Re: [Freeipa-users] routing requests to local servers - DNS SRV + view?

2012-04-13 Thread Brian Cook
Yes, this is exactly what I am trying to accomplish. I've already been looking in to the BIND views clause and would like to hear if anyone has any feedback as to how well this works in the real world. In this case the implementation of IPA is using an external standard BIND implementation loa

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Rich Megginson
On 04/13/2012 03:40 PM, Dan Scott wrote: On Fri, Apr 13, 2012 at 16:41, Rich Megginson wrote: On 04/13/2012 02:30 PM, Dan Scott wrote: On Fri, Apr 13, 2012 at 15:24, Rich Megginsonwrote: It's not a problem until it's a problem :-) I would go ahead and run CLEANRUV. I cleaned up a load o

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
On Fri, Apr 13, 2012 at 16:41, Rich Megginson wrote: > On 04/13/2012 02:30 PM, Dan Scott wrote: >> >> On Fri, Apr 13, 2012 at 15:24, Rich Megginson  wrote: >>> It's not a problem until it's a problem :-)  I would go ahead and run >>> CLEANRUV. >> >> I cleaned up a load of these entries, but now I

Re: [Freeipa-users] routing requests to local servers - DNS SRV + view?

2012-04-13 Thread Petr Spacek
On 04/13/2012 10:28 PM, Jakub Hrozek wrote: On Fri, Apr 13, 2012 at 01:04:55PM -0700, Brian Cook wrote: Ideally I would rely on a -group- of servers, and then rely on DNS if it is down. I don't want to hammer one server. We're talking about 500-1000 servers running virtual machines

Re: [Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Kelvin Edmison
On 2012-04-13, at 4:25 PM, Rob Crittenden wrote: > Kelvin Edmison wrote: >> >> On 2012-04-13, at 1:18 PM, Rob Crittenden wrote: >> >>> Kelvin Edmison wrote: On 2012-04-13, at 1:09 PM, Rob Crittenden wrote: > Kelvin Edmison wrote: >> Hi, >> >> When troubleshooti

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Rich Megginson
On 04/13/2012 02:30 PM, Dan Scott wrote: On Fri, Apr 13, 2012 at 15:24, Rich Megginson wrote: On 04/13/2012 01:03 PM, Dan Scott wrote: If I'm interpreting this correctly, it can't be deleted because it's not a leaf node, but it doesn't have any sub-entries that I can delete first. You are cor

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
On Fri, Apr 13, 2012 at 15:24, Rich Megginson wrote: > On 04/13/2012 01:03 PM, Dan Scott wrote: If I'm interpreting this correctly, it can't be deleted because it's not a leaf node, but it doesn't have any sub-entries that I can delete first. >>> >>> You are correct.  Try this: >>>

Re: [Freeipa-users] routing requests to local servers

2012-04-13 Thread Jakub Hrozek
On Fri, Apr 13, 2012 at 01:04:55PM -0700, Brian Cook wrote: >Ideally I would rely on a -group- of servers, and then rely on DNS if it >is down. I don't want to hammer one server. We're talking about 500-1000 >servers running virtual machines, so potentially a lot of traffic. Got >

Re: [Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Rob Crittenden
Kelvin Edmison wrote: On 2012-04-13, at 1:18 PM, Rob Crittenden wrote: Kelvin Edmison wrote: On 2012-04-13, at 1:09 PM, Rob Crittenden wrote: Kelvin Edmison wrote: Hi, When troubleshooting what I thought was an NFS4 issue, I have found what looks to be a bug in ipa-client-install. On a

Re: [Freeipa-users] routing requests to local servers

2012-04-13 Thread Brian Cook
Ideally I would rely on a -group- of servers, and then rely on DNS if it is down. I don't want to hammer one server. We're talking about 500-1000 servers running virtual machines, so potentially a lot of traffic. Got any suggestions for that? --- Brian Cook Solutions Architect, Red Hat, Inc

Re: [Freeipa-users] routing requests to local servers

2012-04-13 Thread Rob Crittenden
Brian Cook wrote: Has anyone worked any magic to keep DNS, kerberos and LDAP request routed to local servers in an IPA setup where topology is separated by WAN links? I have looked at things like doing sorts in the DNS client configuration, BIND views, etc. but I would like to know if anyone els

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Rich Megginson
On 04/13/2012 01:03 PM, Dan Scott wrote: Thanks for the quick response. Simo: Thanks - I'd prefer to clean it up properly rather than start from scratch. I haven't changed the LDAP schema at all. All I've done is the use the IPA tools for user admin and add/remove replicas. I just felt like I'v

[Freeipa-users] routing requests to local servers

2012-04-13 Thread Brian Cook
Has anyone worked any magic to keep DNS, kerberos and LDAP request routed to local servers in an IPA setup where topology is separated by WAN links? I have looked at things like doing sorts in the DNS client configuration, BIND views, etc. but I would like to know if anyone else has tried to tac

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
Thanks for the quick response. Simo: Thanks - I'd prefer to clean it up properly rather than start from scratch. I haven't changed the LDAP schema at all. All I've done is the use the IPA tools for user admin and add/remove replicas. I just felt like I've been emailing this list once a week or so

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Rich Megginson
On 04/13/2012 12:22 PM, Dan Scott wrote: On Fri, Apr 13, 2012 at 13:43, Rich Megginson wrote: On 04/13/2012 11:39 AM, Dan Scott wrote: I'm convinced that my LDAP directories contain lots of cruft which has built up and is causing problems on my system. There may even be some corruption since t

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Simo Sorce
On Fri, 2012-04-13 at 13:39 -0400, Dan Scott wrote: > Hi, > > I've been using FreeIPA for a couple of years (Upgraded/Migrated from > FreeIPA 1). The servers are in various states (Some upgraded from > Fedora 10/11 through each release, some fresh installs of Fedora > 15/16). I've also had to add/

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
On Fri, Apr 13, 2012 at 13:43, Rich Megginson wrote: > On 04/13/2012 11:39 AM, Dan Scott wrote: >> I'm convinced that my LDAP directories contain lots of cruft which has >> built up and is causing problems on my system. There may even be some >> corruption since there's an entry which I'm unable t

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Rich Megginson
On 04/13/2012 11:39 AM, Dan Scott wrote: Hi, I've been using FreeIPA for a couple of years (Upgraded/Migrated from FreeIPA 1). The servers are in various states (Some upgraded from Fedora 10/11 through each release, some fresh installs of Fedora 15/16). I've also had to add/remove replicas many

[Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
Hi, I've been using FreeIPA for a couple of years (Upgraded/Migrated from FreeIPA 1). The servers are in various states (Some upgraded from Fedora 10/11 through each release, some fresh installs of Fedora 15/16). I've also had to add/remove replicas many times - and run into problems installing wh

Re: [Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Kelvin Edmison
On 2012-04-13, at 1:18 PM, Rob Crittenden wrote: > Kelvin Edmison wrote: >> >> On 2012-04-13, at 1:09 PM, Rob Crittenden wrote: >> >>> Kelvin Edmison wrote: Hi, When troubleshooting what I thought was an NFS4 issue, I have found what looks to be a bug in ipa-client-install

Re: [Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Rob Crittenden
Kelvin Edmison wrote: On 2012-04-13, at 1:09 PM, Rob Crittenden wrote: Kelvin Edmison wrote: Hi, When troubleshooting what I thought was an NFS4 issue, I have found what looks to be a bug in ipa-client-install. On a CentOS 5.8 machine, I ran ipa-client-install --no-ntp --force --hostname=k

Re: [Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Kelvin Edmison
On 2012-04-13, at 1:09 PM, Rob Crittenden wrote: > Kelvin Edmison wrote: >> Hi, >> >> When troubleshooting what I thought was an NFS4 issue, I have found what >> looks to be a bug in ipa-client-install. >> >> On a CentOS 5.8 machine, I ran >> ipa-client-install --no-ntp --force --hostname=kelv

Re: [Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Rob Crittenden
Kelvin Edmison wrote: Hi, When troubleshooting what I thought was an NFS4 issue, I have found what looks to be a bug in ipa-client-install. On a CentOS 5.8 machine, I ran ipa-client-install --no-ntp --force --hostname=kelvin-c5. and successfully bound to the domain. I am now trying to get nfs

[Freeipa-users] ipa-client-install on CentOS 5 creating zero-length /etc/sysconfig/network file

2012-04-13 Thread Kelvin Edmison
Hi, When troubleshooting what I thought was an NFS4 issue, I have found what looks to be a bug in ipa-client-install. On a CentOS 5.8 machine, I ran ipa-client-install --no-ntp --force --hostname=kelvin-c5. and successfully bound to the domain. I am now trying to get nfs4 up and running, and f

[Freeipa-users] multiple domains/realms?

2012-04-13 Thread Christoph Kaminski
HiI have multiple domains her but I want to use one user/group etc. database. How can I do it? Options:1. Different realm for each domain, but how to share the user/group etc infos betwen different ipa servers?2. One realm for al domains. Possible? (it is possible to change the realm after install