Solved

named won't start, unknown key 'rndc-key'

Posted on 2014-07-31
12
1,893 Views
Last Modified: 2014-07-31
I have a VPS running Centos 6.4 and WHM 11.44.1

Yesterday I started receiving emails saying that the named service had failed and couldn't be restarted.

When attempting to start the server I get the following

Starting named: /etc/init.d/named: line 97: 28896 Aborted                 /usr/sbin/named-checkconf $ckcf_options ${named_conf} > /dev/null 2>&1

Error in named configuration:
/etc/named.conf:4: unknown key 'rndc-key'
/etc/rndc.key:1: key '': bad key name
/etc/rndc.key:1: key '': bad key name
/etc/rndc.key:1: key '': bad key name
mem.c:1246: REQUIRE(ctx->references == 1) failed, back trace
#0 0x7fce761546c6 in ??
#1 0x7fce7615489a in ??
#2 0x7fce761667a2 in ??
#3 0x403571 in ??
#4 0x7fce7499bd1d in ??
#5 0x4025d9 in ??

In an attempt to fix the issue I've updated WHM to the latest version and ran the command /scripts/fixrndc as described on various websites on the internet, but it still doesn't seem to resolve the issue.

I'm hoping someone will be able to help me fix this issue.
0
Comment
Question by:SheppardDigital
  • 6
  • 5
12 Comments
 
LVL 13

Expert Comment

by:duncanb7
ID: 40231360
Are you using cpanel?

If so, try it ,rebulid the /etc/named.conf file, it may work

/scripts/rebuilddnsconfig


Duncan
0
 

Author Comment

by:SheppardDigital
ID: 40231368
During the rebuild it tries to restarted named and I get the same error as above.
0
 
LVL 13

Expert Comment

by:duncanb7
ID: 40231373
you are using cpanel, right ?

Duncan
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 

Author Comment

by:SheppardDigital
ID: 40231375
whm/cpanel
0
 
LVL 13

Expert Comment

by:duncanb7
ID: 40231388
when you rebullid it , did you rename the file  /etc/named.conf ?

Duncan
0
 

Author Comment

by:SheppardDigital
ID: 40231391
I didn't rename any files when I ran /scripts/rebuilddnsconfig
0
 

Author Comment

by:SheppardDigital
ID: 40231396
If it helps, this is the content of /etc/rndc.conf

key "" {
        algorithm hmac-md5;
        secret "";
};

Open in new window


and this is the top of the file /etc/named.conf

include "/etc/rndc.key";

controls {
        inet 127.0.0.1 allow { localhost; } keys { "rndc-key"; };
};

options {
    /* make named use port 53 for the source of all queries, to allow
         * firewalls to block all ports except 53:
         */

    // query-source    port 53;

    /* We no longer enable this by default as the dns posion exploit
        has forced many providers to open up their firewalls a bit */

    // Put files that named is allowed to write in the data/ directory:
    directory                "/var/named"; // the default
    pid-file                 "/var/run/named/named.pid";
    dump-file                "data/cache_dump.db";
    statistics-file          "data/named_stats.txt";
   /* memstatistics-file     "data/named_mem_stats.txt"; */
    allow-transfer {"none";};
};

Open in new window


It looks to me like rdnc-key isn't defined in the rndc.conf file. I guess this is causing the problem, but how do I re-create that key?
0
 

Author Comment

by:SheppardDigital
ID: 40231416
Just to add, I've tried renaming the rndc.conf file and running the /scripts/fixrndc commend, but again, it doesn't generate a key.
0
 
LVL 13

Accepted Solution

by:
duncanb7 earned 500 total points
ID: 40231427
it seems the rndc.key  issue.
Please take a  look on how to generate rndc.key file  at his article ,
http://tecadmin.net/configure-rndc-for-bind9/

Duncan
0
 
LVL 62

Expert Comment

by:gheist
ID: 40231465
On normal centos it generates absent rndc.conf when starting
0
 

Author Closing Comment

by:SheppardDigital
ID: 40232141
This resolved my issue, although I had to remove the options section from the generated rndc.key
0
 
LVL 13

Expert Comment

by:duncanb7
ID: 40232144
thx for yr pt

ve a nice day

duncan
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Daily system administration tasks often require administrators to connect remote systems. But allowing these remote systems to accept passwords makes these systems vulnerable to the risk of brute-force password guessing attacks. Furthermore there ar…
It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question