On 6.5.2015 10:06, Petr Spacek wrote: > General advice about views is > 'do not use them' :-) > > It is much cleaner to put internal names in a sub-domain like int.example.com. > (while example.com. is the public-facing domain) and restrict access to this > sub-domain using ACL. > > In long term it will make your life much easier when it comes to DNSSEC > validation. Please see > http://www.freeipa.org/page/Deployment_Recommendations#DNS for other related > recommendations. > > I hope this helps.
I tried to summarize this for future generations: http://www.freeipa.org/page/DNS#Caveats -- Petr^2 Spacek -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project