[Samba] dns_tkey_gssnegotiate: TKEY is unacceptable

Rowland penny rpenny at samba.org
Fri Jul 3 14:31:22 UTC 2020

On 03/07/2020 15:24, Robert E. Wooden via samba wrote:
> On 7/3/2020 9:15 AM, Rowland penny via samba wrote:
>> No, might as well tell you now, it's relevant. Samba moved the keytab 
>> to the 'bind-dns' directory sometime ago, so you should be using the 
>> keytab in the bind-dns directory, which will mean altering the 
>> named.conf files if you are using Bind9
> Yes, I saw that during setup. I had to "think thru" Louis' 
> instructions, to test, locate and make sure I was using the correct 
> "dns.keytab" for the BIND9_DLZ setup.
>> Depends, are you actually using the correct keytab ?
>> Rowland
> Apparently, I missed this. So, I am not sure what to change to correct?
> Any explanation you could provide would clarify this for me?
> (FYI, Debian 10 with Samba 4.12.3)
Does 'sudo rm -f /var/lib/samba/private/dns.keytab' give you any hint to 
which is the correct keytab ?


More information about the samba mailing list