Yeah, think so, filed:
https://bugzilla.redhat.com/show_bug.cgi?id=1533228
On Wed, Jan 10, 2018 at 8:07 PM, Martin Basti via FreeIPA-users <
freeipa-users@lists.fedorahosted.org> wrote:
> You should open a bug about this, IPA should not fail if zone where
> replica belongs is a forward zone.
>
You should open a bug about this, IPA should not fail if zone where replica
belongs is a forward zone.
Probably the easiest solution might be to update FreeIPA's code before
installing.
/usr/lib/python??/site-packages/ipaserver/install/bindinstance.py:add_rr
and replace lines showed in diff:
---
OK, just reproduced the error:
[root@ipa2 ~]# ipa-replica-install -v -w $pw -n ipa.pdp7.net -P alex
--mkhomedir --setup-ca --setup-dns --auto-forwarders
[...]
ipa : DEBUG [2/8]: setting up our own record
[2/8]: setting up our own record
ipa.ipaserver.plugins.dns.dnsrecord_add:
Ah, wait, this new replica doesn't have CA and DNS. Will try various
combinations and post back.
On Tue, Jan 9, 2018 at 10:03 PM, Alex Corcoles wrote:
> That's weird. I've now tried a replica install on a fresh VM and it has
> worked- exact same parameters as before ¬ ¬U, no
That's weird. I've now tried a replica install on a fresh VM and it has
worked- exact same parameters as before ¬ ¬U, no "invalid
'dnszoneidnsname': only master zones can contain records". Maybe I had a
problem with the previous install failing and me cleaning up/retrying
incorrectly.
Never
do you have a traceback in log? I'm curious where exactly this happened,
what is your FreeIPA version?
[1]
I haven't install FreeIPA in LXC, but I'm happy user of FreeIPA running in
LXC :-) So it should work
2018-01-09 11:40 GMT+01:00 Alex Corcoles via FreeIPA-users <
Hi Marti,
On Tue, Jan 9, 2018 at 12:46 AM, Martin Basti via FreeIPA-users <
freeipa-users@lists.fedorahosted.org> wrote:
> it looks that replica is trying to add records to your forward zone. What
> is the hostname of the replica?
>
Yeah, it's xxx.h2.int.pdp7.net, which is within the forwarded