funnily(?) enough... it is peculiar.

Only after I disabled/demoted key master - so there was none in the domain - then enabled/promoted key master on a different DNS server then... repeated this "action" on each remaining DNS master, only then DNSSEC records started propagating across all servers/masters.

Also, on some master first try would fail with:
...
Do you want to search for missing reverse zones? [yes]: no
[Errno 13] Permission denied: '/var/lib/ipa/sysrestore/7fc1acff6ed4f4cd0309c4510e17adfc3c1349c9782bcc12caacbad49da75383-hosts

then immediate, second try succeeded.

My deployment, my masters are in containers - perhaps this might serve as note for others with similar/same type of deployment in case of similar issues (but I had DNSSEC issue in the past which now I think might have contributed to, originated this problem)

thanks, L.
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to