On Fri, 2011-11-04 at 16:43 +0100, tomasz.napier...@allegro.pl wrote:
> On 4 lis 2011, at 14:52, Rob Crittenden wrote:
> > Can you provide more context from the client install log (or the whole log)?
> Sure:
> http://pastie.org/2810505
> One more thing:in that domain (.dc2) there is already working IPA 1.x, and we 
> have DNS entries pointing to that installation. It might be KDC autodiscovery 
> issue, but how can I disable auto discovery?

Not necessarily related to your problem, but in general I would strongly
suggest all freeipa users to:

a) use domain names that are longer than a single component
   (for example in your case 'ipa.dc2' instead of just 'dc2')

b) let the kerberos realm exactly match the domain name.
   (In your case let it be 'IPA.DC2')

We do not enforce these rules but not following them can cause you
additional headaches in some cases.


Simo Sorce * Red Hat, Inc * New York

Freeipa-users mailing list

Reply via email to