[Freeipa-users] Re: URL / Host Aliases and CNAME's. How to create custom internal URL's such as http://portal/ -> https://some-very-long-host01.my.long.domain.com/some-excessively-long-url.html

2021-12-20 Thread Peter Fern via FreeIPA-users
Typically you fix this on your network, not in DNS, by setting the DNS search suffix via DHCP, so that when a user enters http://portal/ they actually resolve http://portal.yourdomain.com/. On 21/12/21 14:55, TomK via FreeIPA-users wrote: Hello, Wondering, how to create custom internal URL's

[Freeipa-users] Re: Migration UI endpoint broken (missing user.js)

2021-10-04 Thread Peter Fern via FreeIPA-users
On 4/10/21 23:42, Alexander Bokovoy wrote: On ma, 04 loka 2021, Peter Fern via FreeIPA-users wrote: Hi all, I'm performing a migration currently, and migrate-ds went smoothly, however when attempting to generate the kerberos credentials as a user, by visiting the documented http://server/ui

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread Peter Fern via FreeIPA-users
On 11/6/19 11:33 pm, John Keates via FreeIPA-users wrote: IPA als already highly available, from the service side using DNS and multiple records for all services, on the web side: every server has a working web interface. If you want to redirect users to any working interface, a generic load

[Freeipa-users] Re: systemd thinks it or something wants ipa service

2019-05-09 Thread Peter Fern via FreeIPA-users
You have the freeipa server package installed, and the systemd service enabled, but the server is not configured.  If you want it to run on this machine, configure the server as suggested right there in the log messages, if not, either remove the package, or disable the systemd  service. On

[Freeipa-users] Re: DHCP + FreeIPA: How to ensure DHCP only servers those IP's NOT defined in FreeIPA DNS?

2019-02-03 Thread Peter Fern via FreeIPA-users
Either specify static allocations in your DHCP server, or set the IPs statically on the nodes from outside the dynamic range, or just enable DDNS updates in SSSD and it should update your DNS records to match whatever IP the node gets at boot. On 4/2/19 7:49 am, TomK via FreeIPA-users wrote:

[Freeipa-users] Re: Problem running IPA client on IPv6 only connection

2019-01-07 Thread Peter Fern via FreeIPA-users
Easiest way without trying to fight the system is probably to get the remote site access to the local network via a VPN. On 8/1/19 12:38 pm, William Muriithi via FreeIPA-users wrote: Hello, I have an IPA clients that has both IPv4 and IPv6 addresses.  One of the IPA client is in the office

[Freeipa-users] Re: Manage public DNS using FreeIPA, when FreeIPA is on internal network/IPs?

2018-11-08 Thread Peter Fern via FreeIPA-users
On 9/11/18 3:07 pm, John Petrini via FreeIPA-users wrote: The mname override now lives in ldap and is configured using the dnsserver-mod command. fake_mname is no longer included in named.conf. I think that feature was added to address this issue: https://pagure.io/bind-dyndb-ldap/issue/162 We

[Freeipa-users] Re: Manage public DNS using FreeIPA, when FreeIPA is on internal network/IPs?

2018-11-08 Thread Peter Fern via FreeIPA-users
It can be done, but there are some caveats you should be aware of: - You'll need to disable the fake_mname that bind gets configured with for your SOA to show up correctly - Any time you add/change a replica, you'll need to check your NS/SOA records and probably correct them again, as they get

[Freeipa-users] Re: Manage public DNS using FreeIPA, when FreeIPA is on internal network/IPs?

2018-11-08 Thread Peter Fern via FreeIPA-users
On 9/11/18 2:14 pm, John Petrini via FreeIPA-users wrote: Yes. When you create a new zone it creates NS records for each IPA server by default but you can change them to whatever you want. If you do this you'll probably want to remove the SOA mname override from each of your IPA DNS servers

[Freeipa-users] Re: upgrade to ubuntu 17.10 fails

2017-12-01 Thread Peter Fern via FreeIPA-users
i/pki.version confusing postinstall in another), but most > of these behaviours were captured as bugs too.  It feels very close to > being something that can be reliably deployed, so I don't think it > needs a huge amount more TLC to make it more of a pleasure to install ;) > > Cheers,

[Freeipa-users] Re: upgrade to ubuntu 17.10 fails

2017-11-28 Thread Peter Fern via FreeIPA-users
On 23/11/17 05:34, David Harvey via FreeIPA-users wrote: > Not sure why tomcat is more resilient when launched as root, but the > pki seems to work ok at issuing certs after the above and a reboot for > good measure. This sounds like there are broken permissions in the current Ubuntu packages.