For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

gizmo_176486's avatar
gizmo_176486
Icon for Nimbostratus rankNimbostratus
Aug 23, 2017

named daemon keeps restarting after upgrade to v11.6.1 hf2

hi everyone! not sure if any of you had this experience... so i'm upgrading hardware and firmware:

 

Platform: 6400 to 2000s (LTM only)

 

Firmware: 10.2.4 to 11.6.1 HF2

 

i get to the point where i load the ucs file, with minor edits it loads successfully but i start getting

 

Aug 22 17:46:10 bigip1 emerg logger: Re-starting named

 

Aug 22 17:46:23 bigip1 emerg logger: Re-starting named

 

Aug 22 17:46:34 bigip1 emerg logger: Re-starting named

 

Aug 22 17:47:18 bigip1 emerg logger: Re-starting named

 

Aug 22 17:47:29 bigip1 emerg logger: Re-starting named

 

i've tried a bunch of troubleshooting stuff but it looks like every time there is a change in named.conf it fails as the permissions gets reverted back to read-only.

 

any idea to permanently fix it?

 

4 Replies

  • I think the root alone has the rw permissions set. And for groups and others, its null. Did you try that ? Also I see you have specified (LTM only) in your question. You dont have a GTM module, did you have GTM module in the 10.x (before upgrading) and used the same UCS now ?

     

  • JG's avatar
    JG
    Icon for Cumulonimbus rankCumulonimbus

    On my system (v11.6.0 HF2):

      ls -al /var/named/config/
    total 48
    drwxr-xr-x 3 named named 4096 Aug 18 13:11 .
    drwxr-xr-x 8 named named 4096 Feb  4  2017 ..
    -rw------- 1 named named 2389 Feb  4  2017 bind.keys
    drwxrwxr-x 2 named named 4096 Aug 20 08:19 namedb
    -rw------- 1 named named 1013 Aug 18 13:11 named.conf
    -rw------- 1 named named   77 Feb 17  2017 rndc.key
    

    .

  • it is in fact, permissions issue. we don't have a gtm module provisioned on this device. the orginal ucs had only read-only permissions. i was able to fix it by giving +rw permissions and regenerated a new ucs file.