Hello community. As described in the topic title i get these 2 error messages in the system diagnostic section of my Univention DC:
- Critical: KDC service check
- Critical: Check kerberos authenticated dns updates
Expanding the first item i see only a “ph” and some buttons that should help me solve my problem (but none of them does); Expanding the second item i get this:
Errors occurred while running
kinit
ornsupdate
.
nsupdate
check for domain fakedomain.biz failed (ucsdc.frigoimpianti.biz).
nsupdate
check for domain fakedomain.biz failed (ucsdc).
Name is obviously fake, tld is correct
The problem is that when i try to update the system it miserably fails and the errors reported become way more than just those 2. I have tried every possible link i have found here but i had no luck.
Apparently all the commands with kinit and klist are all good.
I am at a loss here. I have seen this happening only in broken installations but this hasn’t been touched in a while.
The UCS version is 4.4-6 errata787.
The thing i have noticed is that it’s using samba as DNS and if i switch to bind_DLZ when i try to perform the DNS update with:
samba_dnsupdate --all-names --verbose
It throws and uncaught exception:
ERROR(runtime): uncaught exception - (9711, WERR_DNS_ERROR_RECORD_ALREADY_EXISTS’)
and everything fails.
I have also tried to look at samba4 rejects but there are none.
I think i have done whatever i could possibly think of but the errors are always there.
I hope i can find some help in here. If you need more info on the configuration please just ask and i will provide.
Thanks in advance
G