[Freeipa-users] In master/replica DNS -- can 'notifies' be disabled?

2021-08-27 Thread Harry G. Coin via FreeIPA-users
Does the 'sending notifies' feature bind offers between a freeipa master and replica serve any purpose whatever assuming there are no other dns servers involved in the freeipa dns managed zones? I'd like to put an option in the ext to turn off notifies, but I do want the SOA serial numbers to matc

[Freeipa-users] Debugging hint re: replica 'rndc sign' fail -> ipa-dnskeysyncd fail

2021-08-27 Thread Harry G. Coin via FreeIPA-users
I was going to ask for help for a very perplexing problem.  The symptoms seemed to have very little to do with the solution, so searching online led nowhere.  Hopefully, by posting this the next person to hit this will find this answer. In short, the answer is, on the replica: dsconf -D "cn=Direc

[Freeipa-users] Re: ipa-healthcheck - ipahealthcheck.ds.replication.ReplicationConflictCheck.idnsname Replication conflict

2021-08-27 Thread Kathy Zhu via FreeIPA-users
Hi Rob, After deleted those hidden records inside the zones, I deleted those zones smoothly. Remember 1.1.10.in-addr.arpa.zone which was marked with glue=true? There was one hidden ptr record inside the zone. After that record being deleted, 1.1.10.in-addr.arpa.zone disappread itself :-). Thank yo

[Freeipa-users] Re: ipa-healthcheck - ipahealthcheck.ds.replication.ReplicationConflictCheck.idnsname Replication conflict

2021-08-27 Thread Rob Crittenden via FreeIPA-users
Kathy Zhu wrote: > Hi Rob,  > > Thank you! That filter did the trick. There are 9 pTRRecord in the zone! > See attached for details. What is the safe way to delete those "hidden" > records? I assume that the zone can be deleted after those pTRRecord > being deleted first. Many thanks. Use ldapde

[Freeipa-users] Re: ipa-healthcheck - ipahealthcheck.ds.replication.ReplicationConflictCheck.idnsname Replication conflict

2021-08-27 Thread Kathy Zhu via FreeIPA-users
Hi Rob, Thank you! That filter did the trick. There are 9 pTRRecord in the zone! See attached for details. What is the safe way to delete those "hidden" records? I assume that the zone can be deleted after those pTRRecord being deleted first. Many thanks. Kathy. [root@ipa0 ~]$ ldapsearch -Y GSSA

[Freeipa-users] Re: ipa-healthcheck - ipahealthcheck.ds.replication.ReplicationConflictCheck.idnsname Replication conflict

2021-08-27 Thread Rob Crittenden via FreeIPA-users
Kathy Zhu wrote: > Hi Rob,  > > There are 5 more reverse zones which can not be deleted as well. IPA > said "Not allowed on non-leaf entry". Though that is the same complaint, > however, there are no "glue, extensibleobject" objectclasses associated > with those 5 zones. Please see attached for de

[Freeipa-users] Re: Cannot add externally-signed IPA CA certificate

2021-08-27 Thread Ravindra Kumar via FreeIPA-users
Can you share the commands you followed. I am facing the same issues ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://docs.