open: /etc/bind/named.conf: permission denied

aagghh

Verified User
Joined
Aug 22, 2021
Messages
10
hi
The named service is stopped and cannot be started.
The permissin of the named.conf should be set as follows, but the problem was not solved:
root:root
root:bind
bind:bind
chmod 640
chmod 644
chmod 755
chmod 777

my os: ubuntu 20.04

named directory: /etc/bind/

/var/log/syslog output:
Aug 11 10:54:03 srv named[286916]: running as: named -f -u bind -4
Aug 11 10:54:03 srv named[286916]: compiled by GCC 9.4.0
Aug 11 10:54:03 srv named[286916]: compiled with OpenSSL version: OpenSSL 1.1.1f 31 Mar 2020
Aug 11 10:54:03 srv named[286916]: linked to OpenSSL version: OpenSSL 1.1.1f 31 Mar 2020
Aug 11 10:54:03 srv named[286916]: compiled with libxml2 version: 2.9.10
Aug 11 10:54:03 srv named[286916]: linked to libxml2 version: 20914
Aug 11 10:54:03 srv named[286916]: compiled with json-c version: 0.13.1
Aug 11 10:54:03 srv named[286916]: linked to json-c version: 0.13.1
Aug 11 10:54:03 srv named[286916]: compiled with zlib version: 1.2.11
Aug 11 10:54:03 srv named[286916]: linked to zlib version: 1.2.11
Aug 11 10:54:03 srv named[286916]: ----------------------------------------------------
Aug 11 10:54:03 srv named[286916]: BIND 9 is maintained by Internet Systems Consortium,
Aug 11 10:54:03 srv named[286916]: Inc. (ISC), a non-profit 501(c)(3) public-benefit
Aug 11 10:54:03 srv named[286916]: corporation. Support and training for BIND 9 are
Aug 11 10:54:03 srv named[286916]: available at https://www.isc.org/support
Aug 11 10:54:03 srv named[286916]: ----------------------------------------------------
Aug 11 10:54:03 srv named[286916]: adjusted limit on open files from 524288 to 1048576
Aug 11 10:54:03 srv named[286916]: found 56 CPUs, using 56 worker threads
Aug 11 10:54:03 srv named[286916]: using 56 UDP listeners per interface
Aug 11 10:54:04 srv named[286916]: using up to 21000 sockets
Aug 11 10:54:04 srv named[286916]: loading configuration from '/etc/bind/named.conf'
Aug 11 10:54:04 srv named[286916]: open: /etc/bind/named.conf: permission denied
Aug 11 10:54:04 srv named[286916]: loading configuration: permission denied
Aug 11 10:54:04 srv named[286916]: exiting (due to fatal error)
Aug 11 10:54:04 srv systemd[1]: named.service: Main process exited, code=exited, status=1/FAILURE
Aug 11 10:54:04 srv systemd[1]: named.service: Failed with result 'exit-code'.
Aug 11 10:54:04 srv systemd[1]: named.service: Scheduled restart job, restart counter is at 5.
Aug 11 10:54:04 srv systemd[1]: Stopped BIND Domain Name Server.
Aug 11 10:54:04 srv systemd[1]: named.service: Start request repeated too quickly.
Aug 11 10:54:04 srv systemd[1]: named.service: Failed with result 'exit-code'.
Aug 11 10:54:04 srv systemd[1]: Failed to start BIND Domain Name Server.
Aug 11 10:54:06 srv systemd[1]: named.service: Start request repeated too quickly.
Aug 11 10:54:06 srv systemd[1]: named.service: Failed with result 'exit-code'.
Aug 11 10:54:06 srv systemd[1]: Failed to start BIND Domain Name Server.


named status:
root@srv:/etc/bind# service named status -l
● named.service - BIND Domain Name Server
Loaded: loaded (/lib/systemd/system/named.service; enabled; vendor preset: enabled)
Active: failed (Result: exit-code) since Fri 2023-08-11 10:57:04 +0330; 7s ago
Docs: man:named(8)
Process: 291505 ExecStart=/usr/sbin/named -f $OPTIONS (code=exited, status=1/FAILURE)
Main PID: 291505 (code=exited, status=1/FAILURE)
CPU: 280ms

Aug 11 10:57:04 srv.arazitco.com systemd[1]: named.service: Scheduled restart job, restart counter is at 5.
Aug 11 10:57:04 srv.arazitco.com systemd[1]: Stopped BIND Domain Name Server.
Aug 11 10:57:04 srv.arazitco.com systemd[1]: named.service: Start request repeated too quickly.
Aug 11 10:57:04 srv.arazitco.com systemd[1]: named.service: Failed with result 'exit-code'.
Aug 11 10:57:04 srv.arazitco.com systemd[1]: Failed to start BIND Domain Name Server.
Aug 11 10:57:06 srv.arazitco.com systemd[1]: named.service: Start request repeated too quickly.
Aug 11 10:57:06 srv.arazitco.com systemd[1]: named.service: Failed with result 'exit-code'.
Aug 11 10:57:06 srv.arazitco.com systemd[1]: Failed to start BIND Domain Name Server.
 
service named restart
then you will see journactl command to check extended status of process
 
Aug 11 10:54:04 srv named[286916]: open: /etc/bind/named.conf: permission denied
Check if these both permissions are the same, because maybe it's the directory, mind the s here for the directory.
drwxr-sr-x 2 root bind 4.0K 2023-08-11 00:24 bind
and
-rw-r--r-- 1 root bind 6.3K 2023-08-10 15:02 named.conf
 
Back
Top