Re: [Freeipa-users] AD-Trust Replica

2017-03-22 Thread Wimmer Ronald (BCC.B.SO)
Shouldn't the replica be seen as a master. I know that the trust does not have to be set up twice but should the samba configuration considering ad trust not be identical to the master? What about the trust-specific DNS entries? Regards, Ronald -- Manage your subscription for the Freeipa-users

[Freeipa-users] AD-Trust Replica

2017-03-22 Thread Wimmer Ronald (BCC.B.SO)
Hi, do I have to setup the AD-trust on the Replica as well? Or is it just the master server where it has to be set up? Regards, Ronald -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on

[Freeipa-users] Potential problems when using a loadbalancer

2017-03-09 Thread Wimmer Ronald (BCC.B.SO)
Hi, what kind of challenges will I run into when I want to use a loadbalancer in front of my two IPA servers? - LDAP: Should not be a problem - Kerberos: will definitely be a challenge. Is this link the solution or am I still missing something: http://directory.fedoraproject.

Re: [Freeipa-users] External DNS and replication

2017-03-09 Thread Wimmer Ronald (BCC.B.SO)
From: Martin Basti [mailto:mba...@redhat.com] Sent: Mittwoch, 08. März 2017 14:54 To: Wimmer Ronald (BCC.B.SO) ; freeipa-users@redhat.com Subject: Re: [Freeipa-users] External DNS and replication On 08.03.2017 14:05, Wimmer Ronald (BCC.B.SO) wrote: Hi, I am using FreeIPA with external DNS. Is

[Freeipa-users] External DNS and replication

2017-03-08 Thread Wimmer Ronald (BCC.B.SO)
Hi, I am using FreeIPA with external DNS. Is it ok to balance the requests between master and replica with DNS SRV records like this: _kerberos-master._tcp.example.net. 86400 IN SRV 10 50 88 ipa1.example.net. _kerberos-master._udp.example.net. 86400 IN SRV 10 50 88 ipa1.example.net. _kerberos._t