[Freeipa-users] Re: Freel IPA on CentOS CA_UNREACHABLE Error - kerberos

2024-05-20 Thread Rob Crittenden via FreeIPA-users
girish f via FreeIPA-users wrote: > We have one new customer, they have setup of one single node of IPA on CentOS. > > There certificate is expired, and everthing went down. > > When we are trying to bring services up. > > pki_tomcatd is not starting, another thing is > > When we run command >

[Freeipa-users] Re: Questions about replica

2024-05-20 Thread Rob Crittenden via FreeIPA-users
Dmitry Krasov via FreeIPA-users wrote: > If I will change line in sssd.conf file to "ipa_server = ipa_server = _srv_, > ipa.dom.loc" on existent enrolled clients. Will they work fine with failover? You duplicated ipa_server = but otherwise yes. You can have the _srv_ last if you want to point t

[Freeipa-users] Re: update clients dns records

2024-05-20 Thread Rob Crittenden via FreeIPA-users
Dmitry Krasov via FreeIPA-users wrote: > Hello. > How can I update clients dns records automatically, without setup of DHCP > server? That question doesn't have a lot to go on but I guess I'd recommend starting with the ipa-client-install(1) man page and the --enable-dns-updates option. This enab

[Freeipa-users] Re: Reinitializing isolated replica with updated certificate

2024-05-20 Thread William Faulk via FreeIPA-users
Well, I performed a reinitialization of that server. It continues to use the new certificates that aren't reflected in the LDAP database, but that doesn't seem to cause any active problems, and the replication issue was resolved. -- ___ FreeIPA-users ma

[Freeipa-users] Re: update clients dns records

2024-05-20 Thread Dmitry Krasov via FreeIPA-users
all hosts already enrolled with --enable-dns-updates option but it still doesn't work -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Cond