[Freeipa-users] ipa server(master) and alternative name

lejeczek peljasz at yahoo.co.uk
Wed Jul 6 10:24:40 UTC 2016


hi users,

I'd like to ask if it possible to add (after deployment is 
finished) an AltSubjectName to fIPA master?

I shall say what I'm hoping to achieve - having 3 servers I 
hope to have in IPA's DNS a host, A record that will be 
resolving to three server's IPs. Like eg. ipa-ca which seems 
to hold all servers IPs.

I started with:

$ ipa dnsrecord-add private.my.dom.priv linux --a-ip-address 
10.5.6.100(which is master's IP)

but I feel I got of the wrong foot there, I see with ipa 
command:

ipa: ERROR: cert validation failed for...

((SEC_ERROR_UNTRUSTED_ISSUER) Peer's certificate issuer has 
been marked as not trusted by the user.)

can this be done?

many thanks,

L




More information about the Freeipa-users mailing list