[Samba] dnsupdate failed with TKEY is unaceptable

Rowland penny rpenny at samba.org
Wed Nov 18 20:16:09 UTC 2020

On 18/11/2020 19:27, Rommel Rodriguez Toirac wrote:
>  It is /etc/named.conf and /etc/samba/smb.conf
> # cat /etc/named.conf
>   tkey-gssapi-keytab "/usr/local/samba/private/dns.keytab";
> include "/usr/local/samba/bind-dns/named.conf";
OK, does the /usr/local/samba/bind-dns directory exist ?

if it does, is the 'named.conf. file in there, set up to use your Bind9 
version ?

Also the dns.keytab should also exist in the same directory (there is 
bug report about this not happening on newly joined DC's), so if it 
doesn't exist, copy it from '/usr/local/samba/private' keeping the same 
permissions. Update the 'tkey-gssapi-keytab' path to reflect the change.


More information about the samba mailing list