[Freeipa-users] Re: ipa-replica-install -- cannot get past [26/41]: creating DS keytab

2019-01-30 Thread Jonathon Jenkins via FreeIPA-users
I have found the issue - on the master there was an old krbPrincipalName associated with this host. Clearing it out allowed this process to finish. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] ipa-replica-install -- cannot get past [26/41]: creating DS keytab

2019-01-30 Thread Jonathon Jenkins via FreeIPA-users
Greetings, I cannot get the ipa-replica-install to proceed past step 26/41 - creating DS keytab. I see the command that is to be run, and I can run that just fine before and after the ipa-replica-install command, and it creates the keytab. I am not sure how to proceed from here - the bug

[Freeipa-users] Re: Migrating named from bind to flat files

2018-09-28 Thread Jonathon Jenkins via FreeIPA-users
Hi John, Thanks for the reply. Here's why I was thinking I could move to flat files: I've noted that when creating ipa-replia servers, I have needed to specify '--setup-dns' along with a forwarding option if I wanted the server to configure named-pkcs11 to use the bind backend. Otherwise, named

[Freeipa-users] Migrating named from bind to flat files

2018-09-27 Thread Jonathon Jenkins via FreeIPA-users
Greetings, I have a set-up that has many Freeipa servers throughout various regions, acting as DNS servers throughout these regions. To set the stage, I, along with my colleagues, are competent in FreeIPA administration, but we're not ldap experts. We've had a couple scenarios wherein changes to