[Freeipa-users] Question about dogtag integration

Loris Santamaria loris at lgs.com.ve
Fri Oct 29 16:17:45 UTC 2010


Hi all

while trying the latest nightly build of IPAv2 I noticed the integrated
certification authority is installed in a second 389DS instance, so a
full IPAv2 server would have (at least) two 389DS instances running. 

Why is it installed that way, instead of simply adding another suffix in
the main instance? Using an alternative suffix in the main instance
would consume less memory, would be a service less to monitor, and IMHO
a cleaner design having only one ldap server in the system answering all
possible queries.


-- 
Loris Santamaria   linux user #70506   xmpp:loris at lgs.com.ve
Links Global Services, C.A.            http://www.lgs.com.ve
Tel: 0286 952.06.87  Cel: 0414 095.00.10  sip:103 at lgs.com.ve
------------------------------------------------------------
-O9 -omg-optimize -fomit-instructions




More information about the Freeipa-users mailing list