Secure only dynamic updates to Microsoft DNS expects TKEY negotiation for each updat
having client application sending secure (gss-tsig based) dynamic updates micorsoft dns.
after successful tkey negotiation, dynamic update accepted/success.
but, when try use same tkey name ( established context is not expired) we getting "query refused error".
there configuration/setting needs enabled in ms dns reuse established context (tkey name)?
per rfc 3645,
<rfc snip>
these client , server use established security context sign , validate signatures when exchange packets each other until context expires.
</rfc snip>
also, there way can enable debug/trace log know reason "query refused" ?
thanks,
ganeshkumar s.
hi,
to enable dns debug log:
right click dns server->properties->debug logging->log packets debugging
if debug log doesn’t help, recommend capture packets. described in rfc 3645, please check current major_status is.
Windows Server > Windows Server General Forum
Comments
Post a Comment