[Freeipa-users] Re: Modify default dirsrv/LDAP certificate (add SAN)

2018-10-16 Thread Andrew Bruce via FreeIPA-users
Hi David - how did you create the IPA service for ldap failover? I have the same setup - multiple LDAP servers, a single "ldap.xxx" DNS record pointing to haproxy loadbalancers. However, I do not understand if you used "ipa service-add" or what to setup in freeipa. Could you paste in your free

[Freeipa-users] Re: Modify default dirsrv/LDAP certificate (add SAN)

2017-07-11 Thread David Goudet via FreeIPA-users
Ok, great. I will do that (and monitor that additional SAN ldapha.xx is persistant after upgrade) Thank you for your help BR - Original Message - From: "Fraser Tweedale" To: "David Goudet" Cc: "FreeIPA users list" Sent: Monday, July 10, 2017 11:25:56 PM Subject: Re: [Freeipa-users]

[Freeipa-users] Re: Modify default dirsrv/LDAP certificate (add SAN)

2017-07-10 Thread Fraser Tweedale via FreeIPA-users
On Mon, Jul 10, 2017 at 02:24:20PM +0200, David Goudet wrote: > Hi, > > Thank you for your response. > > Certmonger will track and manage this certificate (and keep my modification) > but when FreeIPA software will be updated is this SAN configuration will be > persistent? > Is it possible tha

[Freeipa-users] Re: Modify default dirsrv/LDAP certificate (add SAN)

2017-07-10 Thread David Goudet via FreeIPA-users
Hi, Thank you for your response. Certmonger will track and manage this certificate (and keep my modification) but when FreeIPA software will be updated is this SAN configuration will be persistent? Is it possible that LDAP certificate request can be changed (deleted and re-created for exemple

[Freeipa-users] Re: Modify default dirsrv/LDAP certificate (add SAN)

2017-07-09 Thread Fraser Tweedale via FreeIPA-users
On Fri, Jul 07, 2017 at 10:38:25AM +0200, David Goudet via FreeIPA-users wrote: > Hi, > > I am using FreeIPAv4, some of clients products does not support LDAP failover > so i am configuring LDAP loadbalancer based on KeepAlived to do LDAP stream > fail-over. > I have two FreeIPA server (ds01.xxx