On 12/04/2024 18.46, C Wilson via FreeIPA-users wrote:
Hello

I'm trying to roll out a new IPA server for our development environment and 
have nicely automated the server installation process with Ansible but when 
I've come to rolling out the clients I'm hitting this problem.

When running ipa-client-install:
ipa-client-install -N --fixed-primary --server server.domain.local --realm 
DOMAIN.LOCAL --domain DOMAIN.local --principal admin --password 'adminpassword' 
-U

I recommend against use of .local TLD for an IPA installation. The .local addresses are reserved for link-local networks, mDNS and zeroconf. Host lookups for .local behave differently and may result in surprising behavior.

Instead use one of the recommended TLDs from https://www.rfc-editor.org/rfc/rfc6762#appendix-G or https://www.rfc-editor.org/rfc/rfc2606.html .

Christian

--
Christian Heimes
Principal Software Engineer, Identity Management and Platform Security

Red Hat GmbH, https://de.redhat.com/ , Registered seat: Grasbrunn,
Commercial register: Amtsgericht Muenchen, HRB 153243,
Managing Directors: Charles Cachera, Brian Klemm, Laurie Krebs, Michael O'Neill
--
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to