Hide Forgot
This bug is created as a clone of upstream ticket: https://fedorahosted.org/freeipa/ticket/1408 If a client is in a subnet not controlled by an IPA DNS server then the nsupdate may fail to add the client. One option would be to perform a DNS query to see who is authoritative for the reverse zone and warn the user if it is not one of the IPA servers. We'd also have to see if DNS is configured in IPA at all. The IPA servers can be found in cn=masters,cn=ipa,cn=etc,$BASEDN.
Added to client install troubleshooting: http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/troubleshooting-client-install.html#id4629718
Verified the additional troubleshooting in: http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/troubleshooting-client-install.html#id4629718 Red_Hat_Enterprise_Linux-Identity_Management_Guide-6-en-US-2.2.0-2 ---