[Samba] GSS-TSIG DNS update fails (BIND9_DLZ/SAMBA_INTERNAL), kea-dhcp-ddns

Anton Shevtsov shevtsovay at basealt.ru
Mon Aug 3 09:45:02 UTC 2026


Correction to my earlier "works" report: GSS context reuse degrades on 
the MIT-krb5 Samba build too — not on the second update as with Heimdal, 
but after 5-6 successful updates on the same reused key. named then logs:

Aug 03 14:37:42 dc1.new.alt named[3585]: samba_dlz: spnego update failed
Aug 03 14:37:42 dc1.new.alt named[3585]: client @0x7f4748f57098 
192.168.180.10#47370/key kea-dhcp\@NEW.ALT: updating zone 'new.alt/IN': 
update failed: rejected by secure update (REFUSED)


03.08.2026 13:17, Anton Shevtsov via samba пишет:
> After switching Samba to the MIT-krb5 build (samba-mitkrb5), the problem
> is gone. With both sides on MIT krb5, Kea reuses the same GSS-TSIG key
> across multiple updates and all succeed; forward and reverse records
> update correctly. So: MIT-krb5 Samba + BIND9_DLZ works as expected for
> GSS-TSIG updates from a Kea/MIT client, including GSS context reuse; the
> Heimdal build did not in this scenario.
-- 


More information about the samba mailing list