On the latest stable freeipa on v9, in a two-master setup: after a
period of normal operations, I need to reboot one of them. When that
happens, each boot, nslookup times out on the newly rebooted one, even
after named has been running for minutes.
The logs are filled with such as (signed) zones sending and receiving
'notifies', sometimes on v6 interfaces and sometimes on v4, often for
the same zones, with slightly increasing serial numbers. DNSSec is
active on most zones.
During that time, 'nslookups' on the most recently booted machine time
out. Letting time pass (usually 10 to 15 minutes) this 'notify storm'
settles and normal bind/named operations commence. Operations on the
other node (not rebooted) remain normal throughout, though its logs too
are filled with 'notifies' received on v4 and v6, but not sent.
What can be done? I don't mind the 'notify storm' as such, but during
that I need resolution to occur. What am I missing?
Thanks!
Harry Coin
Show replies by date