随记:RHEL6.2下DNS无法解析公网域名troubleshooting

研究xcat时随手用RHEL6.2搭了DNS,却发现本地域名正常却无法解析外部域名,日志里报错

Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 202.106.0.20#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.36.148.17#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.203.230.10#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.5.5.241#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 193.0.14.129#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 199.7.83.42#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 128.8.10.90#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 128.63.2.53#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.228.79.201#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 198.41.0.4#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 202.12.27.33#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.58.128.30#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.33.4.12#53
Jan  7 09:04:50 xCat named[3163]: error (no valid RRSIG) resolving 'cn/DS/IN': 192.112.36.4#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:7fe::53#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:500:2f::f#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:7fd::1#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:500:3::42#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:500:2d::d#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:500:1::803f:235#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:503:ba3e::2:30#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:dc3::35#53
Jan  7 09:04:50 xCat named[3163]: error (network unreachable) resolving 'cn/DS/IN': 2001:503:c27::2:30#53

我没有启用ipv6,所以主要错误在于”(no valid RRSIG)”

wiki下查了下RRSIG是一种表示DNSSEC凭证的记录类型,应该是启用了DNSSEC导致我的DNS无法向根服务器进行查询,我不需要DNSSEC功能,可以关掉

vi  /etc/named.conf

修改21行

dnssec-enable no;

再次测试,正常了

你可能感兴趣的:(dns,无法解析,troubleshooting,RHEL6.2,公网域名)