Re: GSS-TSIG DNS update fails (BIND9_DLZ/SAMBA_INTERNAL), kea-dhcp-ddns
Anton Shevtsov via samba <[email protected]> Mon, 3 Aug 2026 13:17:43 +0500
| Newsgroups | gmane.network.samba.general |
|---|---|
| Organization | BaseALT |
| Message-ID | <[email protected]> |
After switching Samba to the MIT-krb5 build (samba-mitkrb5), the problem is gone. With both sides on MIT krb5, Kea reuses the same GSS-TSIG key across multiple updates and all succeed; forward and reverse records update correctly. So: MIT-krb5 Samba + BIND9_DLZ works as expected for GSS-TSIG updates from a Kea/MIT client, including GSS context reuse; the Heimdal build did not in this scenario. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba