#3268 Document various DNS scenarios related to AD trusts
Closed: Invalid None Opened 10 years ago by pspacek.

This bug is for documentation related to #3261. Various scenarios will be added to bug comments.


Replying to attachment 3268.v2:

Petr, what is the recommended way to tell the IPA server about the DNS
server of its super-domain? I think in the IPA documentation the only
way that is mentioned is the --forwarder option of ipa-server-install.
But with your comments about about forwarders I guess there is a better
way?

It is not necessary declare parent zone explicitly. Each zone should be reachable from DNS root, because each DNS server have built-in list of root servers. Each resolver can start from the root and find any other node in the DNS tree.

In case of "split horizon DNS" server on corporate boundary should return different answers to queries comming from inside and outside of corporate network (via DNS views or so).

FreeIPA project no longer actively maintains an upstream guide (see details). This ticket is already cloned to RHEL downstream guide so the issue should fixed at least there. Closing the upstream ticket.

Metadata Update from @pspacek:
- Issue assigned to elladeon
- Issue set to the milestone: FreeIPA 3.x Documentation

6 years ago

Login to comment on this ticket.

Metadata