[Kea-users] DDNS + GSS-TSIG to Active Directory :
Francis Dupont
fdupont at isc.org
Fri Jul 24 12:06:04 UTC 2026
Nicolas Ecarnot via Kea-users writes:
=> it is an AD known bug.
> From our 3.0.3 ISC Kea DDNS service, using the gss-tsig library (3.0.3)
> on a Debian 12, we're trying to update a specific DNS zone hosted on a
> windows 2016 Active Directory server.
>
> We're already succesfully updating this zone from some other Linux
> boxes, using a dedicated account and after having correctly set up the
> Kerberos parameters.
>
> From the DDNS service, after triggering an update
> (renew/creation/removal), I can see in the logs that the service is
> complaining about Message Integrity Check [1] and the update is never
> happening in Active Directory DNS.
>
> I tried to debug this situation with A.I. and made tons of tests,
> proving that everything related to Kerberos was OK.
> Now, I'm stuck at this point and I would like to know if some of you are
> using this setup (DDNS+AD) smoothly?
>
> Thank you for reading
>
> Nicolas
>
>
> [1] The faulty logs :
>
> 2026-07-24T11:48:01.955801+02:00 cti-dhcp-prd01 kea-dhcp-ddns[4070818]:
> INFO GSS_TSIG_VERIFY_FAILED GSS-TSIG verify failed: gss_verify_mic
> failed with GSSAPI error: Major = 'A token had an invalid Message
> Integrity Check (MIC)' (393216), Minor = 'Packet was replayed in wrong
> direction' (100002)..
=> the problem is the wrong direction.
I do not know if Microsoft has the intention to fix it but as you were
not the first to report the problem we developed a workaround in
#4326 merged in 3.1.9 (so available in 3.2.0 and the soon being
released 3.3.0) with the number 2476.
Thanks
Francis Dupont <fdupont at isc.org>
PS: I do not remember if we got feedback about this so if it works for you
please put a note here.
More information about the Kea-users
mailing list