[Freeipa-users] DNS questions

Christoph Kaminski christoph.kaminski at biotronik.com
Sat Apr 11 10:08:56 UTC 2015


Hi all,

have some questions about DNS in IPA...

first some info to our DNS structure:

we have 4 internale domains and a lot of subdomains, for example:

domain:
ourdom.int

subdomains:
 - mgmt.ourdom.int
 - io.ourdom.int
 - app.ourdom.int

etc

Questions:

1. How we should build the zones in ipa? should each subdomain get a zone? 
I see I can make only one zone for the domain and put there the subdomain 
records to (like myhost.mgmt then it resolvs as myhost.mgmt.ourdom.int) 
What is the right way for this? Is there a difference between the ways?

(we got problems with IPA 4.1 to load the zones for domains because our 
IPA server are 'inside' the mgmt subdomain. It was necessary to put a A 
record for the IPA servers into the domain. Example: ipa1.mgmt . Without 
this record the resolving for subdomains has worked but not for the 
domains... With IPA 3.3.3 we didnt have this problem)

2. We have 8 IPA Server here (because all our domains are blackboxes, the 
hosts can communicate only with 2 IPA servers inside the blackbox, IPA 
server can connect each other over a special out of band network). What 
should be inside the NS record of each domain? All IPA servers (the hosts 
inside the blackbox can reach only 2) or only the 2 reachable?

TiA for the answers!

Greetz
Christoph Kaminski

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20150411/9241247f/attachment.htm>


More information about the Freeipa-users mailing list