Hi FreeIPA users,

I nested this under a related topic before (subject: Replica
re-initialization failing Replication bind with GSSAPI auth failed: LDAP
error 49 (Invalid credentials) () ) but it was admittedly a bit off topic...

Is configuring resolv.conf with the single resolver 127.0.0.1 the blessed /
recommended setup?
We've had some chicken and egg situations recently where dirsrv being sad
has broken local DNS resolution, and then krb behaviours and lookup for the
other IPA servers has been impaired as a result.

If solely using local bind / loopback in resolv.conf is the recommended
state, should we be putting the other IPA servers in /etc/hosts or anything
to make sure they can identify one and other in the case of dirsrv sadness?

Thanks in advance,

David
--
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to