On 6.5.2015 10:06, Petr Spacek wrote:
> General advice about views is
> 'do not use them' :-)
> 
> It is much cleaner to put internal names in a sub-domain like int.example.com.
> (while example.com. is the public-facing domain) and restrict access to this
> sub-domain using ACL.
> 
> In long term it will make your life much easier when it comes to DNSSEC
> validation. Please see
> http://www.freeipa.org/page/Deployment_Recommendations#DNS for other related
> recommendations.
> 
> I hope this helps.

I tried to summarize this for future generations:
http://www.freeipa.org/page/DNS#Caveats

-- 
Petr^2 Spacek

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to