Re: [Freeipa-users] Virtualising FreeIPA domain controller

2012-03-02 Thread Simo Sorce
On Fri, 2012-03-02 at 15:39 +0100, Ondrej Valousek wrote: > > > Well I do not know about just 'pausing' it sounds not plausible to me, > > except wrt clock skew which may cause krb auth and replication to fail. > > > Yes, that's exactly what is happening. This should be easily fixed by making su

Re: [Freeipa-users] Virtualising FreeIPA domain controller

2012-03-02 Thread Ondrej Valousek
Well I do not know about just 'pausing' it sounds not plausible to me, except wrt clock skew which may cause krb auth and replication to fail. Yes, that's exactly what is happening. But if you restore such a snapshot after the original machine had a fatal accident then it may come with issues

Re: [Freeipa-users] Virtualising FreeIPA domain controller

2012-03-02 Thread Simo Sorce
On Fri, 2012-03-02 at 12:37 +0100, Ondrej Valousek wrote: > I just got an information that it is a very bad idea to have virtual > Domain controllers in Active Directory - server's (and potentially the > whole AD) metadata gets corrupted once you 'pause' the machine - just > to get a snapshot or ba