# Include this in dhcpd.conf to have DHCPd create Dynamic DNS entries in Active Directory
# DNS using GSS-TSIG/Kerberos authentication.
#
# Refer to https://pastebin.com/SRPh7Bcu for step-by-step instructions.
#
# Adapted from
# https://unix.stackexchange.com/questions/270097/isc-dhcp-with-active-directory-secure-dynamic-dns-updates/271815#271815
# https://blog.michael.kuron-germany.de/2011/02/isc-dhcpd-dynamic-dns-updates-against-secure-microsoft-dns/
#
# include can be at the global or pool-level.
on commit {
set noname = concat("dhcp-", binary-to-ascii(10, 8, "-", leased-address));
set ClientIP = binary-to-ascii(10, 8, ".", leased-address);
set ClientMac = binary-to-ascii(16, 8, ":", substring(hardware, 1, 6));
set ClientName = pick-first-value(option host-name, host-decl-name, config-option host-name, noname);
log(concat("Commit: IP: ", ClientIP, " Mac: ", ClientMac, " Name: ", ClientName));
execute("/usr/local/sbin/dns-krbnsupdate.sh", "add", ClientIP, "-h", ClientName, "-m", ClientMac);
}
on release {
set ClientIP = binary-to-ascii(10, 8, ".", leased-address);
set ClientMac = binary-to-ascii(16, 8, ":", substring(hardware, 1, 6));
log(concat("Release: IP: ", ClientIP, " Mac: ", ClientMac));
# cannot get a ClientName here, for some reason that always fails
execute("/usr/local/sbin/dns-krbnsupdate.sh", "delete", ClientIP, "-m", ClientMac);
}
# comment this section if using TXT RR in https://pastebin.com/taNfvCSt
on expiry {
set ClientIP = binary-to-ascii(10, 8, ".", leased-address);
# cannot get a ClientMac here, apparently this only works when actually receiving a packet
log(concat("Expired: IP: ", ClientIP));
# cannot get a ClientName here, for some reason that always fails
execute("/usr/local/sbin/dns-krbnsupdate.sh", "delete", ClientIP);
}
Comments
0 B
|👍
/👎