# Include this in dhcpd.conf to have DHCPd create Dynamic DNS entries in Active Directory # DNS using GSS-TSIG/Kerberos authentication. # # Refer to https://pastebin.com/SRPh7Bcu for step-by-step instructions. # # Adapted from # https://unix.stackexchange.com/questions/270097/isc-dhcp-with-active-directory-secure-dynamic-dns-updates/271815#271815 # https://blog.michael.kuron-germany.de/2011/02/isc-dhcpd-dynamic-dns-updates-against-secure-microsoft-dns/ # # include can be at the global or pool-level. on commit { set noname = concat("dhcp-", binary-to-ascii(10, 8, "-", leased-address)); set ClientIP = binary-to-ascii(10, 8, ".", leased-address); set ClientMac = binary-to-ascii(16, 8, ":", substring(hardware, 1, 6)); set ClientName = pick-first-value(option host-name, host-decl-name, config-option host-name, noname); log(concat("Commit: IP: ", ClientIP, " Mac: ", ClientMac, " Name: ", ClientName)); execute("/usr/local/sbin/dns-krbnsupdate.sh", "add", ClientIP, "-h", ClientName, "-m", ClientMac); } on release { set ClientIP = binary-to-ascii(10, 8, ".", leased-address); set ClientMac = binary-to-ascii(16, 8, ":", substring(hardware, 1, 6)); log(concat("Release: IP: ", ClientIP, " Mac: ", ClientMac)); # cannot get a ClientName here, for some reason that always fails execute("/usr/local/sbin/dns-krbnsupdate.sh", "delete", ClientIP, "-m", ClientMac); } # comment this section if using TXT RR in https://pastebin.com/taNfvCSt on expiry { set ClientIP = binary-to-ascii(10, 8, ".", leased-address); # cannot get a ClientMac here, apparently this only works when actually receiving a packet log(concat("Expired: IP: ", ClientIP)); # cannot get a ClientName here, for some reason that always fails execute("/usr/local/sbin/dns-krbnsupdate.sh", "delete", ClientIP); }