[Freeipa-users] Replacing the "master"

Steven Jones Steven.Jones at vuw.ac.nz
Tue Sep 8 20:43:23 UTC 2015


as below,

regards

Steven


8><----

But overall, there is a decent HOWTO on the migration on these pages:

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/migrating-ipa-proc.html

8><----

fraid not, tried it.

============== 

 [root at vuwunicoipam004 thing]# ipa-replica-install --setup-ca --ip-address=10.100.32.53 --setup-dns --forwarder=10.100.32.31 -U replica-info-vuwunicoipam004.xxxxxxxxx.gpg Checking forwarders, please wait ... WARNING: DNS forwarder 10.100.32.31 does not return DNSSEC signatures in answers Please fix forwarder configuration to enable DNSSEC support. (For BIND 9 add directive "dnssec-enable yes;" to "options {}") WARNING: DNSSEC validation will be disabled Directory Manager (existing master) password: 

CA cannot be installed in CA-less setup. 
[root at vuwunicoipam004 thing]# ======













More information about the Freeipa-users mailing list