[Freeipa-users] FreeIPA replica topologies

James purpleidea at gmail.com
Thu Jul 3 06:10:27 UTC 2014


Hi there,

Is the following correct or incorrect?

Say I want to build a triangle of ipa replicas. A <-> B <-> C <-> (back to A)

I do ipa-server-install on A
I do ipa-replica-prepare on A ... transfer files to B
I do ipa-replica-install on B
then:

Option ONE:
I do ipa-replica-prepare on B ... transfer files to C

Option TWO:
I do ipa-replica-prepare on A ... transfer files to C

Continuing on...
I do ipa-replica-install on C

Since all three hosts are now installed, to close the loop, I do :

Option ONE:
ipa-replica-manage connect C A

Option TWO:
ipa-replica-manage connect B C

Is this all correct? Is option ONE or option TWO preferable and why?
Is the closing of the loop the correct interpretation and method?
Can the "closing of the loop" be done from any host in the cluster ?
If there's a large cluster can it be done from someone not directly
connected to the two peers we want to connect?

Thanks again!
James

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20140703/030174a7/attachment.sig>


More information about the Freeipa-users mailing list