<div dir="ltr"><ul style="margin:0px;list-style-type:circle;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;line-height:25.2000007629395px;vertical-align:baseline;color:rgb(26,26,26);font-family:'Open Sans','liberation sans','Myriad ','Bitstream Vera Sans','Lucida Grande','Luxi Sans',helvetica,verdana,arial,sans-serif"><li class="" style="margin:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;padding:0px;vertical-align:baseline"><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline"><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline">Hi all.</div><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline">I've got a rather big domain environment with 10 distributed locations, and I'm considering using FreeIPA as an id manager for linux users and servers, alongside with existing AD, using trusts. In every location, there are 2 DCs for windows environment, and I'm thinking about deployment of 2 freeIPA servers for each location, with replicas. This document states that I can't use more than 20 servers per IPA domain: <a href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/Setting_up_IPA_Replicas.html#replica-topologies">https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/Setting_up_IPA_Replicas.html#replica-topologies</a> </div></div></li><li class="" style="margin:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;padding:0px;vertical-align:baseline"><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline"><span style="font-size:15.3999996185303px;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit">"No more than 20 servers and replicas should be involved in a single Identity Management domain."</span></div></li><li class="" style="margin:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;padding:0px;vertical-align:baseline"><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline"><span style="font-size:15.3999996185303px;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit">How strict is this restriction? Is there any way I can deploy freeIPA in this situation, assuming that number of locations would increace over time? Is there any other limitations to integrate freeIPA in AD?</span></div></li><li class="" style="margin:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;padding:0px;vertical-align:baseline"><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline"><span style="font-size:15.3999996185303px;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit">Thank you.</span></div></li><li class="" style="margin:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;padding:0px;vertical-align:baseline"><div class="" style="margin:0px 0px 1.8em;padding:0px;border:0px none;font-size:15.3999996185303px;font-stretch:inherit;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit;vertical-align:baseline"><span style="font-size:15.3999996185303px;font-style:inherit;font-variant:inherit;font-weight:inherit;line-height:inherit">(sorry for poor english :)</span></div></li></ul>
</div>