Red Hat Bugzilla – Bug 826799
Identity Management Guide DNS Errors
Last modified: 2012-06-26 11:02:18 EDT
Description of problem:
There are errors in the DNS entries as detailed in section
188.8.131.52.1. The IPA-Generated DNS File
; ldap servers
_ldap._tcp IN SRV 0 100 389 ipaserver.example.com
_kerberos IN TXT EXAMPLE.COM
; kerberos servers
_kerberos._tcp IN SRV 0 100 88 ipaserver.example.com
_kerberos._udp IN SRV 0 100 88 ipaserver.example.com
_kerberos-master._tcp IN SRV 0 100 88 ipaserver.example.com
_kerberos-master._udp IN SRV 0 100 88 ipaserver.example.com
_kpasswd._tcp IN SRV 0 100 464 ipaserver.example.com
_kpasswd._udp IN SRV 0 100 464 ipaserver.example.com
After adding these entries into my bind configuration, I realized that I was unable to allow RHEV-M to add this as a domain.
According to KB65509:
The DNS entries should be as follows:
_kerberos._udp IN SRV 0 100 88 rhev.example.com.
_kerberos._tcp IN SRV 0 100 88 rhev.example.com.
_ldap._tcp IN SRV 0 100 389 rhev.example.com.
(Note the missing '.' at the end).
After correcting these entries, I was able to allow RHEVM to add the domain.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Follow Documentation section 184.108.40.206.1. The IPA-Generated DNS File of the Enterprise Identity Management Guide and create DNS entries in bind.
2. Attempt to join RHEVM to the domain the IPA server is serving
1. RHEV-M is unable to join the IPA domain. "Authentication Failure"
1. RHEV-M should be able to join the IPA Domain.
2. Fix is to add the trailing '.' into the DNS entries.
Moving to proper component.
This Bug is applicable for sections:
- 220.127.116.11.1. The IPA-Generated DNS File
- 2.5.2. Creating the Replica
- Example 8.5. SRV Record
- 8.12. Changing Load Balancing for IPA Servers and Replicas
In all these sections, SRV hostname should have the trailing '.' otherwise the SRV records won't work.
* IPA-generated DNS file: http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/dns-file.html
* Example 9.4, SRV record: http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/managing-dnsrecord-entries.html#adding-dns-records-cmd
* Load balancing: http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/load-balancing.html
* Creating a replica (step 5): http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/Setting_up_IPA_Replicas.html#creating-the-replica