Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #192691 > unrolled thread

Issues while installing Debian

Started by啊肥坚lolz <rex12425@gmail.com>
First post2018-02-19 18:10 +0100
Last post2018-03-09 19:30 +0100
Articles 17 — 7 participants

Back to article view | Back to linux.debian.user


Contents

  Issues while installing Debian 啊肥坚lolz <rex12425@gmail.com> - 2018-02-19 18:10 +0100
    Re: Issues while installing Debian Hans <hans.ullrich@loop.de> - 2018-02-19 18:10 +0100
    Re: Issues while installing Debian Raju Devidas <rajudev@disroot.org> - 2018-02-19 19:00 +0100
    dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-02-28 01:30 +0100
      Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-02-28 06:50 +0100
        Re: Re: dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-03-01 02:10 +0100
          Re: Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-01 07:40 +0100
            Re: dnsmasq and SOA Curt <curty@free.fr> - 2018-03-02 22:00 +0100
              Re: Re: dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-03-06 03:00 +0100
                Re: Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-06 07:30 +0100
            Re: Re: Re: dnsmasq and SOA RODARY Jacques <rodaryj@free.fr> - 2018-03-07 22:20 +0100
              Re: Re: Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-08 10:00 +0100
                Re: dnsmasq and SOA Jacques Rodary <rodaryj@free.fr> - 2018-03-08 19:00 +0100
                  Re: dnsmasq and SOA Jacques Rodary <rodaryj@free.fr> - 2018-03-09 03:40 +0100
                    Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-09 08:40 +0100
                      Re: dnsmasq and SOA Jacques Rodary <rodaryj@free.fr> - 2018-03-09 18:30 +0100
                        Re: dnsmasq and SOA Reco <recoverym4n@gmail.com> - 2018-03-09 19:30 +0100

#192691 — Issues while installing Debian

From啊肥坚lolz <rex12425@gmail.com>
Date2018-02-19 18:10 +0100
SubjectIssues while installing Debian
Message-ID<vkX6V-5Pi-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hello Debian Team,

I faced an issue while installing Debian.
Please Have A Look At My Issue If Can, Thank You.

I'm using non-graphical (text) installer to install Debian, After a manual
partitioning, The installation started(system installation)

After installing till 7% it say installation step failed, I started the
installation again(and even formatted the disk), This problem still
occurred.

This issue many people may happened before.
So I searched online(google) and didn't found any solution. I even looked
into the debian installation documentation.

Here are some of my computer specifications for you if you requires:

Intel Core 2 Duo E6400
1GB RAM(1014MB)
Intel Express Chipset Q45

The Installation Images(ISO) I downloaded from debian website is a  i386
architecture live image(DVD).

Please Reply If You Need More Information About My Issue.

Thanks For Your Reading.
Looking Forward For Your Reply.

[toc] | [next] | [standalone]


#192692

FromHans <hans.ullrich@loop.de>
Date2018-02-19 18:10 +0100
Message-ID<vkX6V-5Pi-15@gated-at.bofh.it>
In reply to#192691
Am Montag, 19. Februar 2018, 17:44:49 CET schrieb 啊肥坚lolz:
Don't use a live debian dvd. Use the official installer cd/dvd fromn debian's 
site. This is Debian, not Ubuntu!

Good luck

Hans
> Hello Debian Team,
> 
> I faced an issue while installing Debian.
> Please Have A Look At My Issue If Can, Thank You.
> 
> I'm using non-graphical (text) installer to install Debian, After a manual
> partitioning, The installation started(system installation)
> 
> After installing till 7% it say installation step failed, I started the
> installation again(and even formatted the disk), This problem still
> occurred.
> 
> This issue many people may happened before.
> So I searched online(google) and didn't found any solution. I even looked
> into the debian installation documentation.
> 
> Here are some of my computer specifications for you if you requires:
> 
> Intel Core 2 Duo E6400
> 1GB RAM(1014MB)
> Intel Express Chipset Q45
> 
> The Installation Images(ISO) I downloaded from debian website is a  i386
> architecture live image(DVD).
> 
> Please Reply If You Need More Information About My Issue.
> 
> Thanks For Your Reading.
> Looking Forward For Your Reply.

[toc] | [prev] | [next] | [standalone]


#192700

FromRaju Devidas <rajudev@disroot.org>
Date2018-02-19 19:00 +0100
Message-ID<vkXTj-65P-9@gated-at.bofh.it>
In reply to#192691

On 02/19/2018 10:14 PM, 啊肥坚lolz wrote:
> Hello Debian Team,
>
> I faced an issue while installing Debian.
> Please Have A Look At My Issue If Can, Thank You.
>
> I'm using non-graphical (text) installer to install Debian, After a
> manual partitioning, The installation started(system installation)
>
> After installing till 7% it say installation step failed, I started
> the installation again(and even formatted the disk), This problem
> still occurred.
>
> This issue many people may happened before.
> So I searched online(google) and didn't found any solution. I even
> looked into the debian installation documentation.
>
> Here are some of my computer specifications for you if you requires:
>
> Intel Core 2 Duo E6400
> 1GB RAM(1014MB)
> Intel Express Chipset Q45
>
> The Installation Images(ISO) I downloaded from debian website is a 
> i386 architecture live image(DVD).
>
> Please Reply If You Need More Information About My Issue.
Use DVD1 from this page.
https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/

let us know, if you still face issues later


>
> Thanks For Your Reading.
> Looking Forward For Your Reply.

[toc] | [prev] | [next] | [standalone]


#193198 — dnsmasq and SOA

FromRODARY Jacques <rodaryj@free.fr>
Date2018-02-28 01:30 +0100
Subjectdnsmasq and SOA
Message-ID<vnXN7-3Zk-1@gated-at.bofh.it>
In reply to#192691
	I finally surrendered, and now use dnsmasq instead of bind. But
in my setup with named,  my box was Start Of Authority, and when there
was a change and reload of the zone files, the only other name server
was notified, before the TTL is over. How can I do that with dnsmasq?
If the dnsmasqHowto wiki is quite clear, but not very detailed, the
manpage is too detailed, and not clear to me. Thanks for your help.
	Jacques

[toc] | [prev] | [next] | [standalone]


#193206 — Re: dnsmasq and SOA

FromReco <recoverym4n@gmail.com>
Date2018-02-28 06:50 +0100
SubjectRe: dnsmasq and SOA
Message-ID<vo2MN-7lY-1@gated-at.bofh.it>
In reply to#193198
	Hi.

On Wed, Feb 28, 2018 at 01:25:00AM +0100, RODARY Jacques wrote:
> 	I finally surrendered, and now use dnsmasq instead of bind.

Welcome to the dark side, we have cookies.


> But in my setup with named,  my box was Start Of Authority, and when
> there was a change and reload of the zone files, the only other name
> server was notified, before the TTL is over. How can I do that with
> dnsmasq?
> If the dnsmasqHowto wiki is quite clear, but not very detailed, the
> manpage is too detailed, and not clear to me. Thanks for your help.

Dnsmasq is a caching DNS first, and an authoritative much later.
So, it's possible for dnsmasq to have a SOA record, but changing it
would probably require editing dnsmasq.conf and restarting dnsmasq.

The part of dnsmasq.conf you need is "auth-soa":

auth-soa=2016021014,hostmaster.example.com,1200,120,604800

The meaning of these fields is described in dnsmasq(8), and from left to
right it is: serial, hostmaster, refresh, retry, expiry.

Reco

[toc] | [prev] | [next] | [standalone]


#193238 — Re: Re: dnsmasq and SOA

FromRODARY Jacques <rodaryj@free.fr>
Date2018-03-01 02:10 +0100
SubjectRe: Re: dnsmasq and SOA
Message-ID<vokTn-3hG-1@gated-at.bofh.it>
In reply to#193206
	I learnt about dnsmasq when I used Tor to see wiki, thanks for this hint. For now it works but I am not sure your help about auth-soa is all I need to get
notifying to the other name server. I just added this line: 
			"auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800" 
in /etc/dnsmasq.conf, and after restarting dnsmasq (systemctl restart dnsmaq.service) I get this result with "systemctl status dnsmaq.service: " dnsmasq.service - dnsmasq
- A lightweight DHCP and caching DNS server
................................
     
févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale
févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53
févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53
févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53
févr. 28 23:52:33 ns dnsmasq[24452]: aucun serveur trouvé dans /run/dnsmasq/resolv.conf, va réessayer
févr. 28 23:52:33 ns dnsmasq[24452]: Lecture de /run/dnsmasq/resolv.conf
févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale
févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53
févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53
févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53"
	
First 88.170.1.14 is my main IP to the outside, is it local?  Second, before I added the refresh,retry, expire fields, supposed to have defaults values (said man 8
dnsmasq), I had another line in the output: 
	"févr. 28 23:20:17 ns dnsmasq[24453]: Too few arguments."
Does this mean dnsmasq will notify the other name server (ns6.gandi.net,  217.70.177.40#53) when needed? For now this server answers query about hosts I didn't put in
/etc/hosts? 
	Anyway it works for the time present, and many thanks again.
		Jacques
		P.S.: Cookies are not my favorites, but I know some recipes you would like, I am sure!

[toc] | [prev] | [next] | [standalone]


#193244 — Re: Re: dnsmasq and SOA

FromReco <recoverym4n@gmail.com>
Date2018-03-01 07:40 +0100
SubjectRe: Re: dnsmasq and SOA
Message-ID<voq2P-7rw-3@gated-at.bofh.it>
In reply to#193238
On Thu, Mar 01, 2018 at 02:04:40AM +0100, RODARY Jacques wrote:
> 	I learnt about dnsmasq when I used Tor to see wiki, thanks for this hint. For now it works but I am not sure your help about auth-soa is all I need to get
> notifying to the other name server.

Ok.

> I just added this line: 
> 			"auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800" 
> in /etc/dnsmasq.conf, and after restarting dnsmasq (systemctl restart dnsmaq.service) I get this result with "systemctl status dnsmaq.service: " dnsmasq.service - dnsmasq
> - A lightweight DHCP and caching DNS server
> ................................
>      
> févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale
> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53
> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53
> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53
> févr. 28 23:52:33 ns dnsmasq[24452]: aucun serveur trouvé dans /run/dnsmasq/resolv.conf, va réessayer
> févr. 28 23:52:33 ns dnsmasq[24452]: Lecture de /run/dnsmasq/resolv.conf
> févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale
> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53
> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53
> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53"
> 	
> First 88.170.1.14 is my main IP to the outside, is it local?

My French is *very* rusty (tried to learn the language back in high
school, and that was some time ago). I remember some expletives vaguely,
but that's it.

Can you please provide your dnsmasq.conf? A simple

grep -v '^#' /etc/dnsmasq.conf | uniq

would suffice.

> Second, before I added the refresh,retry, expire fields, supposed to have defaults values (said man 8
> dnsmasq), I had another line in the output: 
> 	"févr. 28 23:20:17 ns dnsmasq[24453]: Too few arguments."

Dnsmasq can be stubborn sometimes. While manpage says that everything
except serial is optional, it may not be the truth.

The idea is that you define "auth-zone" for your domain first, and
create a SOA record for it with "auth-soa" secord.


> Does this mean dnsmasq will notify the other name server (ns6.gandi.net,  217.70.177.40#53) when needed?

Your registered domain is "rodary.net", so that means that your
registrar nameserver should see appropriate SOA record.
The question is - does it see it now? What does show (your DNS):

dig in soa rodary.net @127.0.0.1


Because dig shows old SOA record for me:

dig in soa rodary.net

rodary.net.             3599    IN      SOA     ns.rodary.net.  root.ns.rodary.net. 2018022101 10800 3600 604800 3600


> For now this server answers query about hosts I didn't put in
> /etc/hosts? 

Unless you put some domains into "local" stanza, queries for such domain
should be resolved via nameservers put in /etc/resolv.conf or "server"
stanza. In your case it's resolv.conf.

The exception to the rule is auto-registered DHCP leases. As long as
DHCP client provides "client-id" identifier, dnsmasq should create
temporary A and PTR records for such client.

Reco

[toc] | [prev] | [next] | [standalone]


#193284 — Re: dnsmasq and SOA

FromCurt <curty@free.fr>
Date2018-03-02 22:00 +0100
SubjectRe: dnsmasq and SOA
Message-ID<voZWx-7Aa-7@gated-at.bofh.it>
In reply to#193244
On 2018-03-01, Reco <recoverym4n@gmail.com> wrote:
>>      
>> févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale
>> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53
>> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53
>> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53
>> févr. 28 23:52:33 ns dnsmasq[24452]: aucun serveur trouvé dans /run/dnsmasq/resolv.conf, va réessayer
>> févr. 28 23:52:33 ns dnsmasq[24452]: Lecture de /run/dnsmasq/resolv.conf
>> févr. 28 23:52:33 ns dnsmasq[24452]: ignore le serveur de nom 88.170.1.143 - interface locale
>> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 217.70.177.40#53
>> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.240#53
>> févr. 28 23:52:33 ns dnsmasq[24452]: utilise le serveur de nom 212.27.40.241#53"
>> 	
>> First 88.170.1.14 is my main IP to the outside, is it local?
>
> My French is *very* rusty (tried to learn the language back in high
> school, and that was some time ago). I remember some expletives vaguely,
> but that's it.
>

More or less
 
 ignoring name server 88.170.1.143 - local interface
 using name server 217.70.177.40#53
 (...)
 no server found in /run/dnsmasq/resolv.conf, will retry
 Reading /run/dnsmasq/resolv.conf

 ignoring name server 88.170.1.143 - local interface 
 (...)

-- 
Bah, the latest news, the latest news is not the last.
Samuel Beckett

[toc] | [prev] | [next] | [standalone]


#193397 — Re: Re: dnsmasq and SOA

FromRODARY Jacques <rodaryj@free.fr>
Date2018-03-06 03:00 +0100
SubjectRe: Re: dnsmasq and SOA
Message-ID<vqa3w-2Go-3@gated-at.bofh.it>
In reply to#193284
 For the time being, my main concern is to keep my connection up! I did succeed, without succeeding for long. Each time I rebooted  I had no access to interness. Three
times (or more) I couldn't have a  full access including on my home wifi  access point. I even reinstalled Stretch two times, before suspecting something else than my
dnmasq, NetworkManager etc...
	It was difficult to find the guilty program, until I thought about Ivahi-daemon which didn't appear in the logs. Shouldn't I  suppress the Avahis pachages? As
soon as I know, I come back to my main concern, i.e. DNS,SOA...  Anyway Thanks you both Reco and Curt

[toc] | [prev] | [next] | [standalone]


#193399 — Re: Re: dnsmasq and SOA

FromReco <recoverym4n@gmail.com>
Date2018-03-06 07:30 +0100
SubjectRe: Re: dnsmasq and SOA
Message-ID<vqegN-685-1@gated-at.bofh.it>
In reply to#193397
	Hi.

On Tue, Mar 06, 2018 at 02:50:34AM +0100, RODARY Jacques wrote:
>  For the time being, my main concern is to keep my connection up! I did succeed, without succeeding for long. Each time I rebooted  I had no access to interness. Three
> times (or more) I couldn't have a  full access including on my home wifi  access point. I even reinstalled Stretch two times, before suspecting something else than my
> dnmasq, NetworkManager etc...
> 	It was difficult to find the guilty program, until I thought about Ivahi-daemon which didn't appear in the logs. Shouldn't I  suppress the Avahis pachages? As
> soon as I know, I come back to my main concern, i.e. DNS,SOA...  Anyway Thanks you both Reco and Curt

As long as you don't need mDNS, you can safely remove these:

apt-get autoremove --purge avahi-autoipd avahi-daemon

Reco

[toc] | [prev] | [next] | [standalone]


#193495 — Re: Re: Re: dnsmasq and SOA

FromRODARY Jacques <rodaryj@free.fr>
Date2018-03-07 22:20 +0100
SubjectRe: Re: Re: dnsmasq and SOA
Message-ID<vqODE-5Fx-11@gated-at.bofh.it>
In reply to#193244
	Sorry for my last post: I sent a draft mail instead of the corrected one.  Let's go back to my own concern: dnsmasq and soa, 
if you don't mind. Here is my dnsmasq.conf file: 
resolv-file=/etc/dnsmasqresolv.conf

interface=eno1
interface=wlp3s0
no-dhcp-interface=enp2s0

auth-zone=rodary.net

auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800

dhcp-range=10.42.0.20,10.42.0.200,infinite

 As you guessed enp2s0 (eth0 now) is my INET interface.
 
	Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to ns6.gandi.net? With all my stupid previous acts, I don't dare to try it, 
specially when it could affect outside hosts e.g. my registrar.

	Jacques

[toc] | [prev] | [next] | [standalone]


#193516 — Re: Re: Re: dnsmasq and SOA

FromReco <recoverym4n@gmail.com>
Date2018-03-08 10:00 +0100
SubjectRe: Re: Re: dnsmasq and SOA
Message-ID<vqZz3-4EM-5@gated-at.bofh.it>
In reply to#193495
	Hi.

On Wed, Mar 07, 2018 at 10:19:32PM +0100, RODARY Jacques wrote:
> 	Sorry for my last post: I sent a draft mail instead of the corrected one.  Let's go back to my own concern: dnsmasq and soa, 
> if you don't mind. Here is my dnsmasq.conf file: 
> resolv-file=/etc/dnsmasqresolv.conf
> 
> interface=eno1
> interface=wlp3s0
> no-dhcp-interface=enp2s0
> 
> auth-zone=rodary.net
> 
> auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800
> 
> dhcp-range=10.42.0.20,10.42.0.200,infinite
> 
>  As you guessed enp2s0 (eth0 now) is my INET interface.
>  
> 	Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to ns6.gandi.net? With all my stupid previous acts, I don't dare to try it, 
> specially when it could affect outside hosts e.g. my registrar.

I never tried it myself, but the manpage says this on auth-peer:

If this option is not given, then AXFR requests will be accepted from any secondary.


The way I understand it, your configuration should work without
auth-peer, while being somewhat insecure. You may need to specify
ns6.gandi.net as secondary through auth-sec-servers, on the other hand.

Yet your configuration does not work, apparently, as 'dig +trace'
shows me this:

rodary.net.             3600    IN      SOA     ns.rodary.net.
root.ns.rodary.net. 2018022101 10800 3600 604800 3600
rodary.net.             3600    IN      NS      ns.rodary.net.
rodary.net.             3600    IN      NS      ns6.gandi.net.
;; Received 169 bytes from 217.70.177.40#53(ns6.gandi.net) in 64 ms


Did your previous BIND configuration implement DNSSEC? Your dnsmasq
should not provide DS records with this config, yet Gandi resolver could
require them.

Reco

[toc] | [prev] | [next] | [standalone]


#193533 — Re: dnsmasq and SOA

FromJacques Rodary <rodaryj@free.fr>
Date2018-03-08 19:00 +0100
SubjectRe: dnsmasq and SOA
Message-ID<vr7ZE-1w8-13@gated-at.bofh.it>
In reply to#193516

On 08/03/2018 09:51, Reco wrote:
> 	Hi.
>
> On Wed, Mar 07, 2018 at 10:19:32PM +0100, RODARY Jacques wrote:
>> 	Sorry for my last post: I sent a draft mail instead of the corrected one.  Let's go back to my own concern: dnsmasq and soa,
>> if you don't mind. Here is my dnsmasq.conf file:
>> resolv-file=/etc/dnsmasqresolv.conf
>>
>> interface=eno1
>> interface=wlp3s0
>> no-dhcp-interface=enp2s0
>>
>> auth-zone=rodary.net
>>
>> auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800
>>
>> 	Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to ns6.gandi.net? With all my stupid previous acts, I don't dare to try it,
>> specially when it could affect outside hosts e.g. my registrar.
> I never tried it myself, but the manpage says this on auth-peer:
>
> If this option is not given, then AXFR requests will be accepted from any secondary.
>
>
> The way I understand it, your configuration should work without
> auth-peer, while being somewhat insecure. You may need to specify
> ns6.gandi.net as secondary through auth-sec-servers, on the other hand.
>
> Yet your configuration does not work, apparently, as 'dig +trace'
> shows me this:
>
> rodary.net.             3600    IN      SOA     ns.rodary.net.
> root.ns.rodary.net. 2018022101 10800 3600 604800 3600
> rodary.net.             3600    IN      NS      ns.rodary.net.
> rodary.net.             3600    IN      NS      ns6.gandi.net.
> ;; Received 169 bytes from 217.70.177.40#53(ns6.gandi.net) in 64 ms
Today "dig in soa rodary.net" gives me:
rodary.net.             600     IN      SOA     . root.ns.rodary.net. 
2018022801 10800 3600 10800 600
Which is neither the answer I had  yesterday, neither yours (by the way 
I don't find how to use the "dig +trace" command), and "dig in ns 
rodary.net" which gave me ns.rodary.net and ns6.gandi.net , gives me 
only ns.rodary.net now, and "dig in ns/soa rodary.net @ns6.gandi.net" 
has no answer, but "recursion requested but not available"
> Did your previous BIND configuration implement DNSSEC?
No.

ns6.gandi.net was NS in my main zone file; so I think I will try 
auth-sec-servers=ns6.gandi.net as it was in my BIND setup
     Jacques

[toc] | [prev] | [next] | [standalone]


#193544 — Re: dnsmasq and SOA

FromJacques Rodary <rodaryj@free.fr>
Date2018-03-09 03:40 +0100
SubjectRe: dnsmasq and SOA
Message-ID<vrg6R-72t-3@gated-at.bofh.it>
In reply to#193533

On 08/03/2018 18:58, Jacques Rodary wrote:
>
>
> On 08/03/2018 09:51, Reco wrote:
>>     Hi.
>>
>> On Wed, Mar 07, 2018 at 10:19:32PM +0100, RODARY Jacques wrote:
>>>     Sorry for my last post: I sent a draft mail instead of the 
>>> corrected one.  Let's go back to my own concern: dnsmasq and soa,
>>> if you don't mind. Here is my dnsmasq.conf file:
>>> resolv-file=/etc/dnsmasqresolv.conf
>>>
>>> interface=eno1
>>> interface=wlp3s0
>>> no-dhcp-interface=enp2s0
>>>
>>> auth-zone=rodary.net
>>>
>>> auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800
>>>
>>>     Shouldn't I add a "auth-peer=217.70.177.40" line for AXFR to 
>>> ns6.gandi.net? With all my stupid previous acts, I don't dare to try 
>>> it,
>>> specially when it could affect outside hosts e.g. my registrar.
>> I never tried it myself, but the manpage says this on auth-peer:
>>
>> If this option is not given, then AXFR requests will be accepted from 
>> any secondary.
>>
>>
>> The way I understand it, your configuration should work without
>> auth-peer, while being somewhat insecure. You may need to specify
>> ns6.gandi.net as secondary through auth-sec-servers, on the other hand.
>>
>> Yet your configuration does not work, apparently, as 'dig +trace'
>> shows me this:
>>
>> rodary.net.             3600    IN      SOA     ns.rodary.net.
>> root.ns.rodary.net. 2018022101 10800 3600 604800 3600
>> rodary.net.             3600    IN      NS      ns.rodary.net.
>> rodary.net.             3600    IN      NS      ns6.gandi.net.
>> ;; Received 169 bytes from 217.70.177.40#53(ns6.gandi.net) in 64 ms
> Today "dig in soa rodary.net" gives me:
> rodary.net.             600     IN      SOA     . root.ns.rodary.net. 
> 2018022801 10800 3600 10800 600
> Which is neither the answer I had  yesterday, neither yours (by the 
> way I don't find how to use the "dig +trace" command), and "dig in ns 
> rodary.net" which gave me ns.rodary.net and ns6.gandi.net , gives me 
> only ns.rodary.net now, and "dig in ns/soa rodary.net @ns6.gandi.net" 
> has no answer, but "recursion requested but not available"
>> Did your previous BIND configuration implement DNSSEC?
No
ns6.gandi.net was NS in my main zone file; so I think I will try 
auth-sec-servers=ns6.gandi.net as it was in my BIND setup. I did and it  
worked: "dig in soa  rodary.net" gives me:
;; ANSWER SECTION:
rodary.net.             600     IN      SOA     . root.ns.rodary.net. 
2018022801 10800 3600 10800 600

;; AUTHORITY SECTION:
rodary.net.             600     IN      NS      .
rodary.net.             600     IN      NS      ns6.gandi.net.

and even if I don't quite understand why "." (the root) is my secondary 
server, I suppose it means  I succeeded to have my host as a stealth 
server! But when I added "auth-peer=217.70.177.40"  I had to restart 
everything, which means reboot for me because I don't understand quite 
well how NetworkManager works.
     Jacques

[toc] | [prev] | [next] | [standalone]


#193550 — Re: dnsmasq and SOA

FromReco <recoverym4n@gmail.com>
Date2018-03-09 08:40 +0100
SubjectRe: dnsmasq and SOA
Message-ID<vrkNb-1WT-5@gated-at.bofh.it>
In reply to#193544
	Hi.

On Fri, Mar 09, 2018 at 03:34:27AM +0100, Jacques Rodary wrote:
> > Today "dig in soa rodary.net" gives me:
> > rodary.net.             600     IN      SOA     . root.ns.rodary.net.
> > 2018022801 10800 3600 10800 600
> > Which is neither the answer I had  yesterday, neither yours (by the way
> > I don't find how to use the "dig +trace" command), and "dig in ns
> > rodary.net" which gave me ns.rodary.net and ns6.gandi.net , gives me
> > only ns.rodary.net now, and "dig in ns/soa rodary.net @ns6.gandi.net"
> > has no answer, but "recursion requested but not available"
> > > Did your previous BIND configuration implement DNSSEC?
> No
> ns6.gandi.net was NS in my main zone file; so I think I will try
> auth-sec-servers=ns6.gandi.net as it was in my BIND setup. I did and it 
> worked: "dig in soa  rodary.net" gives me:
> ;; ANSWER SECTION:
> rodary.net.             600     IN      SOA     . root.ns.rodary.net.
> 2018022801 10800 3600 10800 600
> 
> ;; AUTHORITY SECTION:
> rodary.net.             600     IN      NS      .
> rodary.net.             600     IN      NS      ns6.gandi.net.

Hate to break it to you, but it seems to fail for everyone else.
Today "dig in soa rodary.net" gives me SERVFAIL.


> and even if I don't quite understand why "." (the root) is my secondary
> server, I suppose it means  I succeeded to have my host as a stealth server!

I believe that it means that somehow you're announcing authority on root
domain. I would advise against it.
"dig +trace" gives me "BAD REFERRAL", which is not a good sign, to say the
least.


> But when I added "auth-peer=217.70.177.40"  I had to restart everything,
> which means reboot for me because I don't understand quite well how
> NetworkManager works.

I don't understand it either, but frankly I don't need to. IP adresses,
routing table and packet flow are the state of the kernel. Using
always-running userland tool for their configuration *may* be
appropriate in certain cases (DHCP, anyone?), but for your typical
server environment such cases do not apply.
That said, for your typical server environment nothing beats ifupdown.
So my advice is - if you need a predictable behaviour - you exterminate
NetworkManager, connman and other fancy toys, and stick to the ifupdown,
or maybe systemd-networkd.

Reco

[toc] | [prev] | [next] | [standalone]


#193559 — Re: dnsmasq and SOA

FromJacques Rodary <rodaryj@free.fr>
Date2018-03-09 18:30 +0100
SubjectRe: dnsmasq and SOA
Message-ID<vru09-854-3@gated-at.bofh.it>
In reply to#193550

On 09/03/2018 08:32, Reco wrote:
> 	Hi.
>
> On Fri, Mar 09, 2018 at 03:34:27AM +0100, Jacques Rodary wrote:
>
>> ;; AUTHORITY SECTION:
>> rodary.net.             600     IN      NS      .
>> rodary.net.             600     IN      NS      ns6.gandi.net.
Here is my new dnsmasq.conf:
     no-dhcp-interface=enp2s0
     auth-server=ns.rodary.net,88.170.1.143
     auth-zone=rodary.net
     auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800
     auth-sec-servers=ns6.gandi.net
     dhcp-range=10.42.0.20,10.42.0.200,infinite
I added the auth-server line, and "dig in soa rodary.net" gives:
     ;; ANSWER SECTION:
     rodary.net.             600     IN      SOA     ns.rodary.net. 
root.ns.rodary.net. 2018022801 10800 3600             10800 600
     ;; AUTHORITY SECTION:
     rodary.net.             600     IN      NS      ns.rodary.net.
     rodary.net.             600     IN      NS      ns6.gandi.net.
     ;; Query time: 0 msec
     ;; SERVER: 88.170.1.143#53(88.170.1.143)
which means ns.rodary.net is SOA of my zone and ns6.gandi.net is slave 
server. Without master server the root zone "." servers were 
authoritative for my zone (as they are for all zones).
>> Hate to break it to you, but it seems to fail for everyone else.
>> Today "dig in soa rodary.net" gives me SERVFAIL.
Tell me please if it works now.
>> and even if I don't quite understand why "." (the root) is my secondary
>> server, I suppose it means  I succeeded to have my host as a stealth server!
> I believe that it means that somehow you're announcing authority on root
> domain. I would advise against it.
No, root servers announced authority on rodary.net, since nobody else 
delegated this authority.
>> I don't understand quite well how NetworkManager works.
> I don't understand it either, but frankly I don't need to. IP adresses,
> routing table and packet flow are the state of the kernel. Using
> always-running userland tool for their configuration *may* be
> appropriate in certain cases (DHCP, anyone?), but for your typical
> server environment such cases do not apply.
> That said, for your typical server environment nothing beats ifupdown.
> So my advice is - if you need a predictable behaviour - you exterminate
> NetworkManager, connman and other fancy toys, and stick to the ifupdown,
> or maybe systemd-networkd.
I may do that soon. Thanks for your precious help.
     Jacques

[toc] | [prev] | [next] | [standalone]


#193561 — Re: dnsmasq and SOA

FromReco <recoverym4n@gmail.com>
Date2018-03-09 19:30 +0100
SubjectRe: dnsmasq and SOA
Message-ID<vruWe-d5-7@gated-at.bofh.it>
In reply to#193559
	Hi.

On Fri, Mar 09, 2018 at 06:25:24PM +0100, Jacques Rodary wrote:
> > On Fri, Mar 09, 2018 at 03:34:27AM +0100, Jacques Rodary wrote:
> > 
> > > ;; AUTHORITY SECTION:
> > > rodary.net.             600     IN      NS      .
> > > rodary.net.             600     IN      NS      ns6.gandi.net.
> Here is my new dnsmasq.conf:
>     no-dhcp-interface=enp2s0
>     auth-server=ns.rodary.net,88.170.1.143
>     auth-zone=rodary.net
>     auth-soa=2018022800,root.ns.rodary.net,10800,3600,10800
>     auth-sec-servers=ns6.gandi.net
>     dhcp-range=10.42.0.20,10.42.0.200,infinite
> I added the auth-server line, and "dig in soa rodary.net" gives:
>     ;; ANSWER SECTION:
>     rodary.net.             600     IN      SOA     ns.rodary.net.
> root.ns.rodary.net. 2018022801 10800 3600             10800 600
>     ;; AUTHORITY SECTION:
>     rodary.net.             600     IN      NS      ns.rodary.net.
>     rodary.net.             600     IN      NS      ns6.gandi.net.
>     ;; Query time: 0 msec
>     ;; SERVER: 88.170.1.143#53(88.170.1.143)
> which means ns.rodary.net is SOA of my zone and ns6.gandi.net is slave
> server. Without master server the root zone "." servers were authoritative
> for my zone (as they are for all zones).
> > > Hate to break it to you, but it seems to fail for everyone else.
> > > Today "dig in soa rodary.net" gives me SERVFAIL.
> Tell me please if it works now.

Yup, all lights are green:

; <<>> DiG 9.10.3-P4-Debian <<>> in soa rodary.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31015
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;rodary.net.                    IN      SOA

;; ANSWER SECTION:
rodary.net.             599     IN      SOA     ns.rodary.net.
root.ns.rodary.net. 2018022801 10800 3600 10800 600

Save this config elsewhere just in case. A backup never hurts.


> > > I don't understand quite well how NetworkManager works.
> > I don't understand it either, but frankly I don't need to. IP adresses,
> > routing table and packet flow are the state of the kernel. Using
> > always-running userland tool for their configuration *may* be
> > appropriate in certain cases (DHCP, anyone?), but for your typical
> > server environment such cases do not apply.
> > That said, for your typical server environment nothing beats ifupdown.
> > So my advice is - if you need a predictable behaviour - you exterminate
> > NetworkManager, connman and other fancy toys, and stick to the ifupdown,
> > or maybe systemd-networkd.
> I may do that soon. Thanks for your precious help.

You're welcome.

Reco

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web