[Kea-users] DDNS + GSS-TSIG to Active Directory :
Nicolas Ecarnot
nicolas.isc at ecarnot.net
Fri Jul 24 11:18:35 UTC 2026
Hello,
From our 3.0.3 ISC Kea DDNS service, using the gss-tsig library (3.0.3)
on a Debian 12, we're trying to update a specific DNS zone hosted on a
windows 2016 Active Directory server.
We're already succesfully updating this zone from some other Linux
boxes, using a dedicated account and after having correctly set up the
Kerberos parameters.
From the DDNS service, after triggering an update
(renew/creation/removal), I can see in the logs that the service is
complaining about Message Integrity Check [1] and the update is never
happening in Active Directory DNS.
I tried to debug this situation with A.I. and made tons of tests,
proving that everything related to Kerberos was OK.
Now, I'm stuck at this point and I would like to know if some of you are
using this setup (DDNS+AD) smoothly?
Thank you for reading
Nicolas
[1] The faulty logs :
2026-07-24T11:48:01.955801+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
INFO GSS_TSIG_VERIFY_FAILED GSS-TSIG verify failed: gss_verify_mic
failed with GSSAPI error: Major = 'A token had an invalid Message
Integrity Check (MIC)' (393216), Minor = 'Packet was replayed in wrong
direction' (100002)..
2026-07-24T11:48:01.955899+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
ERROR DHCP_DDNS_FORWARD_REMOVE_ADDRS_RESP_CORRUPT DHCP_DDNS Request ID
000001864BAFE9DD8D108ECCD47DD505FD1CF89C2AC1103DF54461F7E15AE0496A63CF:
received a corrupt response from the DNS server, 10.32.0.120 port:53,
while removing forward address mapping for FQDN, form-13.sitpi.lan.
2026-07-24T11:48:01.955974+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
INFO GSS_TSIG_VERIFY_FAILED GSS-TSIG verify failed: gss_verify_mic
failed with GSSAPI error: Major = 'A token had an invalid Message
Integrity Check (MIC)' (393216), Minor = 'Packet was replayed in wrong
direction' (100002)..
2026-07-24T11:48:01.956051+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
ERROR DHCP_DDNS_FORWARD_REMOVE_ADDRS_RESP_CORRUPT DHCP_DDNS Request ID
000001864BAFE9DD8D108ECCD47DD505FD1CF89C2AC1103DF54461F7E15AE0496A63CF:
received a corrupt response from the DNS server, 10.32.0.120 port:53,
while removing forward address mapping for FQDN, form-13.sitpi.lan.
2026-07-24T11:48:01.956456+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
INFO GSS_TSIG_VERIFY_FAILED GSS-TSIG verify failed: gss_verify_mic
failed with GSSAPI error: Major = 'A token had an invalid Message
Integrity Check (MIC)' (393216), Minor = 'Packet was replayed in wrong
direction' (100002)..
2026-07-24T11:48:01.956533+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
ERROR DHCP_DDNS_FORWARD_REMOVE_ADDRS_RESP_CORRUPT DHCP_DDNS Request ID
000001864BAFE9DD8D108ECCD47DD505FD1CF89C2AC1103DF54461F7E15AE0496A63CF:
received a corrupt response from the DNS server, 10.32.0.120 port:53,
while removing forward address mapping for FQDN, form-13.sitpi.lan.
2026-07-24T11:48:01.956597+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
ERROR DHCP_DDNS_REMOVE_FAILED DHCP_DDNS Request ID
000001864BAFE9DD8D108ECCD47DD505FD1CF89C2AC1103DF54461F7E15AE0496A63CF:
Transaction outcome: Status: Failed, Event: NO_MORE_SERVERS_EVT,
Forward change: failed, request: Type: 1 (CHG_REMOVE)
2026-07-24T11:48:01.956656+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
Forward Change: yes
2026-07-24T11:48:01.956766+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
Reverse Change: no
2026-07-24T11:48:01.956805+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
FQDN: [form-13.sitpi.lan.]
2026-07-24T11:48:01.956841+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
IP Address: [10.32.20.6]
2026-07-24T11:48:01.956877+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
DHCID:
[000001864BAFE9DD8D108ECCD47DD505FD1CF89C2AC1103DF54461F7E15AE0496A63CF]
2026-07-24T11:48:01.956914+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
Lease Expires On: 20260727013713
2026-07-24T11:48:01.956950+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
Lease Length: 230398
More information about the Kea-users
mailing list