Displaying 2 results from an estimated 2 matches for "_dc1".
Did you mean:
5dc1
2020 Jul 06
0
dns_tkey_gssnegotiate: TKEY is unacceptable
.../etc/bind/named.conf.options to
.../private/dns.ketab (for testing purposes), DC1 (joined with DC01)
samba_dnsupdate --verbose ?all-names _will fail_ with
"dns_tkey_gssnegotiate: TKEY is unacceptable" and the "Successfully
obtained Kerberos ticket to DNS/DC1.SUBDOM.EXAMPLE.COM as _DC1$_."
(Notice that DC1 is "acquiring password" password from itself.)
When I change the DC01 ".../private/dns-keytab" _back to_
"....bind-dns/dns.keytab" DC1 will then "samba_dnsupdate --verbose
?all-names" correctly BUT, "Successfully obtained Ke...
2020 Jul 03
2
dns_tkey_gssnegotiate: TKEY is unacceptable
On 7/3/2020 9:50 AM, Rowland penny via samba wrote:
> I thought I explained that, but lets try again ;-)
>
> Originally, Samba used /var/lib/samba/private for the dns.keytab and
> other dns files. This was then found to be possibly insecure, so it
> was decided to use /var/lib/samba/bind-dns instead. When you upgrade
> the Samba packages, the old files are not removed, but the