---
title: "Configuring GSS-TSIG"
canonical: "https://docs.infoblox.com/space/BloxOneDDI/186876219/Configuring%20GSS-TSIG"
format: markdown
---
<span style="color: #000000">GSS-TSIG (Generic Security Service Algorithm for Secret Key Transaction) is used to authenticate DDNS updates. It is a variant of the TSIG authentication which uses the Kerberos v5 authentication system.</span>

<span style="color: #000000">GSS-TSIG consists of a set of client-server negotiations to establish a security context. It makes use of a Kerberos server (for example, when it is running on the AD domain controller) that functions as the Kerberos KDC (Key Distribution Center) and provides session tickets and temporary session keys to users and computers within an Active Directory (AD) domain. Together, the client and server create and verify transaction signatures on messages they exchange. Microsoft Server versions 2012 R2, 2016, and 2019 support DDNS updates that use GSS-TSIG. You can configure the NIOS-X Server to accept GSS-TSIG–signed DDNS updates from one or more clients that belong to different AD domains in which each domain has a unique Kerberos key that corresponds to a DNS service principal.</span>

![t_GSS-TSIG-B1DDI.drawio.png](media://66b74edc-ea25-4079-9197-f39fa4ee80a6)


> Macro (excerpt)
> 
> > Macro (drawio)

The following is a high-level diagram of the GSS-TSIG process:

<span style="color: #000000">To view the list of GSS-TSIG entries:</span>

- <span style="color: #000000">If you are a user,  click </span><span style="color: #000000">**Configure > Administration > TSIG Keys >**</span><span style="color: #000000"> </span><span style="color: #000000">**GSS-TSIG**</span><span style="color: #000000">. If there are multiple entries, click the particular entry to view its details. If there are no entries, you can create one by following the instructions in </span><span style="color: #000000">*[Creating GSS-TSIG](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186746728)*</span><span style="color: #000000">.</span>
- <span style="color: #000000">If you are an administrator, you can create, edit, or delete a GSS-TSIG entry. If you are a user, you can only view a GSS-TSIG entry. For more information, see </span><span style="color: #000000">*[Role-based Access Control](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186681007)*</span><span style="color: #000000">[.](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186681007)</span>

> ⚠️ After enabling GSS-TSIG, you can view the transactions in service logs. For more information, see *[Viewing Service Logs](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneDDI/pages/186466397)**.*

<span style="color: #000000">You can also do the following in the GSS-TSIG tab:</span>

- <span style="color: #000000">Reorder the columns, or select the columns to be displayed: Click the menu button, </span>> Macro (inline-media-image)

<span style="color: #000000">.</span>
- <span style="color: #000000">Modify a GSS-TSIG entry: Click the menu button, </span>> Macro (inline-media-image)

<span style="color: #000000"> and then </span><span style="color: #000000">**Edit**</span><span style="color: #000000">, or select the checkbox for a specific record and click the </span><span style="color: #000000">**Edit**</span><span style="color: #000000"> button.</span>
- <span style="color: #000000">Delete the GSS-TSIG entry: Click the menu button, </span>> Macro (inline-media-image)

<span style="color: #000000"> and then </span><span style="color: #000000">**Delete**</span><span style="color: #000000">, or select the respective AnyCast address and click the </span><span style="color: #000000">**Delete**</span><span style="color: #000000"> button. A GSS-TSIG entry can be deleted only if it is not used in the GSS-TSIG DNS configuration in the Global DNS Properties, in the DNS Config profile, or at the level of the DNS server.</span>
- <span style="color: #000000">GSS-TSIG entry's information, such as principal, algorithm, version, domain (realm), comment, and tags are shown in the information pane by default. Comment and tags can be modified. If you do not want to view the details in the panel on the right, click the information button, </span>> Macro (inline-media-image)

<span style="color: #000000">.</span>
- <span style="color: #000000">Search for records in Universal DDI according to a specific keyword: Type the keyword in the </span><span style="color: #000000">**Search**</span><span style="color: #000000"> text box. </span>
- <span style="color: #000000">Filter the objects by </span><span style="color: #000000">**Principal**</span><span style="color: #000000">, </span><span style="color: #000000">**Domain, Version, Algorithm, Comments**</span><span style="color: #000000">, or </span><span style="color: #000000">**Tags**</span><span style="color: #000000">:  Click the filter button, </span>> Macro (inline-media-image)

<span style="color: #000000">.  To save a filter after selecting the required parameters click the save button, </span>> Macro (inline-media-image)

<span style="color: #000000">, specify a name for the filter, and click </span><span style="color: #000000">**Save & Close**</span><span style="color: #000000">. To reload a previously saved filter, click the star button, </span>> Macro (inline-media-image)

<span style="color: #000000">, and select the required filter. </span>

<span style="color: #000000">You can perform the following actions:</span>

> Macro (children)