Re: GSS-TSIG DNS update fails (BIND9_DLZ/SAMBA_INTERNAL), kea-dhcp-ddns

Anton Shevtsov via samba <[email protected]> Mon, 3 Aug 2026 13:17:43 +0500
Newsgroups gmane.network.samba.general
Organization BaseALT
Message-ID <[email protected]>
After switching Samba to the MIT-krb5 build (samba-mitkrb5), the problem
is gone. With both sides on MIT krb5, Kea reuses the same GSS-TSIG key
across multiple updates and all succeed; forward and reverse records
update correctly. So: MIT-krb5 Samba + BIND9_DLZ works as expected for
GSS-TSIG updates from a Kea/MIT client, including GSS context reuse; the
Heimdal build did not in this scenario.
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba