ALT Linux Bugzilla
– Attachment 9084 Details for
Bug 39440
MS DNS RFC 2845 violation (samba and windows compatibility)
New bug
|
Search
|
[?]
|
Help
Register
|
Log In
[x]
|
Forgot Password
Login:
[x]
|
EN
|
RU
Лог ошибки tsig
tsig-error.log (text/x-log), 36.94 KB, created by
Evgeny Sinelnikov
on 2020-12-15 15:59:21 MSK
(
hide
)
Description:
Лог ошибки tsig
Filename:
MIME Type:
Creator:
Evgeny Sinelnikov
Created:
2020-12-15 15:59:21 MSK
Size:
36.94 KB
patch
obsolete
> >[root@dc nsupdate]# ./nsupdate -g /var/log/named/req >Outgoing update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 >;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >; TSIG error with server: tsig verify failure > > >__________________ > >[root@dc nsupdate]# ./nsupdate -g -d /var/log/named/req >Outgoing update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 >;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >Reply from SOA query: >;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31386 >;; flags: qr aa ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 >;; QUESTION SECTION: >;dc.domain.alt. IN SOA > >;; AUTHORITY SECTION: >domain.alt. 3600 IN SOA dc.domain.alt. hostmaster.domain.alt. 1 900 600 86400 3600 > >Found zone name: domain.alt >The master is: dc.domain.alt >start_gssrequest >Found realm from ticket: DOMAIN.ALT >send_gssrequest >Outgoing update query: >;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 43079 >;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 >;; QUESTION SECTION: >;1789845724.sig-dc.domain.alt. ANY TKEY > >;; ADDITIONAL SECTION: >1789845724.sig-dc.domain.alt. 0 ANY TKEY gss-tsig. 1608036898 1608036898 3 NOERROR 1295 YIIFCwYJKoZIhvcSAQICAQBuggT6MIIE9qADAgEFoQMCAQ6iBwMFACAA AACjggQRYYIEDTCCBAmgAwIBBaEMGwpET01BSU4uQUxUoh8wHaADAgEB oRYwFBsDRE5TGw1kYy5kb21haW4uYWx0o4ID0TCCA82gAwIBEqEDAgEB ooIDvwSCA7tor3hlgNjAnuEQSZb5g7MG0Y/RqkeT2P53W2NC249JeHNK +oUZqnv15Bg2mmEDbYglVp9m44y7lxLkf117zthBtS+WEtyQK1fDtwX1 yKlQjHd94KvYwlKEsJFt5Ct4/hqAt6OydV5HtZE3vhtp8Dzsx4YMzXEj r2/muYxjF5Hn9ukT+Wt9GGoxAZRKga/hCrw/Lsfk+xqbrPOdkzm8QbGB cEkheQKHOIYfPlVVvSh3lfDHwN5YaSCfLpTp/uIxG3tYQi45flKfldKr tZR++gx3/hdfeOc1cf1xu+nGqceteitxJeaAVfRcumyqE2170jRa0R3M yJb2sXcYSvfwDm58nWIUhIklKeFbgt/EJznxg3bBmsW6J7F8oV8GkAZq EExaVxlYBDWo/7J0nsKafx3sY3Gerua7yF1o8gBXWEk83DnrD15MXcPc hIyT8kk5tT+4fiwx0k0ofZT7VBLHIM4YLnhBsbEsT0S1JyTgT6z3U6rL Wasr1d03Z9JJT9oXFBvqPM1kwbD7bLGV7i5tNnLGmsHs/yAvt67jFySb Z9BGTUii840VpemejTyDnu/MaG7MJFKvcug7l4rmpGxpx4yaWV87sn7I Ly14VwdMIQ7DbZs80ib0UUzU8HNfyV4QbXW74njVTtvfi2VpBg7l6Z0T YUfw+jZ2FVVfY1JYO05KFsrwwj0BxkK2kucuhk2uDS6XE6++VVQSjQfy piCGbLPG1ePiPeimLAn/CPaeC3nbJFg3eYQWeb3jMJDx54rYU9D9DGKk 5WELJdkYtx5qHAVsk0GJTasRgyApwqGCKnOrtF1sCA53sCaZIF33j1Ll AoxsBYy2SWXBugT+Jkc3xDYenx2VN7Sf8Pd5yBA5q7Q4N1GeN010Ls/S S/qbPJg6x85Shm2kXGPsfpl3im5yzAGvPqziy80aUniB2Be0YeczRl1p p8dXMahp+s6oNpmhyfZEQWTeanZBrS4tQS8mDrsI8H4gwgQ/z7YRl2z+ 1PEOtcvbuEn8bX5Eu3oKg/NQbNoQascVnkkAhNPCUihShIzYnVcGUeEp KFXN8Kvcw9X6v7WzQa4qKBGLh1JCLEILhz34d0nqNL/FStv32QHPHbD0 B65i0RfQOiggoQ8tPk+N0DR/f5InKENJJ3zLHx8zY9Z5fNDIO51immjw UY4IxqdxjVKsJHT40n5rraABFvQx8wvyKPSBy0TzeRW3XDya8YvvWXHd lRhCM6tIUvmNPAc9RbHOab0HQrhVUthTGQcGYhZGVq3WGA/lsuKzpIHL MIHIoAMCARKigcAEgb01guUVE8vg7WYpqrN6s45RbSVvJmjCk6QHFcAR S6CW3nXcqwF33wgVhP0OGe8IywbKHXXCaGe0nP9GzaqAOedfOoCvNWK+ TTSrBfrAxfom889SUgjSmU5gAwxDrXeV8G1WK1kBwi1G7jFOUSHg6J7w rCcfgXoGCcSOhaIfXofBafmePjF+YJiVH7u1fYqaK3/QCP5FoENC+hlP ixHmu28crkjxYcmPKnReRHJyz8rjHBdTZEMGepzG2m5biVY= 0 > >recvmsg reply from GSS-TSIG query >;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 43079 >;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 >;; QUESTION SECTION: >;1789845724.sig-dc.domain.alt. ANY TKEY > >;; ANSWER SECTION: >1789845724.sig-dc.domain.alt. 0 ANY TKEY gss-tsig. 1608036898 1608036898 3 NOERROR 156 YIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKi cQRvrs0rDd/BjOGmxWcSQX6cOuOur5xteMx5GhvBfaniciXdMTJLlBfn DLfkmNnZoai6Z9Wq6dOsPTX3/7Per4rDK8cDntlZ4VP10bmPuYUTf5hM Fk/Nd6Iy7llX3aY2yMNRXug++tstqu3qE+w6TDxt 0 > >;; TSIG PSEUDOSECTION: >1789845724.sig-dc.domain.alt. 0 ANY TSIG gss-tsig. 1608036898 300 28 BAQF//////8AAAAALtSN233ssA/CFAxa65S2Cw== 43079 NOERROR 0 > >Sending update to 10.64.128.2#53 >Outgoing update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 25830 >;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >;; TSIG PSEUDOSECTION: >1789845724.sig-dc.domain.alt. 0 ANY TSIG gss-tsig. 1608036898 300 28 BAQE//////8AAAAAM2sc7XeVF6W3b22/Kl5fLQ== 25830 NOERROR 0 > >; TSIG error with server: tsig verify failure > >Reply from update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 25830 >;; flags: qr ra; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 >;; ZONE SECTION: >;domain.alt. IN SOA > >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >;; TSIG PSEUDOSECTION: >1789845724.sig-dc.domain.alt. 0 ANY TSIG gss-tsig. 1608036899 300 28 BAQF//////8AAAAALtSN3Bh3h7mUfETOrxI9Ew== 25830 NOERROR 0 > >__________________ > > >[root@dc nsupdate]# ./nsupdate -g -d -D /var/log/named/req >setup_system() >reset_system() >user_interaction() >do_next_command() >do_next_command() >evaluate_update() >update_addordelete() >do_next_command() >show_message() >Outgoing update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0 >;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0 >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >do_next_command() >start_update() >recvsoa() >About to create rcvmsg >show_message() >Reply from SOA query: >;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15238 >;; flags: qr aa ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 >;; QUESTION SECTION: >;dc.domain.alt. IN SOA > >;; AUTHORITY SECTION: >domain.alt. 3600 IN SOA dc.domain.alt. hostmaster.domain.alt. 1 900 600 86400 3600 > >Found zone name: domain.alt >The master is: dc.domain.alt >start_gssrequest >Found realm from ticket: DOMAIN.ALT >send_gssrequest >show_message() >Outgoing update query: >;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50535 >;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 >;; QUESTION SECTION: >;4122024131.sig-dc.domain.alt. ANY TKEY > >;; ADDITIONAL SECTION: >4122024131.sig-dc.domain.alt. 0 ANY TKEY gss-tsig. 1608036978 1608036978 3 NOERROR 1295 YIIFCwYJKoZIhvcSAQICAQBuggT6MIIE9qADAgEFoQMCAQ6iBwMFACAA AACjggQRYYIEDTCCBAmgAwIBBaEMGwpET01BSU4uQUxUoh8wHaADAgEB oRYwFBsDRE5TGw1kYy5kb21haW4uYWx0o4ID0TCCA82gAwIBEqEDAgEB ooIDvwSCA7tor3hlgNjAnuEQSZb5g7MG0Y/RqkeT2P53W2NC249JeHNK +oUZqnv15Bg2mmEDbYglVp9m44y7lxLkf117zthBtS+WEtyQK1fDtwX1 yKlQjHd94KvYwlKEsJFt5Ct4/hqAt6OydV5HtZE3vhtp8Dzsx4YMzXEj r2/muYxjF5Hn9ukT+Wt9GGoxAZRKga/hCrw/Lsfk+xqbrPOdkzm8QbGB cEkheQKHOIYfPlVVvSh3lfDHwN5YaSCfLpTp/uIxG3tYQi45flKfldKr tZR++gx3/hdfeOc1cf1xu+nGqceteitxJeaAVfRcumyqE2170jRa0R3M yJb2sXcYSvfwDm58nWIUhIklKeFbgt/EJznxg3bBmsW6J7F8oV8GkAZq EExaVxlYBDWo/7J0nsKafx3sY3Gerua7yF1o8gBXWEk83DnrD15MXcPc hIyT8kk5tT+4fiwx0k0ofZT7VBLHIM4YLnhBsbEsT0S1JyTgT6z3U6rL Wasr1d03Z9JJT9oXFBvqPM1kwbD7bLGV7i5tNnLGmsHs/yAvt67jFySb Z9BGTUii840VpemejTyDnu/MaG7MJFKvcug7l4rmpGxpx4yaWV87sn7I Ly14VwdMIQ7DbZs80ib0UUzU8HNfyV4QbXW74njVTtvfi2VpBg7l6Z0T YUfw+jZ2FVVfY1JYO05KFsrwwj0BxkK2kucuhk2uDS6XE6++VVQSjQfy piCGbLPG1ePiPeimLAn/CPaeC3nbJFg3eYQWeb3jMJDx54rYU9D9DGKk 5WELJdkYtx5qHAVsk0GJTasRgyApwqGCKnOrtF1sCA53sCaZIF33j1Ll AoxsBYy2SWXBugT+Jkc3xDYenx2VN7Sf8Pd5yBA5q7Q4N1GeN010Ls/S S/qbPJg6x85Shm2kXGPsfpl3im5yzAGvPqziy80aUniB2Be0YeczRl1p p8dXMahp+s6oNpmhyfZEQWTeanZBrS4tQS8mDrsI8H4gwgQ/z7YRl2z+ 1PEOtcvbuEn8bX5Eu3oKg/NQbNoQascVnkkAhNPCUihShIzYnVcGUeEp KFXN8Kvcw9X6v7WzQa4qKBGLh1JCLEILhz34d0nqNL/FStv32QHPHbD0 B65i0RfQOiggoQ8tPk+N0DR/f5InKENJJ3zLHx8zY9Z5fNDIO51immjw UY4IxqdxjVKsJHT40n5rraABFvQx8wvyKPSBy0TzeRW3XDya8YvvWXHd lRhCM6tIUvmNPAc9RbHOab0HQrhVUthTGQcGYhZGVq3WGA/lsuKzpIHL MIHIoAMCARKigcAEgb1Sg5LCe885eotm4PfRGAI1yjypLna6XaRLsEEb S246zTpUT7pLqNT+eWfpiTMovc1uPZw0+DRmywxuU8kokL6RpLKvQRou J1dpj3Zs1fsQS1i0uIvrXP6w0uFwA0Z5QnL17JQhAIxtIqrZx/MeK3Zp QwQ5xnegJau6Pp2Ef+5FcIW1YTrCc71E95U7rLfqEvwMJ7msosfEzjUG G2KuqhJuMM2Oeek+JAaVahHUA6gQTLQ0aZPlmWg9/vWo46M= 0 > >Out of recvsoa >recvgss() >recvgss creating rcvmsg >show_message() >recvmsg reply from GSS-TSIG query >;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50535 >;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 >;; QUESTION SECTION: >;4122024131.sig-dc.domain.alt. ANY TKEY > >;; ANSWER SECTION: >4122024131.sig-dc.domain.alt. 0 ANY TKEY gss-tsig. 1608036978 1608036978 3 NOERROR 156 YIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKi cQRviLXow1sv0JudvaLzskyRJPNOCFXI9OnR9vtnMQs65B2vGBltBa8u +5bYl0y6WmQ+jF7DVJ4+RmrUmwE4X63BDvxJyVrXg/zBj7pe2d1X4pKT hcRJ6UavzXvK7ecu8/aZKFxXWy4Wippd71VL/rKJ 0 > >;; TSIG PSEUDOSECTION: >4122024131.sig-dc.domain.alt. 0 ANY TSIG gss-tsig. 1608036978 300 28 BAQF//////8AAAAAHS52G8PrjO7tzBE8YVrKyA== 50535 NOERROR 0 > >send_update() >Sending update to 10.64.128.2#53 >show_message() >Outgoing update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 41395 >;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >;; TSIG PSEUDOSECTION: >4122024131.sig-dc.domain.alt. 0 ANY TSIG gss-tsig. 1608036978 300 28 BAQE//////8AAAAAKATemBvDF3ZSWpYOsXj6Zg== 41395 NOERROR 0 > >Out of recvgss >update_completed() >; TSIG error with server: tsig verify failure >show_message() > >Reply from update query: >;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 41395 >;; flags: qr ra; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1 >;; ZONE SECTION: >;domain.alt. IN SOA > >;; UPDATE SECTION: >dc.domain.alt. 900 IN A 10.64.128.2 > >;; TSIG PSEUDOSECTION: >4122024131.sig-dc.domain.alt. 0 ANY TSIG gss-tsig. 1608036979 300 28 BAQF//////8AAAAAHS52HJxlqW+pFlfe05frKA== 41395 NOERROR 0 > >done_update() >reset_system() >user_interaction() >cleanup() >Shutting down task manager >shutdown_program() >Shutting down request manager >Destroy DST lib >Destroying request manager >Freeing the dispatchers >Shutting down dispatch manager >Destroying event >Shutting down socket manager >Shutting down timer manager >Destroying hash context >Destroying name state >Removing log context >Destroying memory context > > >__________________ > > >[root@dc lib]# tshark -i lo -O dns >Running as user "root" and group "root". This could be dangerous. >Capturing on 'Loopback: lo' >Frame 1: 43 bytes on wire (344 bits), 43 bytes captured (344 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 127.0.0.1, Dst: 127.0.0.1 >User Datagram Protocol, Src Port: 52880, Dst Port: 52880 >Data (1 byte) > >Frame 2: 63 bytes on wire (504 bits), 63 bytes captured (504 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 6, Src: ::1, Dst: ::1 >User Datagram Protocol, Src Port: 36965, Dst Port: 36965 >Data (1 byte) > >Frame 3: 73 bytes on wire (584 bits), 73 bytes captured (584 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 127.0.0.1, Dst: 127.0.0.1 >User Datagram Protocol, Src Port: 41356, Dst Port: 53 >Domain Name System (query) > Transaction ID: 0xb9ef > Flags: 0x0100 Standard query > 0... .... .... .... = Response: Message is a query > .000 0... .... .... = Opcode: Standard query (0) > .... ..0. .... .... = Truncated: Message is not truncated > .... ...1 .... .... = Recursion desired: Do query recursively > .... .... .0.. .... = Z: reserved (0) > .... .... ...0 .... = Non-authenticated data: Unacceptable > Questions: 1 > Answer RRs: 0 > Authority RRs: 0 > Additional RRs: 0 > Queries > dc.domain.alt: type A, class IN > Name: dc.domain.alt > [Name Length: 13] > [Label Count: 3] > Type: A (Host Address) (1) > Class: IN (0x0001) > >Frame 4: 136 bytes on wire (1088 bits), 136 bytes captured (1088 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 127.0.0.1, Dst: 127.0.0.1 >User Datagram Protocol, Src Port: 53, Dst Port: 41356 >Domain Name System (response) > Transaction ID: 0xb9ef > Flags: 0x8580 Standard query response, No error > 1... .... .... .... = Response: Message is a response > .000 0... .... .... = Opcode: Standard query (0) > .... .1.. .... .... = Authoritative: Server is an authority for domain > .... ..0. .... .... = Truncated: Message is not truncated > .... ...1 .... .... = Recursion desired: Do query recursively > .... .... 1... .... = Recursion available: Server can do recursive queries > .... .... .0.. .... = Z: reserved (0) > .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server > .... .... ...0 .... = Non-authenticated data: Unacceptable > .... .... .... 0000 = Reply code: No error (0) > Questions: 1 > Answer RRs: 1 > Authority RRs: 1 > Additional RRs: 0 > Queries > dc.domain.alt: type A, class IN > Name: dc.domain.alt > [Name Length: 13] > [Label Count: 3] > Type: A (Host Address) (1) > Class: IN (0x0001) > Answers > dc.domain.alt: type A, class IN, addr 10.64.128.2 > Name: dc.domain.alt > Type: A (Host Address) (1) > Class: IN (0x0001) > Time to live: 900 (15 minutes) > Data length: 4 > Address: 10.64.128.2 > Authoritative nameservers > domain.alt: type SOA, class IN, mname dc.domain.alt > Name: domain.alt > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > Time to live: 3600 (1 hour) > Data length: 35 > Primary name server: dc.domain.alt > Responsible authority's mailbox: hostmaster.domain.alt > Serial Number: 1 > Refresh Interval: 900 (15 minutes) > Retry Interval: 600 (10 minutes) > Expire limit: 86400 (1 day) > Minimum TTL: 3600 (1 hour) > [Request In: 3] > [Time: 0.000337316 seconds] > >Frame 5: 73 bytes on wire (584 bits), 73 bytes captured (584 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 127.0.0.1, Dst: 127.0.0.1 >User Datagram Protocol, Src Port: 41356, Dst Port: 53 >Domain Name System (query) > Transaction ID: 0x3efb > Flags: 0x0100 Standard query > 0... .... .... .... = Response: Message is a query > .000 0... .... .... = Opcode: Standard query (0) > .... ..0. .... .... = Truncated: Message is not truncated > .... ...1 .... .... = Recursion desired: Do query recursively > .... .... .0.. .... = Z: reserved (0) > .... .... ...0 .... = Non-authenticated data: Unacceptable > Questions: 1 > Answer RRs: 0 > Authority RRs: 0 > Additional RRs: 0 > Queries > dc.domain.alt: type AAAA, class IN > Name: dc.domain.alt > [Name Length: 13] > [Label Count: 3] > Type: AAAA (IPv6 Address) (28) > Class: IN (0x0001) > >Frame 6: 120 bytes on wire (960 bits), 120 bytes captured (960 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 127.0.0.1, Dst: 127.0.0.1 >User Datagram Protocol, Src Port: 53, Dst Port: 41356 >Domain Name System (response) > Transaction ID: 0x3efb > Flags: 0x8580 Standard query response, No error > 1... .... .... .... = Response: Message is a response > .000 0... .... .... = Opcode: Standard query (0) > .... .1.. .... .... = Authoritative: Server is an authority for domain > .... ..0. .... .... = Truncated: Message is not truncated > .... ...1 .... .... = Recursion desired: Do query recursively > .... .... 1... .... = Recursion available: Server can do recursive queries > .... .... .0.. .... = Z: reserved (0) > .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server > .... .... ...0 .... = Non-authenticated data: Unacceptable > .... .... .... 0000 = Reply code: No error (0) > Questions: 1 > Answer RRs: 0 > Authority RRs: 1 > Additional RRs: 0 > Queries > dc.domain.alt: type AAAA, class IN > Name: dc.domain.alt > [Name Length: 13] > [Label Count: 3] > Type: AAAA (IPv6 Address) (28) > Class: IN (0x0001) > Authoritative nameservers > domain.alt: type SOA, class IN, mname dc.domain.alt > Name: domain.alt > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > Time to live: 3600 (1 hour) > Data length: 35 > Primary name server: dc.domain.alt > Responsible authority's mailbox: hostmaster.domain.alt > Serial Number: 1 > Refresh Interval: 900 (15 minutes) > Retry Interval: 600 (10 minutes) > Expire limit: 86400 (1 day) > Minimum TTL: 3600 (1 hour) > [Request In: 5] > [Time: 0.000216585 seconds] > >Frame 7: 73 bytes on wire (584 bits), 73 bytes captured (584 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >User Datagram Protocol, Src Port: 55924, Dst Port: 53 >Domain Name System (query) > Transaction ID: 0x1f8f > Flags: 0x0000 Standard query > 0... .... .... .... = Response: Message is a query > .000 0... .... .... = Opcode: Standard query (0) > .... ..0. .... .... = Truncated: Message is not truncated > .... ...0 .... .... = Recursion desired: Don't do query recursively > .... .... .0.. .... = Z: reserved (0) > .... .... ...0 .... = Non-authenticated data: Unacceptable > Questions: 1 > Answer RRs: 0 > Authority RRs: 0 > Additional RRs: 0 > Queries > dc.domain.alt: type SOA, class IN > Name: dc.domain.alt > [Name Length: 13] > [Label Count: 3] > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > >Frame 8: 120 bytes on wire (960 bits), 120 bytes captured (960 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >User Datagram Protocol, Src Port: 53, Dst Port: 55924 >Domain Name System (response) > Transaction ID: 0x1f8f > Flags: 0x8480 Standard query response, No error > 1... .... .... .... = Response: Message is a response > .000 0... .... .... = Opcode: Standard query (0) > .... .1.. .... .... = Authoritative: Server is an authority for domain > .... ..0. .... .... = Truncated: Message is not truncated > .... ...0 .... .... = Recursion desired: Don't do query recursively > .... .... 1... .... = Recursion available: Server can do recursive queries > .... .... .0.. .... = Z: reserved (0) > .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server > .... .... ...0 .... = Non-authenticated data: Unacceptable > .... .... .... 0000 = Reply code: No error (0) > Questions: 1 > Answer RRs: 0 > Authority RRs: 1 > Additional RRs: 0 > Queries > dc.domain.alt: type SOA, class IN > Name: dc.domain.alt > [Name Length: 13] > [Label Count: 3] > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > Authoritative nameservers > domain.alt: type SOA, class IN, mname dc.domain.alt > Name: domain.alt > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > Time to live: 3600 (1 hour) > Data length: 35 > Primary name server: dc.domain.alt > Responsible authority's mailbox: hostmaster.domain.alt > Serial Number: 1 > Refresh Interval: 900 (15 minutes) > Retry Interval: 600 (10 minutes) > Expire limit: 86400 (1 day) > Minimum TTL: 3600 (1 hour) > [Request In: 7] > [Time: 0.000222479 seconds] > >Frame 9: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 50621, Dst Port: 53, Seq: 0, Len: 0 > >Frame 10: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 50621, Seq: 0, Ack: 1, Len: 0 > >Frame 11: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 50621, Dst Port: 53, Seq: 1, Ack: 1, Len: 0 > >Frame 12: 1435 bytes on wire (11480 bits), 1435 bytes captured (11480 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 50621, Dst Port: 53, Seq: 1, Ack: 1, Len: 1381 >Domain Name System (query) > Length: 1379 > Transaction ID: 0xe82e > Flags: 0x0000 Standard query > 0... .... .... .... = Response: Message is a query > .000 0... .... .... = Opcode: Standard query (0) > .... ..0. .... .... = Truncated: Message is not truncated > .... ...0 .... .... = Recursion desired: Don't do query recursively > .... .... .0.. .... = Z: reserved (0) > .... .... ...0 .... = Non-authenticated data: Unacceptable > Questions: 1 > Answer RRs: 0 > Authority RRs: 0 > Additional RRs: 1 > Queries > 2722618815.sig-dc.domain.alt: type TKEY, class ANY > Name: 2722618815.sig-dc.domain.alt > [Name Length: 28] > [Label Count: 4] > Type: TKEY (Transaction Key) (249) > Class: ANY (0x00ff) > Additional records > 2722618815.sig-dc.domain.alt: type TKEY, class ANY > Name: 2722618815.sig-dc.domain.alt > Type: TKEY (Transaction Key) (249) > Class: ANY (0x00ff) > Time to live: 0 (0 seconds) > Data length: 1321 > Algorithm name: gss-tsig > Signature Inception: Dec 15, 2020 16:53:55.000000000 +04 > Signature Expiration: Dec 15, 2020 16:53:55.000000000 +04 > Mode: GSSAPI (3) > Error: No error (0) > Key Size: 1295 > Key Data: 6082050b06092a864886f71201020201006e8204fa308204⦠> GSS-API Generic Security Service Application Program Interface > OID: 1.2.840.113554.1.2.2 (KRB5 - Kerberos 5) > krb5_blob: 01006e8204fa308204f6a003020105a10302010ea2070305⦠> krb5_tok_id: KRB5_AP_REQ (0x0001) > Kerberos > ap-req > pvno: 5 > msg-type: krb-ap-req (14) > Padding: 0 > ap-options: 20000000 > 0... .... = reserved: False > .0.. .... = use-session-key: False > ..1. .... = mutual-required: True > ticket > tkt-vno: 5 > realm: DOMAIN.ALT > sname > name-type: kRB5-NT-PRINCIPAL (1) > sname-string: 2 items > SNameString: DNS > SNameString: dc.domain.alt > enc-part > etype: eTYPE-AES256-CTS-HMAC-SHA1-96 (18) > kvno: 1 > cipher: 68af786580d8c09ee1104996f983b306d18fd1aa4793d8fe⦠> authenticator > etype: eTYPE-AES256-CTS-HMAC-SHA1-96 (18) > cipher: 9fc3a67e3f9572be4a406454e5f0d92f9fa9e8f32c5a91a5⦠> Other Size: 0 > >Frame 13: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 50621, Seq: 1, Ack: 1382, Len: 0 > >Frame 14: 418 bytes on wire (3344 bits), 418 bytes captured (3344 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 50621, Seq: 1, Ack: 1382, Len: 364 >Domain Name System (response) > Length: 362 > Transaction ID: 0xe82e > Flags: 0x8080 Standard query response, No error > 1... .... .... .... = Response: Message is a response > .000 0... .... .... = Opcode: Standard query (0) > .... .0.. .... .... = Authoritative: Server is not an authority for domain > .... ..0. .... .... = Truncated: Message is not truncated > .... ...0 .... .... = Recursion desired: Don't do query recursively > .... .... 1... .... = Recursion available: Server can do recursive queries > .... .... .0.. .... = Z: reserved (0) > .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server > .... .... ...0 .... = Non-authenticated data: Unacceptable > .... .... .... 0000 = Reply code: No error (0) > Questions: 1 > Answer RRs: 1 > Authority RRs: 0 > Additional RRs: 1 > Queries > 2722618815.sig-dc.domain.alt: type TKEY, class ANY > Name: 2722618815.sig-dc.domain.alt > [Name Length: 28] > [Label Count: 4] > Type: TKEY (Transaction Key) (249) > Class: ANY (0x00ff) > Answers > 2722618815.sig-dc.domain.alt: type TKEY, class ANY > Name: 2722618815.sig-dc.domain.alt > Type: TKEY (Transaction Key) (249) > Class: ANY (0x00ff) > Time to live: 0 (0 seconds) > Data length: 182 > Algorithm name: gss-tsig > Signature Inception: Dec 15, 2020 16:53:55.000000000 +04 > Signature Expiration: Dec 15, 2020 16:53:55.000000000 +04 > Mode: GSSAPI (3) > Error: No error (0) > Key Size: 156 > Key Data: 60819906092a864886f71201020202006f8189308186a003⦠> GSS-API Generic Security Service Application Program Interface > OID: 1.2.840.113554.1.2.2 (KRB5 - Kerberos 5) > krb5_blob: 02006f8189308186a003020105a10302010fa27a3078a003⦠> krb5_tok_id: KRB5_AP_REP (0x0002) > Kerberos > ap-rep > pvno: 5 > msg-type: krb-ap-rep (15) > enc-part > etype: eTYPE-AES256-CTS-HMAC-SHA1-96 (18) > cipher: 6f0d7b07e6a55f932063051c256061e07c2e5786a7ca3b08⦠> Other Size: 0 > Additional records > 2722618815.sig-dc.domain.alt: type TSIG, class ANY > Name: 2722618815.sig-dc.domain.alt > Type: TSIG (Transaction Signature) (250) > Class: ANY (0x00ff) > Time to live: 0 (0 seconds) > Data length: 54 > Algorithm Name: gss-tsig > Time Signed: Dec 15, 2020 16:53:55.000000000 +04 > Fudge: 300 > MAC Size: 28 > MAC > [Expert Info (Warning/Undecoded): No dissector for algorithm:gss-tsig] > [No dissector for algorithm:gss-tsig] > [Severity level: Warning] > [Group: Undecoded] > Original Id: 59438 > Error: No error (0) > Other Len: 0 > [Request In: 12] > [Time: 0.002976984 seconds] > >Frame 15: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 50621, Dst Port: 53, Seq: 1382, Ack: 365, Len: 0 > >Frame 16: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 52519, Dst Port: 53, Seq: 0, Len: 0 > >Frame 17: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 52519, Seq: 0, Ack: 1, Len: 0 > >Frame 18: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 52519, Dst Port: 53, Seq: 1, Ack: 1, Len: 0 > >Frame 19: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 50621, Dst Port: 53, Seq: 1382, Ack: 365, Len: 0 > >Frame 20: 197 bytes on wire (1576 bits), 197 bytes captured (1576 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 52519, Dst Port: 53, Seq: 1, Ack: 1, Len: 143 >Domain Name System (query) > Length: 141 > Transaction ID: 0x1254 > Flags: 0x2800 Dynamic update > 0... .... .... .... = Response: Message is a query > .010 1... .... .... = Opcode: Dynamic update (5) > .... ..0. .... .... = Truncated: Message is not truncated > .... ...0 .... .... = Recursion desired: Don't do query recursively > .... .... .0.. .... = Z: reserved (0) > .... .... ...0 .... = Non-authenticated data: Unacceptable > Zones: 1 > Prerequisites: 0 > Updates: 1 > Additional RRs: 1 > Zone > domain.alt: type SOA, class IN > Name: domain.alt > [Name Length: 10] > [Label Count: 2] > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > Updates > dc.domain.alt: type A, class IN, addr 10.64.128.2 > Name: dc.domain.alt > Type: A (Host Address) (1) > Class: IN (0x0001) > Time to live: 900 (15 minutes) > Data length: 4 > Address: 10.64.128.2 > Additional records > 2722618815.sig-dc.domain.alt: type TSIG, class ANY > Name: 2722618815.sig-dc.domain.alt > Type: TSIG (Transaction Signature) (250) > Class: ANY (0x00ff) > Time to live: 0 (0 seconds) > Data length: 54 > Algorithm Name: gss-tsig > Time Signed: Dec 15, 2020 16:53:55.000000000 +04 > Fudge: 300 > MAC Size: 28 > MAC > [Expert Info (Warning/Undecoded): No dissector for algorithm:gss-tsig] > [No dissector for algorithm:gss-tsig] > [Severity level: Warning] > [Group: Undecoded] > Original Id: 4692 > Error: No error (0) > Other Len: 0 > >Frame 21: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 52519, Seq: 1, Ack: 144, Len: 0 > >Frame 22: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 50621, Seq: 365, Ack: 1383, Len: 0 > >Frame 23: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 50621, Dst Port: 53, Seq: 1383, Ack: 366, Len: 0 > >Frame 24: 197 bytes on wire (1576 bits), 197 bytes captured (1576 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 52519, Seq: 1, Ack: 144, Len: 143 >Domain Name System (response) > Length: 141 > Transaction ID: 0x1254 > Flags: 0xa880 Dynamic update response, No error > 1... .... .... .... = Response: Message is a response > .010 1... .... .... = Opcode: Dynamic update (5) > .... .0.. .... .... = Authoritative: Server is not an authority for domain > .... ..0. .... .... = Truncated: Message is not truncated > .... ...0 .... .... = Recursion desired: Don't do query recursively > .... .... 1... .... = Recursion available: Server can do recursive queries > .... .... .0.. .... = Z: reserved (0) > .... .... ..0. .... = Answer authenticated: Answer/authority portion was not authenticated by the server > .... .... ...0 .... = Non-authenticated data: Unacceptable > .... .... .... 0000 = Reply code: No error (0) > Zones: 1 > Prerequisites: 0 > Updates: 1 > Additional RRs: 1 > Zone > domain.alt: type SOA, class IN > Name: domain.alt > [Name Length: 10] > [Label Count: 2] > Type: SOA (Start Of a zone of Authority) (6) > Class: IN (0x0001) > Updates > dc.domain.alt: type A, class IN, addr 10.64.128.2 > Name: dc.domain.alt > Type: A (Host Address) (1) > Class: IN (0x0001) > Time to live: 900 (15 minutes) > Data length: 4 > Address: 10.64.128.2 > Additional records > 2722618815.sig-dc.domain.alt: type TSIG, class ANY > Name: 2722618815.sig-dc.domain.alt > Type: TSIG (Transaction Signature) (250) > Class: ANY (0x00ff) > Time to live: 0 (0 seconds) > Data length: 54 > Algorithm Name: gss-tsig > Time Signed: Dec 15, 2020 16:53:56.000000000 +04 > Fudge: 300 > MAC Size: 28 > MAC > [Expert Info (Warning/Undecoded): No dissector for algorithm:gss-tsig] > [No dissector for algorithm:gss-tsig] > [Severity level: Warning] > [Group: Undecoded] > Original Id: 4692 > Error: No error (0) > Other Len: 0 > [Request In: 20] > [Time: 0.622232899 seconds] > >Frame 25: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 52519, Dst Port: 53, Seq: 144, Ack: 144, Len: 0 > >Frame 26: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 52519, Dst Port: 53, Seq: 144, Ack: 144, Len: 0 > >Frame 27: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 53, Dst Port: 52519, Seq: 144, Ack: 145, Len: 0 > >Frame 28: 54 bytes on wire (432 bits), 54 bytes captured (432 bits) on interface lo, id 0 >Ethernet II, Src: 00:00:00_00:00:00 (00:00:00:00:00:00), Dst: 00:00:00_00:00:00 (00:00:00:00:00:00) >Internet Protocol Version 4, Src: 10.64.128.2, Dst: 10.64.128.2 >Transmission Control Protocol, Src Port: 52519, Dst Port: 53, Seq: 145, Ack: 145, Len: 0 > >^C28 packets captured >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 39440
:
9082
| 9084