[Samba] dns.keytab doesn't exist

Johannes Engel jcnengel+samba at gmail.com
Fri Dec 11 07:15:30 UTC 2020

Hi Dan,

have you run

samba_upgradedns --dns-backend=BIND9_DLZ

already? That should create all necessary files. Or depending upon
your Samba version, could you please check for

May I assume that you are using a packaged build of Samba?

Best regards


Am Fr., 11. Dez. 2020 um 07:28 Uhr schrieb Dan Egli via samba <
samba at lists.samba.org>:

> I was reading on the samba wiki about how to use bind9_dlz as the DNS
> backend for an AD Domain, but in the setup instructions for bind given
> in the wiki it says to be sure to include the line tkey-gssapi-keytab
> "/var/lib/samba/bind-dns/dns.keytab"; in my named.conf file, in the
> options section. That's great, except I don't HAVE a dns.keytab file
> anywhere on the system. I've looked at the page carefully and nothing
> says where the file comes from. Only that it's in the
> /var/lib/samba/bind-dns directory, but on my system that directory is
> empty. Is this something that bind is going to create or something? I'm
> a bit lost. Any help is appreciated!
> In case anyone is wondering, I'm using bind because the system already
> has bind on it to serve internet DNS requests. So rather than try to
> figure out how to let samba maintain it's own internal DNS cache and
> still have the main one, I just figured I'd let bind handle the whole
> thing.
> --
> Dan Egli
>  From my Test Server
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba

More information about the samba mailing list