Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 24

Thread: LDAP Cannot bind on migration to new server

  1. #11
    drizzt's Avatar
    drizzt is offline Intermediate Member
    Join Date
    Nov 2008
    Location
    Pavia (Italia)
    Posts
    19
    Rep Power
    6

    Default

    cat /etc/hosts
    Code:
    127.0.0.1 localhost
    78.46.91.12  smtp.netjungle.it smtp
    cat /etc/resolv.conf
    Code:
    nameserver 127.0.0.1
    # hetzner
    nameserver 213.133.98.98
    nameserver 213.133.99.99
    nameserver 213.133.100.100
    # opendns
    nameserver 208.67.222.222
    nameserver 208.67.220.220
    dig netjungle.it MX
    Code:
    ; <<>> DiG 9.4.2-P2 <<>> netjungle.it MX
    ;; global options:  printcmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50075
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 13, ADDITIONAL: 1
    
    ;; QUESTION SECTION:
    ;netjungle.it.			IN	MX
    
    ;; ANSWER SECTION:
    netjungle.it.		3600	IN	MX	20 smtp2.netjungle.it.
    netjungle.it.		3600	IN	MX	10 smtp.netjungle.it.
    
    ;; AUTHORITY SECTION:
    .			29597	IN	NS	C.ROOT-SERVERS.NET.
    .			29597	IN	NS	H.ROOT-SERVERS.NET.
    .			29597	IN	NS	K.ROOT-SERVERS.NET.
    .			29597	IN	NS	L.ROOT-SERVERS.NET.
    .			29597	IN	NS	I.ROOT-SERVERS.NET.
    .			29597	IN	NS	M.ROOT-SERVERS.NET.
    .			29597	IN	NS	D.ROOT-SERVERS.NET.
    .			29597	IN	NS	B.ROOT-SERVERS.NET.
    .			29597	IN	NS	J.ROOT-SERVERS.NET.
    .			29597	IN	NS	E.ROOT-SERVERS.NET.
    .			29597	IN	NS	A.ROOT-SERVERS.NET.
    .			29597	IN	NS	G.ROOT-SERVERS.NET.
    .			29597	IN	NS	F.ROOT-SERVERS.NET.
    
    ;; ADDITIONAL SECTION:
    smtp.netjungle.it.	2592000	IN	A	127.0.0.1
    
    ;; Query time: 110 msec
    ;; SERVER: 127.0.0.1#53(127.0.0.1)
    ;; WHEN: Mon Mar  2 14:13:36 2009
    ;; MSG SIZE  rcvd: 300
    dig netjungle.it ANY
    Code:
    ; <<>> DiG 9.4.2-P2 <<>> netjungle.it ANY
    ;; global options:  printcmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23037
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 13, ADDITIONAL: 1
    
    ;; QUESTION SECTION:
    ;netjungle.it.			IN	ANY
    
    ;; ANSWER SECTION:
    netjungle.it.		3542	IN	MX	10 smtp.netjungle.it.
    netjungle.it.		3542	IN	MX	20 smtp2.netjungle.it.
    
    ;; AUTHORITY SECTION:
    .			29539	IN	NS	B.ROOT-SERVERS.NET.
    .			29539	IN	NS	I.ROOT-SERVERS.NET.
    .			29539	IN	NS	J.ROOT-SERVERS.NET.
    .			29539	IN	NS	A.ROOT-SERVERS.NET.
    .			29539	IN	NS	E.ROOT-SERVERS.NET.
    .			29539	IN	NS	D.ROOT-SERVERS.NET.
    .			29539	IN	NS	H.ROOT-SERVERS.NET.
    .			29539	IN	NS	C.ROOT-SERVERS.NET.
    .			29539	IN	NS	K.ROOT-SERVERS.NET.
    .			29539	IN	NS	F.ROOT-SERVERS.NET.
    .			29539	IN	NS	L.ROOT-SERVERS.NET.
    .			29539	IN	NS	G.ROOT-SERVERS.NET.
    .			29539	IN	NS	M.ROOT-SERVERS.NET.
    
    ;; ADDITIONAL SECTION:
    smtp.netjungle.it.	2592000	IN	A	127.0.0.1
    
    ;; Query time: 1 msec
    ;; SERVER: 127.0.0.1#53(127.0.0.1)
    ;; WHEN: Mon Mar  2 14:14:34 2009
    ;; MSG SIZE  rcvd: 300
    host `hostname`
    Code:
    smtp.netjungle.it has address 127.0.0.1
    smtp.netjungle.it mail is handled by 10 smtp.netjungle.it.
    I can confirm you that I had the same problem both with source server up or not.
    At the moment I can't switch off it because it's in production. I've got a backup MX server but I can shutdown Zimbra just in the night.
    Last edited by drizzt; 03-02-2009 at 06:20 AM.
    Giorgio Salluzzo - Sviluppatore Python / Django

  2. #12
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,201
    Rep Power
    56

    Default

    You need zimbra to have an IP on your LAN not localhost and you also need the following in your /etc/hosts file:

    Code:
    127.0.0.1 localhost.localdomain localhost
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  3. #13
    uxbod's Avatar
    uxbod is offline Moderator
    Join Date
    Nov 2006
    Location
    UK
    Posts
    8,016
    Rep Power
    24

    Default

    As you have a local BIND install just point the MX and A records at the IP 78.46.91.12 which you have assigned; plus fixing the localhost entry which Phoenix has advised.

  4. #14
    drizzt's Avatar
    drizzt is offline Intermediate Member
    Join Date
    Nov 2008
    Location
    Pavia (Italia)
    Posts
    19
    Rep Power
    6

    Default

    smtp.netjungle.it is pointing to 127.0.0.1 in both configurations.

    New Server
    Code:
    ; <<>> DiG 9.4.2-P2 <<>> smtp.netjungle.it ANY
    ;; global options:  printcmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24368
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;smtp.netjungle.it.		IN	ANY
    
    ;; ANSWER SECTION:
    smtp.netjungle.it.	2592000	IN	SOA	smtp.netjungle.it. hostmaster.smtp.netjungle.it. 10118 43200 3600 3600000 2592000
    smtp.netjungle.it.	2592000	IN	NS	127.0.0.1.smtp.netjungle.it.
    smtp.netjungle.it.	2592000	IN	A	127.0.0.1
    smtp.netjungle.it.	2592000	IN	MX	10 smtp.netjungle.it.
    
    ;; Query time: 0 msec
    ;; SERVER: 127.0.0.1#53(127.0.0.1)
    ;; WHEN: Mon Mar  2 14:45:17 2009
    ;; MSG SIZE  rcvd: 138
    Old Server
    Code:
    ; <<>> DiG 9.4.2-P2 <<>> smtp.netjungle.it ANY
    ;; global options:  printcmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 861
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;smtp.netjungle.it.             IN      ANY
    
    ;; ANSWER SECTION:
    smtp.netjungle.it.      2592000 IN      SOA     smtp.netjungle.it. hostmaster.smtp.netjungle.it. 10118 43200 3600 3600000 2592000
    smtp.netjungle.it.      2592000 IN      NS      127.0.0.1.smtp.netjungle.it.
    smtp.netjungle.it.      2592000 IN      A       127.0.0.1
    smtp.netjungle.it.      2592000 IN      MX      10 smtp.netjungle.it.
    
    ;; Query time: 1 msec
    ;; SERVER: 127.0.0.1#53(127.0.0.1)
    ;; WHEN: Mon Mar  2 14:43:29
    Giorgio Salluzzo - Sviluppatore Python / Django

  5. #15
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,201
    Rep Power
    56

    Default

    Quote Originally Posted by drizzt View Post
    smtp.netjungle.it is pointing to 127.0.0.1 in both configurations.
    That is incorrect, you need to point it to a real IP address. Is this server behind a firewall and on a public IP?
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  6. #16
    drizzt's Avatar
    drizzt is offline Intermediate Member
    Join Date
    Nov 2008
    Location
    Pavia (Italia)
    Posts
    19
    Rep Power
    6

    Default

    Quote Originally Posted by phoenix View Post
    That is incorrect, you need to point it to a real IP address. Is this server behind a firewall and on a public IP?
    The old server is behind a firewall, the new one has a public IP.
    Giorgio Salluzzo - Sviluppatore Python / Django

  7. #17
    uxbod's Avatar
    uxbod is offline Moderator
    Join Date
    Nov 2006
    Location
    UK
    Posts
    8,016
    Rep Power
    24

    Default

    If your new server going to be sat in a DMZ using your public IP or will it still be behind a firewall on a private IP/NATd ?

  8. #18
    drizzt's Avatar
    drizzt is offline Intermediate Member
    Join Date
    Nov 2008
    Location
    Pavia (Italia)
    Posts
    19
    Rep Power
    6

    Default

    The current Zimbra server is behind my company firewall in Italy, using NAT for needed ports.
    The new server is out of my network, in a german webfarm, and it has just a public IP.
    Giorgio Salluzzo - Sviluppatore Python / Django

  9. #19
    uxbod's Avatar
    uxbod is offline Moderator
    Join Date
    Nov 2006
    Location
    UK
    Posts
    8,016
    Rep Power
    24

    Default

    Okay, so install your new server with the public IP and update /etc/resolv.conf so that it points to the locally installed BIND server. Then for BIND setup the A and MX records to use the public IP.

  10. #20
    drizzt's Avatar
    drizzt is offline Intermediate Member
    Join Date
    Nov 2008
    Location
    Pavia (Italia)
    Posts
    19
    Rep Power
    6

    Default

    Render unto sysadmin what is sysadmin's!

    Yes, my internal DNS was saying smtp.netjungle.it is 127.0.0.1, and my /etc/hosts was saying it's the public IP.
    I kept the Split DNS configuration but it's just for a firewalled installation.
    I think it will be ok next time I try to move it.

    Many thanks, I owe a pint of beer to you.
    Last edited by drizzt; 03-02-2009 at 08:44 AM.
    Giorgio Salluzzo - Sviluppatore Python / Django

Page 2 of 3 FirstFirst 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. [Network Edition Trial] OS X Installation
    By dmg in forum Installation
    Replies: 4
    Last Post: 02-07-2007, 05:25 PM
  2. Mac OSX install: Java errors & LDAP CA error
    By jefbear in forum Installation
    Replies: 9
    Last Post: 12-16-2006, 03:39 PM
  3. Error 256 on Installation
    By RuinExplorer in forum Installation
    Replies: 5
    Last Post: 10-19-2006, 09:19 AM
  4. Authenticating to the LDAP
    By jasonwillis in forum Installation
    Replies: 4
    Last Post: 03-15-2006, 10:48 AM
  5. ldap pasword problem
    By jasonwillis in forum Installation
    Replies: 15
    Last Post: 03-15-2006, 08:56 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •