Re: [Freeipa-users] The concept of sites...

2011-10-20 Thread Ondrej Valousek
toria University, Wellington, NZ 0064 4 463 6272 From: Sigbjorn Lie [sigbj...@nixtra.com] Sent: Thursday, 20 October 2011 9:11 a.m. To: Steven Jones Cc: freeipa-users@redhat.com Subject: RE: [Freeipa-users] The concept of sites... I see your point

Re: [Freeipa-users] The concept of sites...

2011-10-20 Thread Sigbjorn Lie
gt;> >>> regards >>> >>> Steven Jones >>> >>> >>> >>> Technical Specialist - Linux RHCE >>> >>> >>> >>> Victoria University, Wellington, NZ >>> >>> >>> >>

Re: [Freeipa-users] The concept of sites...

2011-10-20 Thread Ondrej Valousek
0064 4 463 6272 From: Sigbjorn Lie [sigbj...@nixtra.com] Sent: Thursday, 20 October 2011 9:11 a.m. To: Steven Jones Cc: freeipa-users@redhat.com Subject: RE: [Freeipa-users] The concept of sites... I see your point with a messy dns infrastructure, however this woul

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Sigbjorn Lie
2 > > > > From: Sigbjorn Lie [sigbj...@nixtra.com] > Sent: Thursday, 20 October 2011 9:11 a.m. > To: Steven Jones > Cc: freeipa-users@redhat.com > Subject: RE: [Freeipa-users] The concept of sites... > > > I see your point wit

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Sigbjorn Lie
On Wed, October 19, 2011 21:27, Simo Sorce wrote: > On Wed, 2011-10-19 at 15:24 -0400, Dmitri Pal wrote: > >> On 10/19/2011 03:14 PM, Sigbjorn Lie wrote: >> >>> Hi, >>> >>> >>> Has there been given any thought to the concept of sites within IPA to >>> improve cross-site implementations? This shou

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Steven Jones
Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 From: Sigbjorn Lie [sigbj...@nixtra.com] Sent: Thursday, 20 October 2011 9:11 a.m. To: Steven Jones Cc: freeipa-users@redhat.com Subject: RE: [Freeipa-users] The concept of sites...

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Sigbjorn Lie
I see your point with a messy dns infrastructure, however this would happen in the background. You would still only have one kerberos realm per IPA instance. Rgds, Siggi On Wed, October 19, 2011 21:30, Steven Jones wrote: > Hi, > > > I think AD sort of does this which they have now backed a

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Steven Jones
Hi, I think AD sort of does this which they have now backed away from? >From my very limited understanding having sub-domains/realms seems to be >counter-productivein that trying to do cross-realm trusts/passwords/user >info becomes a nightmare? I know somehow I have to get unix.vuw.ac.nz

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Simo Sorce
On Wed, 2011-10-19 at 15:24 -0400, Dmitri Pal wrote: > On 10/19/2011 03:14 PM, Sigbjorn Lie wrote: > > Hi, > > > > Has there been given any thought to the concept of sites within IPA to > > improve cross-site implementations? This should be easy to implement > > as you are already using DNS SRV rec

Re: [Freeipa-users] The concept of sites...

2011-10-19 Thread Dmitri Pal
On 10/19/2011 03:14 PM, Sigbjorn Lie wrote: > Hi, > > Has there been given any thought to the concept of sites within IPA to > improve cross-site implementations? This should be easy to implement > as you are already using DNS SRV records to locate the ldap/kerberos > servers. > > E.g. > Site: Bost