#2008 [RFE] IPA should support and manage DNS Locations
Closed: Fixed Opened by dpal.

https://bugzilla.redhat.com/show_bug.cgi?id=747612

It is related to bug #743503 but to mange the site on the server side.
The original request is the following:
Has there been given any thought to the concept of sites within IPA to improve
cross-site implementations? This should be easy to implement as you are already
using DNS SRV records to locate the ldap/kerberos servers.
E.g.
Site: Boston
Site: London
Create a subdomain of the IPA dns domain named _sites, and a subdomain of
_sites for each site.
Boston._sites.ipa.domain.com would contain the srv entries for IPA servers in
Boston:
_ldap._tcp        in    srv    0 100 389 boston-ipa-server1
_ldap._tcp        in    srv    0 100 389 boston-ipa-server2
.....
London._sites.ipa.domain.com would contain the srv entries for IPA serers in
London:
_ldap._tcp        in    srv    0 100 389 london-ipa-server1
_ldap._tcp        in    srv    0 100 389 london-ipa-server2
....
Now point the client's DNS "search" entry to point to the local site first,
then search the full name space:
Boston client's /etc/resolv.conf:
search Boston._sites.ipa.domain.com ipa.domain.com
London client's /etc/resolv.conf:
search London._sites.ipa.domain.com ipa.domain.com
The main ipa.domain.com could still contain srv records for all IPA servers, or
selected IPA servers at the central hub.
I know I can do this manually within the DNS managment in IPA today, however it
would be a lot easier to maintain "Sites" within the IPA webui/cli. *blink* ;)

Start when have time.

This work should be done following this plan:
http://freeipa.org/page/DNS_Location_Discovery

Linked to Bugzilla bug: https://bugzilla.redhat.com/show_bug.cgi?id=815621 (Red Hat Enterprise Linux 6)

Based on the feedback in the BZ this is pretty important so I am bumping the priority.

BZ 815621 is another RFE, it will be cloned to another ticket.

Putting back in needs triage as it seems like it belongs in 3.3 backlog.

Older design document (http://freeipa.org/page/DNS_Location_Discovery) was obsoleted by the new one: http://www.freeipa.org/page/V3/DNS_Location_Mechanism

Stretch goal for 4.2. The first pass would require 2 parts to happen:

  • bind-dyndb-ldap to generate the _location records for clients, based on named.conf configuration (upstream ticket)
  • FreeIPA UI - for creating the locations and setting up the priorities of the SRV records. The procedure may be as follows:
    • Create location "Brno"
    • Click "Add servers", select Brno-located servers and add them with priority "10" and weight "100". Click Done
    • Click "Add servers", select New York located servers and add them with priority "50" and weight "100". Click Done.
    • Click "Create location"

Whether this would create DNS records directly or it would create a special location object while DNS records will be pre-populated by DS plugin is implementation detail.

Moving to 4.3, we are too close to 4.2 deadline to be able to handle this stretch RFE.

2008 would be hard to implement without #5620.

4.4 priority

Would be really nice to show the locations on the topology graph in some way. Should we open a separate RFE or it is in scope?

master:

  • 29a8615cf36cd46e30c6048ee7e3993532e83005 DNS Locations: Always create DNS related privileges
  • 180d7458de60af3e9a7256f3242eec9031f4442b DNS Locations: add new attributes and objectclasses
  • bae621415dd15a5569774cbc89ba1747b0d069dc DNS Locations: location-* commands
  • 7c3bcafef094d77df698aa0eba8b02e8892ce1c2 DNS Locations: API tests
  • 121e34b90e890285c480a0c89e833d1369d61401 Allow to use non-Str attributes as keys for members
  • 15abfcf0f77664f426ba50ebf20e0f6c2a6f8275 DNS Locations: extend server-* command with locations
  • 79544aa51acc6f48117391b1e0ec70e9f4d7d0bb DNS Location: location-show: return list of servers in location
  • fd2bd60383a739185a0a67fd0fb43338bab17e1d DNS Locations: when removing location remove it from servers first
  • 42719acdcebd3ef939587d4af4c3c6ad743ec601 DNS Locations: extend tests with server-* commands

User interface added, other patches will follow

master:

  • 85d083c36651b15457af75e009f83bc6bb8114b0 Require 389-ds-base >= 1.3.5.6

master:

  • 0f5cca0e45481520d25b20b48f939b2581f4d27b DNS Locations: add index for ipalocation attribute
  • d7671ee66786b674454b7b58c9558e0c7c853cd5 DNS Locations: fix location-del
  • 745a2e6471b27faabeb5479b9d2845b18606d8b0 DNS Locations: add idnsTemplateObject objectclass
  • 87c23ba029df9227384b3f5e2028f3f0e429e9ab DNS Locations: DNS data management
  • 394b094fc22ef67742824ec03d4e851a2876fd81 DNS Locations: permission: allow to read status of services
  • cf634a4ff8a100589f99e57c51b2c4591853e88a DNS Locations: add ACI for template attribute
  • e23159596e1851f156461d00b9f9f99dc698e12b DNS Locations: command dns-update-system-records
  • 45a93265740fdfc14e6ee8785f844f8d34508fc4 DNS Locations: use dns_update_service_records in installers
  • a5a6ceafcd3418a6242bbf948d825f2b61c95f23 DNS Locations: adtrustinstance simplify dns management
  • a7e463948db5870d264f59954c9a2e9b5b59e1dd DNS Locations: use automatic records update in ipa-adtrust-install
  • 4076e8e4e50d527f613536138cd851cd068cd2d9 DNS Locations: server-mod: add automatic records update
  • 88a0952f26f9d1e2ee9d02126b27f3075dbad46a DNS Locations: dnsservers: add required objectclasses
  • 2157ea0e6d0d762bdc71022ddd55045406c4b300 DNS Locations: dnsserver-* commands
  • 52590d6fa581e3b53e2c9350dc307a1f360c40a3 DNS Locations: dnsserver: put server_id option into named.conf
  • 08265f1e92bd91d9e4ba3285b953ff9ccd79040b DNS Locations: dnsserver: use the newer config way in installer
  • d70e52b61b35f42ca2d34ef05310fd2c18c882ce DNS Locations: dnsserver: remove config when replica is removed

master:

  • ef12cad30b3fc867b3b09abe6521c168dbc3ceaf DNS Locations: set proper substitution variable
  • 1997733cdf60bbd5fee8a5286d567580fa4e0198 DNS Locations: require to restart named-pkcs11 affter location change
  • 8dde1201ed9b0ca839ffe7421be7efd04b666e11 DNS Locations: show warning if there is no DNS servers in location
  • b2931210eb794e52eac4b0e295fcbdfc5bb07f87 DNS Locations: prevent to remove used locations
  • bbf8227e3fd678d4bd6659a12055ba3dbe1c8230 DNS Locations: do not generate location records for unused locations
  • 3c50e42036427d7c5e36828f24bd3c180e18a677 DNS Locations: location-del: remove location record
  • 4155eb7b13b20605886ba79c02c232f83a7b439c DNS Locations: Rename ipalocationweight to ipaserviceweight
  • 313e63e3e4ba1aa3dd2ae5de54f6d277329fffee DNS Locations: generate NTP records
  • 88ac58a1ce0641e65bcc7934020f85ef39d8e82b upgrade: don't fail if zone does not exists in in find
  • e82ce439c4c8a4d2f5b4ef384158de93de1644cc DNS Location: add list of roles and DNS servers to location-show
  • 8253727de1f823bb6c06d4687019e64dab825ec3 DNS Locations: dnsserver: print specific error when DNS is not installed

master:

  • b6bab8d4e0d6f4715ef353b6944c85c5e88d44ab DNS Locations: make ipa-ca record generation more robust

master:

  • 894be1bd50905b86d87244d0ede3f266e9737b9a dns: fix dns_update_system_records to work with thin client

master:

  • 926462d335ea49857732f1cf2fd2a1956c5b57d8 Server-del: fix system records removal

master:

  • c6f7d94d5b39c213483909de34c61016b8eba0ac DNS Locations: server-mod: fix if statement

master:

  • e42f662b78d9a9d9c0ca786e69d7c203e6863462 Revert "DNS Locations: do not generate location records for unused locations"
  • 218734ba5ac3326daaf1097ef98217f6c86f526c DNS Locations: hide option --no-msdcs in adtrust-install
  • 7bf3b1d546f22eeb61dce58cb69d471f834b8aac DNS Locations: optimization: use server-find to get information

master:

  • 104040cf363ec50d8006474422f2c13e44266806 DNS Locations: cleanup of bininstance

Metadata Update from @dpal:
- Issue assigned to mbasti
- Issue set to the milestone: FreeIPA 4.4

Metadata