OMAPI key generation without BIND

Michael De Roover isc at
Wed Sep 30 08:48:50 UTC 2020


Earlier I've deployed 2 DHCP servers running ISC DHCP. These were
configured to communicate with each other via OMAPI. Online I found with which I configured the OMAPI
control channel. I also found, however this
appears to be tailored at developers who wish to integrate their
applications with OMAPI.

The former article worked well to configure it,
but it suggests that we use BIND to generate the OMAPI key. I use BIND
on my name servers, and was able to generate a key on one of those name
servers. This does mean however that not only the DHCP servers, but
also the name servers (and my laptop through the clipboard) know this
OMAPI key. I'd rather keep strict boundaries between these environments
and have the DHCP servers capable of generating this key on their own,
preferably without having to install BIND there (as that runs somewhere

The hashing algorithm used to generate these OMAPI keys appears to be
HMAC-MD5. I could not find any standard system utilities that can
generate this kind of key. Are there any such tools available for
conventional Linux systems? Are there any other hashing algorithms that
are supported for this OMAPI key? Alternatively, would it be possible
to include the relevant code from dnssec-keygen in ISC DHCP?

Perhaps this part would be better suited for kea-users, but how well is
DHCP failover supported there? Is it easier to use standard system
tools to generate them for this DHCP server? If so that might be a
reason to upgrade.

Thank you!
Michael De Roover <isc at>

More information about the dhcp-users mailing list