[Kea-users] DDNS + GSS-TSIG to Active Directory :

Francis Dupont fdupont at isc.org
Fri Jul 24 12:06:04 UTC 2026


Nicolas Ecarnot via Kea-users writes:

=> it is an AD known bug.

>  From our 3.0.3 ISC Kea DDNS service, using the gss-tsig library (3.0.3) 
> on a Debian 12, we're trying to update a specific DNS zone hosted on a 
> windows 2016 Active Directory server.
>
> We're already succesfully updating this zone from some other Linux 
> boxes, using a dedicated account and after having correctly set up the 
> Kerberos parameters.
>
>  From the DDNS service, after triggering an update 
> (renew/creation/removal), I can see in the logs that the service is 
> complaining about Message Integrity Check [1] and the update is never 
> happening in Active Directory DNS.
>
> I tried to debug this situation with A.I. and made tons of tests, 
> proving that everything related to Kerberos was OK.
> Now, I'm stuck at this point and I would like to know if some of you are 
> using this setup (DDNS+AD) smoothly?
>
> Thank you for reading
>
> Nicolas
>
>
> [1] The faulty logs :
>
> 2026-07-24T11:48:01.955801+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]: 
> INFO  GSS_TSIG_VERIFY_FAILED GSS-TSIG verify failed: gss_verify_mic 
> failed with GSSAPI error: Major = 'A token had an invalid Message 
> Integrity Check (MIC)' (393216), Minor = 'Packet was replayed in wrong 
> direction' (100002)..

=> the problem is the wrong direction.

I do not know if Microsoft has the intention to fix it but as you were
not the first to report the problem we developed a workaround in
#4326 merged in 3.1.9 (so available in 3.2.0 and the soon being
released 3.3.0) with the number 2476.

Thanks

Francis Dupont <fdupont at isc.org>

PS: I do not remember if we got feedback about this so if it works for you
please put a note here.


More information about the Kea-users mailing list