Re: [Freeipa-users] LDAP - Load Balancer - SSL cert with SAN

2017-01-03 Thread Maciej Drobniuch
I see. Generally the SAN thing I mentioned does the job but definitely not in your case. A IPA power user is needed here. On Tue, Jan 3, 2017 at 4:26 PM, Michael Plemmons < michael.plemm...@crosschx.com> wrote: > Maciej, > Thank you for the information. I am not terminating at a load > balan

Re: [Freeipa-users] LDAP - Load Balancer - SSL cert with SAN

2017-01-03 Thread Michael Plemmons
Maciej, Thank you for the information. I am not terminating at a load balancer. Originally, I was trying to use a Route53 DNS CNAME entry of ipa.dev.crosschx.com but we found documentation that says the entry should be an A record and not a CNAME. I then created an A record in FreeIPA for ipa.d

Re: [Freeipa-users] LDAP - Load Balancer - SSL cert with SAN

2017-01-03 Thread Maciej Drobniuch
Hello Mike, I don't know if I'm aligned with your problem, but generally I was facing a SAN cert issue too. Not sure if you're terminating SSL/TLS on the load balancer or not? Usually I do SAN certs in IPA via GUI/IdM. I am adding a service and hosts assigned to that service. Every host has an