Ticket #754 added a support for SSH public keys and also an ability to automatically update client machine ssh keys during ipa-client-install.
ipa-client-install
However, if you update FreeIPA server with DNS support, it won't update the DNS zone update policy for current zones. Thus, only A and AAAA record updates are allowed and ipa-client-install always fails to update SSHFP records in such zones.
It works on the new install but fails on upgrade.
Note for myself: we need to create a "how to test" procedure, its not that straightforward.
#1211 (on review) contains a plugin for dnszone modifications, we can reuse that one.
attachment freeipa-mkosek-224-add-sshfp-update-policy-for-existing-zones.patch
Patch freeipa-mkosek-224-add-sshfp-update-policy-for-existing-zones.patch sent for review
master: 7fe63f8[[BR]] ipa-2-2: e0dae21
Metadata Update from @mkosek: - Issue assigned to mkosek - Issue set to the milestone: FreeIPA 2.2 Core Effort - 2012/02
Login to comment on this ticket.