Hello community. As described in the topic title i get these 2 error messages in the system diagnostic section of my Univention DC:
Critical: KDC service check
Critical: Check kerberos authenticated dns updates
Expanding the first item i see only a “ph” and some buttons that should help me solve my problem (but none of them does); Expanding the second item i get this:
Errors occurred while running kinit or nsupdate. nsupdate check for domain fakedomain.biz failed (ucsdc.frigoimpianti.biz). nsupdate check for domain fakedomain.biz failed (ucsdc).
Name is obviously fake, tld is correct
The problem is that when i try to update the system it miserably fails and the errors reported become way more than just those 2. I have tried every possible link i have found here but i had no luck.
Apparently all the commands with kinit and klist are all good.
I am at a loss here. I have seen this happening only in broken installations but this hasn’t been touched in a while.
The UCS version is 4.4-6 errata787.
The thing i have noticed is that it’s using samba as DNS and if i switch to bind_DLZ when i try to perform the DNS update with:
and everything fails.
I have also tried to look at samba4 rejects but there are none.
I think i have done whatever i could possibly think of but the errors are always there.
I hope i can find some help in here. If you need more info on the configuration please just ask and i will provide.
Thank you for your hint jolentes. I will move that instance into my test area and will perform the steps suggested in the article you linked at a later time. Although i have no reference to Heimdal in my system diagnostic page therefore i am kind of inclined to believe that your issue, even if it seems to be similar to mine, has a different root cause.
To the forum admins: This is going to be a production system, therefore, i am won’t repair it and go with it as I’d rather perform a full reinstallation since it’s basically an unconfigured UCS. I will mark this post as solved if you wish.