Reply
Accepted Solution

GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

Guru
Posts: 179
2798     0

Hi 

 

IF a DHCP grid member needed to do DDNS updates to a DNS grid member that requires a GSS-TSIG signature. My understanding is that the Keytab file will only need to be loaded on the DNS grid member and not the "DHCP grid member"

 

Is this correct?

 

 

Kindly

Wasfi

Re: GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

Adviser
Posts: 96
2799     0
Dont use GSS-TSIG on INfoblox DNS and DHCP only.

Keytab is needed when

* IB dhcpd shall update MS DNS. You need to load the keytab on IB.

* MS Clients/ DCs shall update IB DNS. Keytab is needed on IB DNS.

Re: GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

Guru
Posts: 179
2799     0

Thank you for your reply Sieber. However, I wanted to ask you that in the case of a DNS and DHCP being Grid members, how do you guarantess the integrity of the DDNS update without GSS-TSIG?

 

Kindly

Wasfi

Re: GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

Adviser
Posts: 96
2799     0

It will do TSIG signed updates to itself (127.0.0.1) if the DHCP Member is also the DNS Primary for the zone.

 

Re: GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

[ Edited ]
Guru
Posts: 179
2799     0

Sorry, what I meant is that the DHCP server is a Grid member and the Primary DNS server for the zone is also a Grid member, but they are different members. Would TSIG signed updates still take place without the need to load a Ktab file on the DHCP member and DNS member? Based on your last answer I think the answer is Yes. However, thought would check.

 

If yes, is this TSIG signed update automatic or do you need to upload a TSIG on the DHCP member and the DNS member?

 

 

Kindly

Wasfi

 

 

Re: GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

Adviser
Posts: 96
2799     0

The DHCP Member will send it to the LAN1 address of the DNS Primary member. The TSIG key will be set automagically by the Grid.

 

Basically, the Grid will take care of all. The only thing you need to do is to enable DDNS and set the 'Domain Name' in the 'IPv4 DHCP Options'.

Re: GSS-TSIG DDNS updates between a DHCP member and a DNS member. Keytab only on DNS?

Guru
Posts: 179
2799     0

Thank you. This is perfect.

Showing results for 
Search instead for 
Do you mean 

Recommended for You

Demo: Infoblox IPAM plug-in integration with OpenStack Newton