Support for REALM != primary DNS domain is problematic. Given that AD is enforing REALM == DNS domain I think we can do the same and simplify things.
Problems:
For all these reasons I would forbid new installations with REALM != primary DNS domain. IMHO it will reduce support costs in long term.
This is one of the claimed differentiators. I am not sure we should remove this functionality. IMO we should warn of the implications rather than disable it completely.
See also #6039
Metadata Update from @pspacek: - Issue assigned to someone - Issue set to the milestone: FreeIPA 4.5 backlog
Thank you taking time to submit this request for FreeIPA. Unfortunately this bug was not given priority and the team lacks the capacity to work on it at this time.
Given that we are unable to fulfil this request I am closing the issue as wontfix. To request re-consideration of this decision please reopen this issue and provide additional technical details about its importance to you.
Metadata Update from @rcritten: - Issue close_status updated to: wontfix - Issue status updated to: Closed (was: Open)
Login to comment on this ticket.