Re: [Freeipa-users] Unable to enroll new client in DNS

2015-10-22 Thread Petr Spacek
On 21.10.2015 22:43, Justin Lambert wrote: > ;; ANSWER SECTION: > 2667812275.sig-ipa1.domain.com. 0 ANY TKEY gss-tsig. 0 0 3 BADKEY 0 0 > > dns_tkey_negotiategss: TKEY is unacceptable Please consult named logs on server ipa1.domain.com and see if there are any errors related to dynamic update.

Re: [Freeipa-users] Unable to enroll new client in DNS

2015-10-22 Thread Petr Spacek
On 22.10.2015 14:23, Justin Lambert wrote: > When I looked at the DNS logs there was nothing of any value (with a fresh > attempt of registering DNS records) so I added a logging channel for ldap > at severity 9. After restarting bind the DNS registration worked without > issue. Removing the

Re: [Freeipa-users] Unable to enroll new client in DNS

2015-10-22 Thread Justin Lambert
When I looked at the DNS logs there was nothing of any value (with a fresh attempt of registering DNS records) so I added a logging channel for ldap at severity 9. After restarting bind the DNS registration worked without issue. Removing the logging channel and re-running the update worked. It

[Freeipa-users] Unable to enroll new client in DNS

2015-10-21 Thread Justin Lambert
I have been trying to register a new node in my FreeIPA server and it isn’t adding DNS records. The host itself gets registered, but DNS updates during the ipa-client-install script fails. The servers and the client are both CentOS 7.1 running version 4.1.0-18. Below is the output showing the