Bug 1004156 - ipa-replica-install should add new NS records to all zones (for redundancy)
ipa-replica-install should add new NS records to all zones (for redundancy)
Status: CLOSED WONTFIX
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.0
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Martin Kosek
Namita Soman
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2013-09-04 02:16 EDT by Martin Kosek
Modified: 2013-10-22 04:54 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Known Issue
Doc Text:
When DNS support is being added for an Identity Management server (for example, by using the ipa-dns-install or by using the --setup-dns flag in ipa-server-install or ipa-replica-install), the script adds a hostname of a new Identity Management DNS server to the list of name servers in the primary Identity Management DNS zone (via DNS NS record). However, it does not add the DNS name server record to other DNS zones served by the Identity Management. As a consequence, the list of name servers in the non-primary DNS zones has only a limited set of Identity Management name servers serving the DNS zone (only one, without user intervention). When the limited set of Identity Management name servers is not available, these DNS zones are not resolvable. To work around this problem, manually add new DNS name server records to all non-primary DNS zones when a new Identity Management replica is being added. Also manually remove such DNS name server records when the replica is being decommissioned. Non-primary DNS zones can maintain higher availability by having a manually maintained set of Identity Management name servers serving it.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-09-04 02:27:33 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Kosek 2013-09-04 02:16:05 EDT
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3343

''ipa-replica-install --setup-dns'' adds NS record pointing to the new replica only to some DNS zones. NS record should be added to *all* existing zones managed by IPA.

There is no redundancy without proper NS records.
Comment 1 Martin Kosek 2013-09-04 02:27:33 EDT
Please document in 7.0, this issue won't be fixed in this version.

Note You need to log in before you can comment on or make changes to this bug.