[Freeipa-users] Re: SSHFP records

2022-02-09 Thread Rob Crittenden via FreeIPA-users
Simon Matthews via FreeIPA-users wrote: > My primary nameserver is on another machine. It is already configured with an > RNDC key to allow updates from DHCP. > > How would I tell IPA to use this RNDC key to update the primary? > > I assume that these updates come from the IPA server, not the

[Freeipa-users] Re: SSHFP records

2022-02-09 Thread Simon Matthews via FreeIPA-users
My primary nameserver is on another machine. It is already configured with an RNDC key to allow updates from DHCP. How would I tell IPA to use this RNDC key to update the primary? I assume that these updates come from the IPA server, not the client when enrolling a client. Currently, the

[Freeipa-users] Re: SSHFP records

2022-02-09 Thread Sam Morris via FreeIPA-users
Only a problem if you want to use SSHFP records to verify the host keys presented by the SSH server running on the client. When SSHing to the client from another machine that has been enrolled, the host key will usually be verified by sss_ssh_knownhostsproxy which does not use SSHFP records.

[Freeipa-users] Re: SSHFP Records on external DNS

2017-12-03 Thread Anvar Kuchkartaev via FreeIPA-users
From client command line ssh-keygen -r `hostname` will give you sshfp records. Anvar Kuchkartaev  an...@aegisnet.eu    Original Message   From: Günther J. Niederwimmer via FreeIPA-users Sent: domingo, 3 de diciembre de 2017 15:50 To: freeipa-users@lists.fedorahosted.org Reply To: FreeIPA users