Hi,
I am running the same named.conf file (except for the listen addresses)
and the same zone files on two servers. One server, running
bind-9.11.36-1.fc33.x86_64 is able to resolve the zone without any
error. The other server, running bind-9.18.28-2.fc39.x86_64 always
returns SERVFAIL for any quesy involing the zone (SOA, A, MX, etc).
Other zones listed in named.conf resolve correctly on both systems. The
zone that fails has two glue records, one for each system.
named.conf has an internal and an external zone. Queries to either the
internal or external zone fail in the same way.
dig soa @173.255.254.106 tylerent.com
01-Oct-2026 04:01:14.925 query-errors: debug 1: client @0x7f1e1d7ae168
173.255.254.106#44975 (tylerent.com): view internal: query failed (zone
not loaded) for tylerent.com/IN/A at ../../../lib/ns/query.c:5676
01-Oct-2026 04:03:35.806 query-errors: debug 1: client @0x7f1e1d7ae168
173.255.254.106#35797 (ns1.tylerent.com): view internal: query failed
(zone not loaded) for ns1.tylerent.com/IN/A at ../../../lib/ns/query.c:5676
Yet, chkconfig finds nothing wrong:
/usr/sbin/named-checkconf -t /var/named/chroot -z etc/named.conf
zone tylerent.com/IN: loaded serial 2026092901
zone dyn.tylerent.com/IN: loaded serial 202006161
...
tylerent.com/IN: loaded serial 2026092901
The same 'zone loaded' messages occur when I (re)start named-chroot
I am a little suspicious that the zones that have problems are the only
zones with glue records. All of the other zones use name servers in the
tylerent.com zone. But, I am not sure why this should matter and there
is the issue that the other server, with the same files works fine.
I am looking for help discovering what is wrong with my named.conf or
zone files. Apparently, sometime after Bind 9.11.36, the Bind code
changed to do additional quality checks and that is perhaps causing the
failure.
Any help in an approach to debugging this would be greatly appreciated.
Especially helpful would be ways for Bind to tell me what is wrong.
Additional information: a test server running
bind-9.16.23-40.el9_8.9.x86_64 using the same named.conf (except for
listen address) and same zone files does resolve the zone correctly.
Thanks for reading!
--
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from
this list.