Learn How We Can Help You Keep Teleworkers Protected During the COVID-19 Crisis



AD Integration - Dynamic DNS Problems

Posts: 1
7710     0

Hi all,

i'm trying to integrate my AD environment with the infoblox DNS. I would like to let my AD clients to dynamically update the dns name on the nios appliance.

Right now the nios appliances are not managing the DHCP, so I want to do GSS-TSIG updates from Clients to Infoblox dns servers.

The nios version is: 6.7.1-204398 I already have my dns zone (authoritative) with AD integration (svc entries & co.) and all works just fine. I tried to follow the admin guide ( "Accepting GSS-TSIG-Authenticated Updates" page 642), the config seems ok but i'm not able to receive authenticated updates.

When i try to update the dns record from an XP machine, I obtain this error message:

err client 192.168.XX.XX#1103: view 1: update 'unitn.it/IN' denied
2013-07-19T09:50:01+02:00 daemon (none) named[26063]: err 192.168.XX.XX#1104: GSS-TSIG authentication failed for (DNS/xxx.unitn.it@UNITN.IT, kvno 2, des-cbc-md5): key not found
2013-07-19T09:50:01+02:00 daemon (none) named[26063]: err gss_accept_sec_context: continuation call to routine required
when i try to do dthe same from a win7 machine, i'm getting only the first error message ( update denied ).
Any hint on how to solve this ?
My domain is a 2003 R2 domain, so i also followed this kb:
15331 Using GSS-TSIG for a Windows 7 or Windows Server 2008 R2 in a Windows Server 2003 AD Server environment
thank you!

Re: AD Integration - Dynamic

Posts: 4
7711     0


i am going to try this but before i do i would like to know if this is an issue


Re: AD Integration - Dynamic

Posts: 60
7711     0

Hi Marco,

If you have not found a resolution to this problem, you should contact Infoblox support at https://support.infoblox.com/. 





Re: AD Integration - Dynamic

Posts: 181
7711     0



The info on that web page helped me greatly in geting GSS-TSIG working in my enviroment.  It was a much better explination, with real world examples than the admin guide.


Re: AD Integration - Dynamic

Posts: 101
7711     0

When you create the keytab file on windows (as in Admin Guide page 648) try the following for crypto

- crypto: all


-crypto RC4-HMAC-NT

(both will work for W2k8 R2 Server & W7k PCs)

Please delete your current AD GSS-TSIG user and create a new one before you create the keytab.



Re: AD Integration - Dynamic DNS Problems

Posts: 51
7711     0



I've the same problem with you. This error typically issued on microsoft behaviour where the old kerberos key are not timing out when you create the new one.


to purge the kerberos ticket cache i follow this guide https://blogs.technet.microsoft.com/tspring/2014/06/23/viewing-and-purging-cached-kerberos-tickets/, and now the client are success to update to Infoblox on my environment.



Showing results for 
Search instead for 
Do you mean 

Recommended for You