* Verified with ISC DHCPd 4.3.5 running under Debian Stretch and Windows 2008R2 DNS
* Adapted from
- https://unix.stackexchange.com/questions/270097/isc-dhcp-with-active-directory-secure-dynamic-dns-updates/271815#271815
- https://blog.michael.kuron-germany.de/2011/02/isc-dhcpd-dynamic-dns-updates-against-secure-microsoft-dns/
NOTE: Verify DHCPd is working and handing out IPs before starting this process.
1. Install heimdal and ntp
apt-get install heimdal-clients ntp
2. Configure ntp to sync clock with DC
3. Generate keytab file (see https://pastebin.com/7KBafRVp) from domain controller
4. Test the kerberos connection on DHCPd side
kinit -k -t ‘<keytab_file>’ ‘<user_principal@REALM>’
klist
5. Create script on DHCPd server (see https://pastebin.com/taNfvCSt)
6. Test DDNS through manual creation of RR
dns-krbnsupdate.sh add <host_ip> -h <host_name> -d
7. Verify creation of DDNS entry on DNS server
8. Delete test DDNS entry manually
dns-krbnsupdate.sh delete <host_ip> -d
9. Modify /etc/dhcp/dhcpd.conf file and apply hooks either at the global or pool-level (see https://pastebin.com/vXjERNuS)
10. Perform a DHCP request/renew
11. Check /var/log/syslog for Dynamic DNS entries.
Comments
0 B
|👍
/👎