Jul 17 22:26:16 tom named[31488]: dumping master file: tmp-TKR1FpouaN: open: permission denied
[/qoute]
What are the current permissions of /tmp? Who is the owner / groop?
Should root:root and 777 (g+rwx,u+rwx,o+rwx)
if not, correct and try again...
|

18th July 2006, 09:00
|
|
Local Meanie
|
|
Join Date: Apr 2006
Location: Switzerland
Posts: 1,046
Thanks: 4
Thanked 34 Times in 32 Posts
|
|
If you are using bind, did you set allow-transfer correctly?
|

18th July 2006, 13:20
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,593 Times in 2,444 Posts
|
|
Which distribution do you use on your secondary DNS?
|

18th July 2006, 21:09
|
|
Member
|
|
Join Date: Aug 2005
Location: Switzerland
Posts: 91
Thanks: 10
Thanked 0 Times in 0 Posts
|
|
@ Ben: Permissions are set correct (1777) and also owner:group
@ sjau: No, I haven't set allow-transfer, but I thought this is done by ISP-DNS-Manager automaticly...
@ falko: I'm using ISPConfig Vers. 2.1.2 on the secondary dns server..ups, quite old. That's why I'm updating now the system to 2.2.5 :-).
Was there any DNS Secondary Server issue on 2.1.2? :-)
Thx, p@sco
|

18th July 2006, 21:44
|
|
Local Meanie
|
|
Join Date: Apr 2006
Location: Switzerland
Posts: 1,046
Thanks: 4
Thanked 34 Times in 32 Posts
|
|
@ Pasco
I'm not familiar with the ISP-DNS-Manager... if it makes config files for Bind then have a look at them and check whether the allow-transfer is set properly...
|

19th July 2006, 12:30
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,593 Times in 2,444 Posts
|
|
Quote:
|
Originally Posted by Pasco
@ falko: I'm using ISPConfig Vers. 2.1.2 on the secondary dns server..ups, quite old. That's why I'm updating now the system to 2.2.5 :-).
|
I don't mean your ISPConfig version, I need to know which Linux distribution you use - Fedora, Debian, SuSE, etc.
|

20th July 2006, 08:42
|
|
Member
|
|
Join Date: Aug 2005
Location: Switzerland
Posts: 91
Thanks: 10
Thanked 0 Times in 0 Posts
|
|
@ Falko: Oh, I've overread that...you've meant my distro. On the primary DNS Server I use Fedora Core 4 and on the secondary DNS Server Fedora Core 5.
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 05:10.
|
Recent comments
19 hours 58 min ago
1 day 5 hours ago
1 day 6 hours ago
1 day 9 hours ago
1 day 14 hours ago
1 day 14 hours ago
1 day 16 hours ago
2 days 2 hours ago
2 days 7 hours ago
2 days 9 hours ago