Thanks you for all informations.


Karim Bourenane +33686464439
+32475753687

Le mar. 11 juin 2019 à 15:33, John Keates <j...@keates.nl> a écrit :

> IPA als already highly available, from the service side using DNS and
> multiple records for all services, on the web side: every server has a
> working web interface.
> If you want to redirect users to any working interface, a generic load
> balancer without keepalive works, redirect them to the IP and the IPA
> server will take care of redirecting to HTTPS and the domain name.
> No need to do anything yourself.
>
> John
>
> On 11 Jun 2019, at 14:54, Karim Bourenane via FreeIPA-users <
> freeipa-users@lists.fedorahosted.org> wrote:
>
> Thanks François, for your reply.
>
> The goal, is to have the service IPA available always, if the server 1
> will be down, and also for load sharing.
>
> I thought about roundrobin dns, but sharing service is not mastered for
> effective sharing and the life test is not present.
>
> Bien à vous
>
> Mr Karim Bourenane
> +33686464439
> +32493866354
>
>
>
> Le mar. 11 juin 2019 à 14:03, François Cami <fc...@redhat.com> a écrit :
>
>> Hi Karim,
>>
>> On Tue, Jun 11, 2019 at 1:56 PM Karim Bourenane via FreeIPA-users
>> <freeipa-users@lists.fedorahosted.org> wrote:
>> >
>> > Hello team
>> >
>> > Hope you are well.
>> >
>> > After an existing installation, we decide to implement a Haproxy +
>> Keepalive in all our IPA's servers.
>> >
>> > The haproxy / keepalive work weel but now the IPA doent run weel,
>> because he want to listen on all interface in the servers.
>> >
>> > Ho i can to modify the IPA (+ all modules KRB5/DNS...) conf server, to
>> bind only in  1 local interface and not to the VIP interface ?
>>
>> Binding to the local interface is in no way expected and will result
>> in some components not working.
>>
>> I am not aware of any scenario where adding HAProxy+Keepalived in
>> front of FreeIPA would provide a tangible benefit. Could you please
>> explain the reasoning behind such a decision?
>>
>> Regards,
>> François
>>
>> > King regard
>> > _______________________________________________
>> > FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
>> > To unsubscribe send an email to
>> freeipa-users-le...@lists.fedorahosted.org
>> > Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
>> > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
>> > List Archives:
>> https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
>>
> _______________________________________________
> FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
> Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
>
>
>
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org

Reply via email to