Bug 809190
| Summary: | ipa-server-install fails when domain name is not resolvable | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Namita Soman <nsoman> | ||||
| Component: | ipa | Assignee: | Rob Crittenden <rcritten> | ||||
| Status: | CLOSED ERRATA | QA Contact: | IDM QE LIST <seceng-idm-qe-list> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 6.2 | CC: | jgalipea, mkosek | ||||
| Target Milestone: | rc | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | ipa-2.2.0-9.el6 | Doc Type: | Bug Fix | ||||
| Doc Text: |
No documentation needed.
|
Story Points: | --- | ||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2012-06-20 13:26:26 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
|
Description
Namita Soman
2012-04-02 17:34:22 UTC
Upstream ticket: https://fedorahosted.org/freeipa/ticket/2602 master: 184a066f4abc0ef83434f8cebbec87028258db65 ipa-2-2: 173f4ae073502f9f1b1adb1e1cc8f063693c5c31
Technical note added. If any revisions are required, please edit the "Technical Notes" field
accordingly. All revisions will be proofread by the Engineering Content Services team.
New Contents:
No documentation needed.
verified using ipa-server-2.2.0-12.el6.x86_64
Was able to successfully install when server hostname was not in a default domain
Verified cli works...added user, modified permission etc
Verified UI, logged in, added host, where dropdown listed both testrelm, and testrelm.com..added one in each
Also verified DNS records...the record for the domain, the host is not in, included fqdn for the host
# ipa dnsrecord-find testrelm
Record name: @
NS record: ipaserver.testrelm.com.
Record name: _kerberos
TXT record: TESTRELM.COM
Record name: _kerberos-master._tcp
SRV record: 0 100 88 ipaserver.testrelm.com.
Record name: _kerberos-master._udp
SRV record: 0 100 88 ipaserver.testrelm.com.
Record name: _kerberos._tcp
SRV record: 0 100 88 ipaserver.testrelm.com.
Record name: _kerberos._udp
SRV record: 0 100 88 ipaserver.testrelm.com.
Record name: _kpasswd._tcp
SRV record: 0 100 464 ipaserver.testrelm.com.
Record name: _kpasswd._udp
SRV record: 0 100 464 ipaserver.testrelm.com.
Record name: _ldap._tcp
SRV record: 0 100 389 ipaserver.testrelm.com.
Record name: _ntp._udp
SRV record: 0 100 123 ipaserver.testrelm.com.
-----------------------------
Number of entries returned 10
-----------------------------
# ipa dnsrecord-find testrelm.com
Record name: @
NS record: ipaserver.testrelm.com.
Record name: ipaserver
A record: 10.16.187.114
SSHFP record: 1 1 C67DE264098040A0C6F8005DBCCDCB3C5DB8186C, 2 1
A20F9E13B7741CD82E2CBBDC44A4EED29B22AAEA
----------------------------
Number of entries returned 2
----------------------------
Verified krb5.con has entries for both domains:
# cat /etc/krb5.conf
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = TESTRELM.COM
dns_lookup_realm = false
dns_lookup_kdc = false
rdns = false
ticket_lifetime = 24h
forwardable = yes
[realms]
TESTRELM.COM = {
kdc = ipaserver.testrelm.com:88
admin_server = ipaserver.testrelm.com:749
default_domain = testrelm
pkinit_anchors = FILE:/etc/ipa/ca.crt
}
[domain_realm]
.testrelm = TESTRELM.COM
testrelm = TESTRELM.COM
.testrelm.com = TESTRELM.COM
testrelm.com = TESTRELM.COM
[dbmodules]
TESTRELM.COM = {
db_library = ipadb.so
}
Also verified setup where: Installed master on ipamaster.us.testrelm.com #ipa-server-install --setup-dns --forwarder=10.14.63.12 --hostname ipamaster.us.testrelm.com -r TESTRELM.COM -n testrelm.com -p Secret123 -P Secret123 -a Secret123 --ip-address 10.16.96.83 Then one replica on - ipareplica1.eu.testrelm.com And a second replica on - ipareplica3.aus.example.com was able to kinit, and add users from any system, and find it on the other. # ipa-replica-manage list ipamaster.us.testrelm.com: master ipareplica1.eu.testrelm.com: master ipareplica3.aus.example.com: master Created attachment 582678 [details]
outputs from dnszone-find dnsrecord-find
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0819.html |