Re: [Freeipa-users] Register IPA-Clients within AD domain

2017-03-29 Thread Ronald Wimmer

On 2017-03-29 11:06, Alexander Bokovoy wrote:

On ke, 29 maalis 2017, Ronald Wimmer wrote:

[...]

Read
http://www.freeipa.org/page/V4/IPA_Client_in_Active_Directory_DNS_domain
There are also higher level description at
http://rhelblog.redhat.com/2016/07/13/i-really-cant-rename-my-hosts/

Thanks a lot!

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


Re: [Freeipa-users] Register IPA-Clients within AD domain

2017-03-29 Thread Alexander Bokovoy

On ke, 29 maalis 2017, Ronald Wimmer wrote:

Hi,

the documentation states "[...] Client machines do not need to be in 
the same domain as FreeIPA servers. For example, FreeIPA may be a 
domain ipa.example.com and clients in domain clients.example.com, 
there just need to be a clear mapping between DNS domain and Kerberos 
realm. [...]"


Can clients be registered properly if the clients.example.com domain 
is an existing Active Directory domain which - of course - already has 
_kerberos entries in DNS?

Read http://www.freeipa.org/page/V4/IPA_Client_in_Active_Directory_DNS_domain
There are also higher level description at 
http://rhelblog.redhat.com/2016/07/13/i-really-cant-rename-my-hosts/


--
/ Alexander Bokovoy

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project