#2394 Add SSHFP update policy for existing zones
Closed: Fixed None Opened 12 years ago by mkosek.

Ticket #754 added a support for SSH public keys and also an ability to automatically update client machine ssh keys during ipa-client-install.

However, if you update FreeIPA server with DNS support, it won't update the DNS zone update policy for current zones. Thus, only A and AAAA record updates are allowed and ipa-client-install always fails to update SSHFP records in such zones.


It works on the new install but fails on upgrade.

Note for myself: we need to create a "how to test" procedure, its not that straightforward.

#1211 (on review) contains a plugin for dnszone modifications, we can reuse that one.

Patch freeipa-mkosek-224-add-sshfp-update-policy-for-existing-zones.patch sent for review

Metadata Update from @mkosek:
- Issue assigned to mkosek
- Issue set to the milestone: FreeIPA 2.2 Core Effort - 2012/02

7 years ago

Login to comment on this ticket.

Metadata