Nameserver startet nicht :(

Bind, PowerDNS
Post Reply
referee
Posts: 15
Joined: 2004-06-18 01:31
 

Nameserver startet nicht :(

Post by referee »

Hallo,

ich bekomme eine Fehlermeldung. Leider weiß ich nicht, welcher Fehler sich hier eingeschlichen hat. Der Rootserver wurde erst kürzlich reinitialisiert. Neues Betriebssystem: Suse 9.1 !

Wenn ich den Status des Nameservers abfrage steht dort "unused", wenn ich den dann starte "done" und bei einer weiteren Statusabfrage wieder "unused".


/var/log/message:

Code: Select all

Jul 17 12:30:44 p15145250 sshd[7154]: Accepted password for root from ::ffff:80.134.56.157 port 62664 ssh2
Jul 17 12:30:44 p15145250 sshd[7154]: subsystem request for sftp
Jul 17 12:30:54 p15145250 named[7214]: starting BIND 9.2.3 -t /var/lib/named -u named
Jul 17 12:30:54 p15145250 named[7214]: using 1 CPU
Jul 17 12:30:54 p15145250 named[7214]: loading configuration from '/etc/named.conf'
Jul 17 12:30:54 p15145250 named[7214]: none:0: open: /etc/named.conf: permission denied
Jul 17 12:30:54 p15145250 named[7214]: loading configuration: permission denied
Jul 17 12:30:54 p15145250 named[7214]: exiting (due to fatal error)
Jul 17 12:31:00 p15145250 /USR/SBIN/CRON[7238]: (root) CMD (/root/confixx/confixx_counterscript.pl ) 
Jul 17 12:31:04 p15145250 sshd[7154]: subsystem request for sftp
/etc/named.conf:

Code: Select all

# Copyright (c) 2001 SuSE GmbH Nuernberg, Germany
#
# Author: Frank Bodammer <feedback@suse.de>
#
# /etc/named.conf
#
# This is a sample configuration file for the name server BIND9. 
# It works as a caching only name server without modification.
#
# A sample configuration for setting up your own domain can be
# found in /usr/share/doc/packages/bind9/sample-config.
#
# A description of all available options can be found in
# /usr/share/doc/packages/bind9/misc/options.

options {

	# The directory statement defines the name server´s 
	# working directory

	directory "/var/lib/named";

	# The forwarders record contains a list of servers to
	# which queries should be forwarded. Enable this line and
	# modify the IP-address to your provider's name server.
	# Up to three servers may be listed.

	#forwarders { 10.11.12.13; 10.11.12.14; };

	# Enable the next entry to prefer usage of the name 
	# server declared in the forwarders section.

	#forward first;

	# The listen-on record contains a list of local network
	# interfaces to listen on. Optionally the port can be 
	# specified. Default is to listen on all interfaces found
	# on your system. The default port is 53.

	#listen-on port 53 { 127.0.0.1; };

	# The listen-on-v6 record enables or disables listening
	# on IPV6 interfaces. Allowed values are 'any' and 'none'
	# or a list of addresses. IPv6 can only be used with 
	# kernel 2.4 in this release.

	listen-on-v6 { any; };

	# The next three statements may be needed if a firewall
	# stands between the local server and the internet.

	#query-source address * port 53;
	#transfer-source * port 53;
	#notify-source * port 53;

	# The allow-query record contains a list of networks or
	# IP-addresses to accept and deny queries from. The 
	# default is to allow queries from all hosts.

	#allow-query { 127.0.0.1; };

	# If notify is set to yes (default), notify messages are
	# sent to other name servers when the the zone data is
	# changed. Instead of setting a global 'notify' statement
	# in the 'options' section, a separate 'notify' can be
	# added to each zone definition.

	notify no;
	
	auth-nxdomain no;
	#erlaubt das zone-update zu ns.schlund.de und ns2.schlund.de
	allow-transfer { 195.20.224.97; 195.20.225.34; };
};

# The following three zone definitions don't need any modification.
# The first one defines localhost while the second defines the
# reverse lookup for localhost. The last zone "." is the 
# definition of the root name servers. 

zone "localhost" in {
	type master;
	file "localhost.zone";
};

zone "0.0.127.in-addr.arpa" in {
	type master;
	file "127.0.0.zone";
};

zone "." in {
	type hint;	
	file "root.hint";
};

# You can insert further zone records for your own domains below.

zone "222.160.217.in.addr.arpa" in {
	type master;
	file "217.160.222.zone";
};

(...)

};
/var/lib/named:

Code: Select all

$TTL 1W
@		IN SOA		ns.hauptdomain.de.   root (
				2004071101	; serial
				8H		; refresh
				2H		; retry
				1W		; expiry
				11H )	        ; minimum

		IN NS		ns.hauptdomain.de.
		IN NS		ns.schlund.de.
		IN MX		10 mail.hauptdomain.de.
		IN MX		20 mxXY.schlund.de.
		IN A		217.160.222.190
*		IN A		217.160.222.190
Last edited by referee on 2008-09-01 14:38, edited 1 time in total.
wgot
Posts: 1675
Joined: 2003-07-06 02:03
 

Re: Nameserver startet nicht :(

Post by wgot »

Referee wrote:Jul 17 12:30:54 p15145250 named[7214]: loading configuration: permission denied
referee
Posts: 15
Joined: 2004-06-18 01:31
 

Re: Nameserver startet nicht :(

Post by referee »

aber wieso ?
wgot
Posts: 1675
Joined: 2003-07-06 02:03
 

Re: Nameserver startet nicht :(

Post by wgot »

Hallo,

Bind darf mindestens eine der Konfigurationsdateien nicht öffnen - Rechte, Besitzer und Gruppe prüfen.

Gruß, Wolfgang
referee
Posts: 15
Joined: 2004-06-18 01:31
 

Re: Nameserver startet nicht :(

Post by referee »

/etc/named.conf
/var/lib/named/127.0.0.zone
/var/lib/named/217.160.222.zone
/var/lib/named/default.hosts
/var/lib/named/localhost.zone
/var/lib/named/root.hint

Diese Dateien haben das Recht root:root !
Welche Rechte müssen sie haben ?
wgot
Posts: 1675
Joined: 2003-07-06 02:03
 

Re: Nameserver startet nicht :(

Post by wgot »

Hallo,

Gruppe und Owner unter denen Bind läuft. Bei Suse 8.x war es named:named. Probier's mal damit.

Gruß, Wolfgang
referee
Posts: 15
Joined: 2004-06-18 01:31
 

Re: Nameserver startet nicht :(

Post by referee »

Super,

das wars, die Rechte müssen named:named sein.
Herzlichen Dank.
Post Reply