Hi. My named-pkcs11 (9.11.26-6.el8 on EL8.5 clearly) seems to be taking on the order of about 25 minutes to be ready to serve it's local zones after a reload. During that time, queries for the local zones fail.
From my journal of a reload (it looks like there were actually two -- both a result of logrotate): Feb 20 03:49:01 server.example.com systemd[1]: Reloading Berkeley Internet Name Domain (DNS) with native PKCS#11. Feb 20 03:49:09 server.example.com sh[1708198]: WARNING: key file (/etc/rndc.key) exists, but using default configuration file (/etc/rndc.conf) Feb 20 03:49:09 server.example.com named-pkcs11[1593328]: received control channel command 'reload' Feb 20 03:49:11 server.example.com named-pkcs11[1593328]: zone 22.75.10.in-addr.arpa/IN: shutting down Feb 20 03:49:11 server.example.com named-pkcs11[1593328]: zone 0.8.10.in-addr.arpa/IN: shutting down Feb 20 03:49:11 server.example.com named-pkcs11[1593328]: zone 101.168.192.in-addr.arpa/IN: shutting down Feb 20 03:49:12 server.example.com named-pkcs11[1593328]: zone a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN: shutting down Feb 20 03:49:12 server.example.com named-pkcs11[1593328]: zone 3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: shutting down Feb 20 03:49:12 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: shutting down Feb 20 03:49:12 server.example.com named-pkcs11[1593328]: zone 0.0.7.1.0.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: checkhints: unable to get root NS rrset from cache: not found Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone 0.0.6.d.1.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone 0.0.9.2.3.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone 2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.f.d.8.4.1.b.e.a.1.3.d.f.ip6.arpa/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone 2.6.5.c.c.9.2.c.4.0.6.5.c.8.d.f.ip6.arpa/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone example.com/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: zone rbl.example.com/IN: shutting down Feb 20 03:49:13 server.example.com named-pkcs11[1593328]: checkhints: unable to get root NS rrset from cache: not found Feb 20 03:49:14 server.example.com httpd[85393]: Server configured, listening on: port 443, port 80 Feb 20 03:49:15 server.example.com named-pkcs11[1593328]: zone joip.com/IN: shutting down Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: loading configuration from '/etc/named.conf' Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: unable to open '/etc/bind.keys'; using built-in keys instead Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: looking for GeoIP2 databases in '/usr/share/GeoIP' Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: using default UDP/IPv4 port range: [32768, 60999] Feb 20 03:50:30 server.example.com named-pkcs11[1593328]: using default UDP/IPv6 port range: [32768, 60999] Feb 20 03:50:31 server.example.com named-pkcs11[1593328]: sizing zone task pool based on 13 zones Feb 20 03:50:32 server.example.com named-pkcs11[1593328]: none:105: 'max-cache-size 90%' - setting to 6889MB (out of 7654MB) Feb 20 03:50:32 server.example.com named-pkcs11[1593328]: dns64 reverse zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.b.9.f.f.4.6.0.0.ip6.arpa. Feb 20 03:50:33 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:50:33 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:50:33 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:50:33 server.example.com named-pkcs11[1593328]: GSSAPI client step 2 Feb 20 03:50:33 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:50:33 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: GSSAPI client step 2 Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 10.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 16.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 17.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 18.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 19.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 20.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 21.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 22.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 23.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 24.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 25.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 26.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 27.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 28.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 29.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 30.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 31.172.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 168.192.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 64.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 65.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 66.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 67.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 68.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 69.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 70.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 71.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 72.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 73.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 74.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 75.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 76.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 77.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 78.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 79.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 80.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 81.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 82.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 83.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 84.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 85.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 86.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 87.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 88.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 89.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 90.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 91.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 92.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 93.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 94.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 95.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 96.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 97.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 98.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 99.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 100.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 101.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 102.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 103.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 104.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 105.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 106.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 107.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 108.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 109.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 110.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 111.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 112.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 113.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 114.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 115.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 116.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 117.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 118.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 119.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 120.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 121.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 122.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 123.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 124.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 125.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 126.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 127.100.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 127.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 254.169.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: D.F.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 8.E.F.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 9.E.F.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: A.E.F.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: B.E.F.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: EMPTY.AS112.ARPA Feb 20 03:50:34 server.example.com named-pkcs11[1593328]: automatic empty zone: HOME.ARPA Feb 20 03:50:35 server.example.com named-pkcs11[1593328]: none:105: 'max-cache-size 90%' - setting to 6889MB (out of 7654MB) Feb 20 03:50:35 server.example.com named-pkcs11[1593328]: configuring command channel from '/etc/rndc.key' Feb 20 03:50:35 server.example.com named-pkcs11[1593328]: configuring command channel from '/etc/rndc.key' Feb 20 03:50:35 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.b.9.f.f.4.6.0.0.ip6.arpa/IN: (master) removed Feb 20 03:50:36 server.example.com named-pkcs11[1593328]: reloading configuration succeeded Feb 20 03:50:36 server.example.com named-pkcs11[1593328]: reloading zones succeeded Feb 20 03:50:36 server.example.com sh[1708198]: server reload successful Feb 20 03:50:36 server.example.com systemd[1]: Reloaded Berkeley Internet Name Domain (DNS) with native PKCS#11. Feb 20 03:51:20 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:20 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:20 server.example.com named-pkcs11[1593328]: managed-keys-zone: Unable to fetch DNSKEY set '.': timed out Feb 20 03:51:20 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:20 server.example.com named-pkcs11[1593328]: GSSAPI client step 2 Feb 20 03:51:21 server.example.com named-pkcs11[1593328]: all zones loaded Feb 20 03:51:21 server.example.com systemd[1]: Reloading Berkeley Internet Name Domain (DNS) with native PKCS#11. Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: running Feb 20 03:51:22 server.example.com sh[1708655]: WARNING: key file (/etc/rndc.key) exists, but using default configuration file (/etc/rndc.conf) Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: received control channel command 'reload' Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: loading configuration from '/etc/named.conf' Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: unable to open '/etc/bind.keys'; using built-in keys instead Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: looking for GeoIP2 databases in '/usr/share/GeoIP' Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-Country.mmdb' Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: opened GeoIP2 database '/usr/share/GeoIP/GeoLite2-City.mmdb' Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: using default UDP/IPv4 port range: [32768, 60999] Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: using default UDP/IPv6 port range: [32768, 60999] Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: sizing zone task pool based on 13 zones Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: none:105: 'max-cache-size 90%' - setting to 6889MB (out of 7654MB) Feb 20 03:51:22 server.example.com named-pkcs11[1593328]: dns64 reverse zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.b.9.f.f.4.6.0.0.ip6.arpa. Feb 20 03:51:22 server.example.com ns-slapd[1840]: [20/Feb/2022:03:51:22.710241429 -0500] - NOTICE - ldbm_back_search - Unindexed search: search base="cn=dns,dc=example,dc=com" scope=2 filter="(|(objectClass=idnsConfigObject)(&(objectClass=idnsServerConfigObject)(idnsServerId=server.example.com))(|(objectClass=idnsZone)(objectClass=idnsForwardZone)(objectClass=idnsRecord)))" conn=11939 op=3 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 2 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: GSSAPI client step 2 Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 10.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 16.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 17.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 18.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 19.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 20.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 21.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 22.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 23.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 24.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 25.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 26.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 27.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 28.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 29.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 30.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 31.172.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 168.192.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 64.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 65.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 66.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 67.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 68.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 69.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 70.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 71.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 72.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 73.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 74.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 75.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 76.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 77.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 78.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 79.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 80.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 81.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 82.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 83.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 84.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 85.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 86.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 87.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 88.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 89.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 90.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 91.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 92.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 93.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 94.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 95.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 96.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 97.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 98.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 99.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 100.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 101.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 102.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 103.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 104.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 105.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 106.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 107.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 108.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 109.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 110.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 111.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 112.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 113.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 114.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 115.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 116.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 117.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 118.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 119.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 120.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 121.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 122.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 123.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 124.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 125.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 126.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 127.100.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 127.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 254.169.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 2.0.192.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 100.51.198.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 113.0.203.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 255.255.255.255.IN-ADDR.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: D.F.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 8.E.F.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 9.E.F.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: A.E.F.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: B.E.F.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: 8.B.D.0.1.0.0.2.IP6.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: EMPTY.AS112.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: automatic empty zone: HOME.ARPA Feb 20 03:51:30 server.example.com named-pkcs11[1593328]: none:105: 'max-cache-size 90%' - setting to 6889MB (out of 7654MB) Feb 20 03:51:37 server.example.com named-pkcs11[1593328]: configuring command channel from '/etc/rndc.key' Feb 20 03:51:37 server.example.com named-pkcs11[1593328]: configuring command channel from '/etc/rndc.key' Feb 20 03:51:37 server.example.com systemd[1]: Reloaded Berkeley Internet Name Domain (DNS) with native PKCS#11. Feb 20 03:51:37 server.example.com sh[1708655]: server reload successful Feb 20 03:51:37 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.b.9.f.f.4.6.0.0.ip6.arpa/IN: (master) removed Feb 20 03:51:37 server.example.com named-pkcs11[1593328]: reloading configuration succeeded Feb 20 03:51:37 server.example.com named-pkcs11[1593328]: reloading zones succeeded Feb 20 03:51:38 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:38 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:38 server.example.com named-pkcs11[1593328]: all zones loaded Feb 20 03:51:38 server.example.com named-pkcs11[1593328]: running Feb 20 03:51:38 server.example.com named-pkcs11[1593328]: GSSAPI client step 1 Feb 20 03:51:38 server.example.com named-pkcs11[1593328]: GSSAPI client step 2 Feb 20 03:51:38 server.example.com ns-slapd[1840]: [20/Feb/2022:03:51:38.637062550 -0500] - NOTICE - ldbm_back_search - Unindexed search: search base="cn=dns,dc=example,dc=com" scope=2 filter="(|(objectClass=idnsConfigObject)(&(objectClass=idnsServerConfigObject)(idnsServerId=server.example.com))(|(objectClass=idnsZone)(objectClass=idnsForwardZone)(objectClass=idnsRecord)))" conn=11942 op=3 Feb 20 03:51:39 server.example.com named-pkcs11[1593328]: managed-keys-zone: Key 20326 for zone . acceptance timer complete: key now trusted Feb 20 03:51:41 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=example.com.,cn=dns,dc=example,dc=com fa486b2d-3df5-11e5-b0d0-8e21c4e9261b Feb 20 03:51:41 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1411 Feb 20 03:51:43 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.0.0.0.f.d.8.4.1.b.e.a.1.3.d.f.ip6.arpa.,cn=dns,dc=example,dc=com fa486b31-3df5-11e5-b0d0-8e21c4e9261b Feb 20 03:51:43 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1412 Feb 20 03:51:44 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com fa486b33-3df5-11e5-b0d0-8e21c4e9261b Feb 20 03:51:44 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1413 Feb 20 03:51:45 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.0.0.0.3.d.5.d.1.c.3.4.2.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com fa486b35-3df5-11e5-b0d0-8e21c4e9261b Feb 20 03:51:45 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1414 Feb 20 03:51:48 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=22.75.10.in-addr.arpa.,cn=dns,dc=example,dc=com fa486b37-3df5-11e5-b0d0-8e21c4e9261b Feb 20 03:51:48 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1415 Feb 20 03:51:49 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.8.10.in-addr.arpa.,cn=dns,dc=example,dc=com 43bdb682-3ed9-11e5-b0d0-8e21c4e9261b Feb 20 03:51:49 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1416 Feb 20 03:51:51 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa.,cn=dns,dc=example,dc=com 1ed0b809-82fd-11e5-93a0-8e21c4e9261b Feb 20 03:51:51 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1417 Feb 20 03:51:53 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=joip.com.,cn=dns,dc=example,dc=com d0d05586-f36c-11e5-8ec6-8e21c4e9261b Feb 20 03:51:53 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1418 Feb 20 03:51:54 server.example.com named-pkcs11[1593328]: zone 10.IN-ADDR.ARPA/IN: shutting down Feb 20 03:51:55 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.0.7.1.0.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com 86728702-c388-11e6-bbce-8e21c4e9261b Feb 20 03:51:55 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1419 Feb 20 03:51:56 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=101.168.192.in-addr.arpa.,cn=dns,dc=example,dc=com 59274702-eebf-11e7-82b4-8e21c4e9261b Feb 20 03:51:56 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1420 Feb 20 03:51:59 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=rbl.example.com.,cn=dns,dc=example,dc=com 9d5d0506-4c6f-11e8-be06-8e21c4e9261b Feb 20 03:51:59 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1421 Feb 20 03:52:02 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.0.9.2.3.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com c5593001-c8c1-11e8-a42f-8e21c4e9261b Feb 20 03:52:02 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1422 Feb 20 03:52:05 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.0.6.d.1.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com b33bcc01-08c9-11e9-803d-8e21c4e9261b Feb 20 03:52:05 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1423 Feb 20 03:52:08 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=2.6.5.c.c.9.2.c.4.0.6.5.c.8.d.f.ip6.arpa.,cn=dns,dc=example,dc=com 79072a01-112b-11ea-b32b-8e21c4e9261b Feb 20 03:52:08 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1424 Feb 20 03:52:09 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=0.0.0.0.3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com e3beaa01-ce24-11eb-8263-8e21c4e9261b Feb 20 03:52:09 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1425 Feb 20 03:52:17 server.example.com logrotate[1708733]: ALERT exited abnormally with [1] Feb 20 03:52:17 server.example.com run-parts[1708735]: (/etc/cron.daily) finished logrotate Feb 20 03:58:21 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 03:58:21 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1617/info Feb 20 03:58:21 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 03:58:21 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1619/info Feb 20 03:58:21 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 03:58:21 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt161b/info Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt161d/info Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt161d/info Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt161f/info Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:00:12 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1621/info Feb 20 04:01:01 server.example.com CROND[1709388]: (root) CMD (run-parts /etc/cron.hourly) Feb 20 04:01:01 server.example.com run-parts[1709391]: (/etc/cron.hourly) starting 0anacron Feb 20 04:01:02 server.example.com anacron[1709397]: Anacron started on 2022-02-20 Feb 20 04:01:02 server.example.com run-parts[1709399]: (/etc/cron.hourly) finished 0anacron Feb 20 04:01:02 server.example.com run-parts[1709401]: (/etc/cron.hourly) starting voipbl_org Feb 20 04:01:02 server.example.com anacron[1709397]: Job `cron.daily' locked by another anacron - skipping Feb 20 04:01:02 server.example.com anacron[1709397]: Normal exit (0 jobs run) Feb 20 04:01:30 server.example.com sssd_be[1225]: GSSAPI client step 1 Feb 20 04:01:30 server.example.com sssd_be[1225]: GSSAPI client step 1 Feb 20 04:01:30 server.example.com sssd_be[1225]: GSSAPI client step 1 Feb 20 04:01:30 server.example.com sssd_be[1225]: GSSAPI client step 2 Feb 20 04:02:15 server.example.com rsyslogd[1799]: [origin software="rsyslogd" swVersion="8.2102.0-5.el8" x-pid="1799" x-info="https://www.rsyslog.com"] rsyslogd was HUPed Feb 20 04:03:18 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:03:18 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1623/info Feb 20 04:03:18 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:03:18 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1625/info Feb 20 04:03:18 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:03:18 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1627/info Feb 20 04:05:48 server.example.com anacron[1704693]: Job `cron.daily' terminated (produced output) Feb 20 04:05:49 server.example.com anacron[1704693]: Normal exit (1 job run) Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1629/info Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1629/info Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt162b/info Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:06:03 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt162d/info Feb 20 04:06:36 server.example.com named-pkcs11[1593328]: client @0x7f9a48307110 140.238.153.74#44385 (a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa): bad zone transfer request: 'a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN': non-authoritative zone (NOTAUTH) Feb 20 04:06:36 server.example.com named-pkcs11[1593328]: client @0x7f9a473957d0 fd8c:5604:c29c:c562::1001#38333 (a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa): bad zone transfer request: 'a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN': non-authoritative zone (NOTAUTH) Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt162f/info Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt162f/info Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1631/info Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: unable to resolve 2001:123:aa:123:0:90cc:a629:cf42:5877 to hostname: Name or service not known Feb 20 04:14:00 server.example.com rpc.gssd[1849]: ERROR: failed to parse nfs/clnt1633/info Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.519225905 -0500] - ERR - _entry_set_tombstone_rdn - Failed to convert DN cn=KDC to RDN Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.606982072 -0500] - ERR - id2entry - str2entry returned NULL for id 134196, string="rdn" Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.648749894 -0500] - ERR - _entry_set_tombstone_rdn - Failed to convert DN cn=KPASSWD to RDN Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.690446337 -0500] - ERR - id2entry - str2entry returned NULL for id 134197, string="rdn" Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.747113034 -0500] - ERR - _entry_set_tombstone_rdn - Failed to convert DN cn=HTTP to RDN Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.827238589 -0500] - ERR - id2entry - str2entry returned NULL for id 134198, string="rdn" Feb 20 04:15:12 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:12.949172078 -0500] - ERR - _entry_set_tombstone_rdn - Failed to convert DN cn=OTPD to RDN Feb 20 04:15:13 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:13.022169147 -0500] - ERR - id2entry - str2entry returned NULL for id 134199, string="rdn" Feb 20 04:15:13 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:13.078265941 -0500] - ERR - _entry_set_tombstone_rdn - Failed to convert DN cn=KEYS to RDN Feb 20 04:15:13 server.example.com ns-slapd[1840]: [20/Feb/2022:04:15:13.173632231 -0500] - ERR - id2entry - str2entry returned NULL for id 134200, string="rdn" Feb 20 04:15:14 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG Detected modify of entry: idnsname=3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa.,cn=dns,dc=example,dc=com 8d1f2201-91a2-11ec-88b1-dfbaae19c7b5 Feb 20 04:15:14 server.example.com ipa-dnskeysyncd[4725]: ipaserver.dnssec.syncrepl: DEBUG New cookie is: server.example.com:389#krbprincipalname=ipa-dnskeysyncd/[email protected],cn=services,cn=accounts,dc=example,dc=com:cn=dns,dc=example,dc=com:(|(objectClass=idnsZone)(objectClass=idnsSecKey)(objectClass=ipk11PublicKey))#1426 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 22.75.10.in-addr.arpa/IN: loaded serial 1645347105 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 22.75.10.in-addr.arpa/IN: sending notifies (serial 1645347105) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.8.10.in-addr.arpa/IN: loaded serial 1645347108 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 101.168.192.in-addr.arpa/IN: loaded serial 1645347114 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.8.10.in-addr.arpa/IN: sending notifies (serial 1645347108) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN: loaded serial 1645347103 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 101.168.192.in-addr.arpa/IN: sending notifies (serial 1645347114) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347103) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: loaded serial 1645348513 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: loaded serial 1645347128 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.7.1.0.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: loaded serial 1645347113 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.6.d.1.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: loaded serial 1645347122 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645348513) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.9.2.3.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: loaded serial 1645347120 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.6.d.1.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347122) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347128) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.7.1.0.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347113) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.9.2.3.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347120) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa/IN: loaded serial 1645347109 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa/IN: sending notifies (serial 1645347109) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.f.d.8.4.1.b.e.a.1.3.d.f.ip6.arpa/IN: loaded serial 1645347102 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.f.d.8.4.1.b.e.a.1.3.d.f.ip6.arpa/IN: sending notifies (serial 1645347102) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 2.6.5.c.c.9.2.c.4.0.6.5.c.8.d.f.ip6.arpa/IN: loaded serial 1645347125 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 2.6.5.c.c.9.2.c.4.0.6.5.c.8.d.f.ip6.arpa/IN: sending notifies (serial 1645347125) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone example.com/IN: loaded serial 1645347100 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone example.com/IN: sending notifies (serial 1645347100) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone rbl.example.com/IN: loaded serial 1645347116 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone rbl.example.com/IN: sending notifies (serial 1645347116) Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone joip.com/IN: loaded serial 1645347111 Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone joip.com/IN: sending notifies (serial 1645347111) Feb 20 04:15:15 server.example.com named-pkcs11[1593328]: checkhints: unable to get root NS rrset from cache: not found Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 22.75.10.in-addr.arpa/IN: sending notifies (serial 1645347105) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 0.8.10.in-addr.arpa/IN: sending notifies (serial 1645347108) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 101.168.192.in-addr.arpa/IN: sending notifies (serial 1645347114) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347103) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645348513) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 0.0.6.d.1.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347122) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.3.2.1.a.a.3.2.1.0.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347128) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 0.0.9.2.3.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347120) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa/IN: sending notifies (serial 1645347109) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 0.0.7.1.0.3.2.1.6.8.7.3.1.0.0.2.ip6.arpa/IN: sending notifies (serial 1645347113) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 0.0.0.0.f.d.8.4.1.b.e.a.1.3.d.f.ip6.arpa/IN: sending notifies (serial 1645347102) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone 2.6.5.c.c.9.2.c.4.0.6.5.c.8.d.f.ip6.arpa/IN: sending notifies (serial 1645347125) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone example.com/IN: sending notifies (serial 1645347100) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone rbl.example.com/IN: sending notifies (serial 1645347116) Feb 20 04:15:19 server.example.com named-pkcs11[1593328]: zone joip.com/IN: sending notifies (serial 1645347111) Feb 20 04:16:16 server.example.com named-pkcs11[1593328]: client @0x7f9a4863a7b0 140.238.153.74#52749 (2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa): transfer of '2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa/IN': AXFR-style IXFR started (serial 1645347109) Feb 20 04:16:16 server.example.com named-pkcs11[1593328]: client @0x7f9a4863a7b0 140.238.153.74#52749 (2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa): transfer of '2.3.4.5.6.7.8.9.d.c.b.a.7.0.6.2.ip6.arpa/IN': AXFR-style IXFR ended Feb 20 04:16:30 server.example.com sssd_be[1225]: GSSAPI client step 1 Feb 20 04:16:30 server.example.com sssd_be[1225]: GSSAPI client step 1 Feb 20 04:16:30 server.example.com sssd_be[1225]: GSSAPI client step 1 Feb 20 04:16:30 server.example.com sssd_be[1225]: GSSAPI client step 2 Feb 20 04:19:08 server.example.com named-pkcs11[1593328]: client @0x7f9a4855a3e0 140.238.153.74#44705 (a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa): transfer of 'a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN': AXFR-style IXFR started (serial 1645347103) Feb 20 04:19:08 server.example.com named-pkcs11[1593328]: client @0x7f9a4855a3e0 140.238.153.74#44705 (a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa): transfer of 'a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN': AXFR-style IXFR ended Notice the huge gap of time between: Feb 20 03:51:54 server.example.com named-pkcs11[1593328]: zone 10.IN-ADDR.ARPA/IN: shutting down and: Feb 20 04:15:14 server.example.com named-pkcs11[1593328]: zone 22.75.10.in-addr.arpa/IN: loaded serial 1645347105 Where even within that gap, named clearly is not serving the local zones: Feb 20 04:06:36 server.example.com named-pkcs11[1593328]: client @0x7f9a48307110 140.238.153.74#44385 (a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa): bad zone transfer request: 'a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN': non-authoritative zone (NOTAUTH) Feb 20 04:06:36 server.example.com named-pkcs11[1593328]: client @0x7f9a473957d0 fd8c:5604:c29c:c562::1001#38333 (a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa): bad zone transfer request: 'a.b.c.d.e.1.2.3.4.5.0.1.0.0.2.ip6.arpa/IN': non-authoritative zone (NOTAUTH) Any ideas on why the huge delay in serving local zones on reload? Cheers, b.
signature.asc
Description: This is a digitally signed message part
_______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
