Secure only dynamic updates to Microsoft DNS expects TKEY negotiation for each updat


having client application sending secure (gss-tsig based) dynamic updates micorsoft dns.

after successful tkey negotiation, dynamic update accepted/success.

but, when try use same tkey name ( established context  is not expired)  we getting "query refused error". 

there configuration/setting needs enabled in ms dns reuse established context (tkey name)? 

per rfc 3645, 

<rfc snip>

these client , server use established security context sign    , validate signatures when exchange packets each    other until context expires.

</rfc snip>

also, there way can enable debug/trace log know reason "query refused" ?

thanks,

ganeshkumar s.

hi,

to enable dns debug log:

right click dns server->properties->debug logging->log packets debugging

if debug log doesn’t help, recommend capture packets. described in rfc 3645, please check current major_status is.



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2