Package: bind9
Version: 1:9.9.5.dfsg-9+deb8u10
Followup-For: Bug #860225
Dear Maintainer,
*** Reporter, please consider answering these questions, where appropriate ***
* What led up to the situation?
* What exactly did you do (or not do) that was effective (or
ineffective)?
* What was the outcome of this action?
* What outcome did you expect instead?
*** End of the template - remove these template lines ***
-- System Information:
Debian Release: 8.7
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 3.16.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)
Versions of packages bind9 depends on:
ii adduser 3.113+nmu3
ii bind9utils 1:9.9.5.dfsg-9+deb8u10
ii debconf [debconf-2.0] 1.5.56
ii init-system-helpers 1.22
ii libbind9-90 1:9.9.5.dfsg-9+deb8u10
ii libc6 2.19-18+deb8u7
ii libcap2 1:2.24-8
ii libcomerr2 1.42.12-2+b1
ii libdns100 1:9.9.5.dfsg-9+deb8u10
ii libgssapi-krb5-2 1.12.1+dfsg-19+deb8u2
ii libisc95 1:9.9.5.dfsg-9+deb8u10
ii libisccc90 1:9.9.5.dfsg-9+deb8u10
ii libisccfg90 1:9.9.5.dfsg-9+deb8u10
ii libk5crypto3 1.12.1+dfsg-19+deb8u2
ii libkrb5-3 1.12.1+dfsg-19+deb8u2
ii liblwres90 1:9.9.5.dfsg-9+deb8u10
ii libssl1.0.0 1.0.1t-1+deb8u6
ii libxml2 2.9.1+dfsg1-5+deb8u4
ii lsb-base 4.1+Debian13+nmu1
ii net-tools 1.60-26+b1
ii netbase 5.3
bind9 recommends no packages.
Versions of packages bind9 suggests:
pn bind9-doc <none>
ii dnsutils 1:9.9.5.dfsg-9+deb8u10
pn resolvconf <none>
pn ufw <none>
-- Configuration Files:
/etc/bind/named.conf.local changed:
//
// Do any local configuration here
//
// Consider adding the 1918 zones here, if they are not used in your
// organization
//include "/etc/bind/zones.rfc1918";
// zone di cui ns2 e' slave di ns1
include "/etc/bind/named.conf.local.slave";
//zone di reverse
include "/etc/bind/named.conf.local.reverse";
// zone di cui ns2 e' slave di server clienti
include "/etc/bind/named.conf.local.slave_ext";
// zone bloccate dall'autority;
include "/etc/bind/named.conf.local.bloccati";
//
// Aggiungere qui solamente le zone MASTER
//
zone "acantho.net" IN {
type master;
file "/etc/bind/master/acantho.net";
};
// *************
//
// le zone seguenti sono interne ad acantho, e devono avere la restrizione:
// allow-query { dns-allowed-internal; };
//
// ************
zone "acantho.nt" IN {
type master;
file "/etc/bind/master/acantho.nt";
allow-query { dns-allowed-internal; };
};
zone "acantho.idc" IN {
type master;
file "/etc/bind/master/acantho.idc";
};
zone "noc.acantho.idc" {
type master; // what used to be called "primary"
file "/etc/bind/master/noc.acantho.idc";
allow-query { dns-allowed-internal; };
sig-validity-interval 990;
};
zone "acantho.sys" {
type master; // what used to be called "primary"
file "/etc/bind/master/acantho.sys";
allow-query { dns-allowed-internal; };
};
-- debconf information:
bind9/different-configuration-file:
bind9/start-as-user: bind
bind9/run-resolvconf: false
root@ns2:/var/log# grep named syslog | grep " 13:1"
Apr 27 13:10:23 ns2 named[29566]: rate-limit: would stop limiting NXDOMAIN
responses to 213.209.226.5/32 for smg.ultra.brightmail.com (3b7d8bd6)
Apr 27 13:10:47 ns2 named[29566]: rate-limit: would continue limiting NXDOMAIN
responses to 213.174.182.194/32 for zen.spamhaus.org (393fe905)
Apr 27 13:11:05 ns2 named[29566]: rate-limit: would continue limiting NXDOMAIN
responses to 77.89.18.196/32 for zen.spamhaus.org (393fe905)
Apr 27 13:11:05 ns2 named[29566]: rate-limit: would continue limiting NXDOMAIN
responses to 77.89.18.196/32 for sbl.spamhaus.org (393fe6b1)
Apr 27 13:11:45 ns2 named[29566]: general: resolver.c:4350: INSIST(fctx->type
== ((dns_rdatatype_t)dns_rdatatype_any) || fctx->type ==
((dns_rdatatype_t)dns_rdatatype_rrsig) || fctx->type ==
((dns_rdatatype_t)dns_rdatatype_sig)) failed, back trace
Apr 27 13:11:45 ns2 named[29566]: general: #0 0x7fcb266dfa00 in ??
Apr 27 13:11:45 ns2 named[29566]: general: #1 0x7fcb248bb8ea in ??
Apr 27 13:11:45 ns2 named[29566]: general: #2 0x7fcb25fa114e in ??
Apr 27 13:11:45 ns2 named[29566]: general: #3 0x7fcb248ddd5b in ??
Apr 27 13:11:45 ns2 named[29566]: general: #4 0x7fcb2428e064 in ??
Apr 27 13:11:45 ns2 named[29566]: general: #5 0x7fcb23c5c62d in ??
Apr 27 13:11:45 ns2 named[29566]: general: exiting (due to assertion failure)
This issiue is very critical for us!
This event happended twice in three days.
Best regards.
Luca Galassi
Acantho