[Freeipa-devel] Should we stop supporting realm != upper(domain) installations?

Christian Heimes cheimes at redhat.com
Fri May 6 13:55:02 UTC 2016


On 2016-05-06 15:50, Martin Babinsky wrote:
> On 05/06/2016 03:43 PM, Petr Spacek wrote:
>> Hello,
>>
>> I wonder if we should stop supporting new installations where
>> Kerberos realm != uppercase(primary DNS domain).
>>
>> It breaks a lot of stuff, is harder to manager and docs are full of
>> warnings
>> discouraging it anyway.
>>
>> Do we really need to support it for new installs?
>>
> 
> Since many people using such setup are bound to shoot themselves in the
> foot at some point I would argue for dropping support for this.
> 
> I even fail to see the use case for having realm different that domain
> name.

+1

We could consider a --force option to skip the check and allow people to
shoot themselves in the knee.

Christian


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 455 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20160506/43c1f8d7/attachment.sig>


More information about the Freeipa-devel mailing list