[Freeipa-users] Re: ipa-ca DNS record - ?

2022-03-31 Thread lejeczek via FreeIPA-users
On 31/03/2022 13:40, Florence Blanc-Renaud wrote: Hi, The command /ipa dns-update-system-records/ can be used to add the missing records. If you'd rather add them manually, the command can be run with the /--dry-run/ option and will display the expected records but will not perform any upd

[Freeipa-users] Re: ipa-ca DNS record - ?

2022-03-31 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, The command *ipa dns-update-system-records* can be used to add the missing records. If you'd rather add them manually, the command can be run with the *--dry-run* option and will display the expected records but will not perform any update. flo On Thu, Mar 31, 2022 at 2:26 PM Rob Crittenden

[Freeipa-users] Re: ipa-ca DNS record - ?

2022-03-31 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > Hi guys. > > What is 'ipa-ca' for and what should it point to? > Also, should IPA change that record ever? > > Reason I ask - from the docs as I understand - it should point to all CA > servers in the domain, but it not happening. It is a generic name for the

[Freeipa-users] Re: 'ipa-ca' DNS record - where used?

2019-09-02 Thread Alexander Bokovoy via FreeIPA-users
On Mon, 02 Sep 2019, Dmitry Perets via FreeIPA-users wrote: Certificates are issued from IPA CA with the OCSP responder URI http://ipa-ca.$DOMAIN/ca/ocsp and CRL distribution point http://ipa-ca.$DOMAIN/ipa/crl/MasterCRL.bin (these are set in the certificate extensions). flo Thanks! Does it h

[Freeipa-users] Re: 'ipa-ca' DNS record - where used?

2019-09-02 Thread Dmitry Perets via FreeIPA-users
> > Certificates are issued from IPA CA with the OCSP responder URI > http://ipa-ca.$DOMAIN/ca/ocsp and CRL distribution point > http://ipa-ca.$DOMAIN/ipa/crl/MasterCRL.bin (these are set in the > certificate extensions). > > flo Thanks! Does it have to be an IPA server with CA? What if it do

[Freeipa-users] Re: 'ipa-ca' DNS record - where used?

2019-09-02 Thread Florence Blanc-Renaud via FreeIPA-users
On 9/2/19 4:58 PM, Dmitry Perets via FreeIPA-users wrote: Hi, I know of one usage - all the IPA ansible modules (ipa_*) query for 'ipa-ca' record to find the IPA server. But for other cases - looks like IPA clients mostly rely on entries like '_kerberos.*' and '_ldap.*'... What other function