]> xn--ix-yja.es Git - alex.git/commitdiff
Add FreeIPA setup to nc1
authoralex <alex@pdp7.net>
Sun, 5 Feb 2023 18:55:10 +0000 (19:55 +0100)
committeralex <alex@pdp7.net>
Sun, 5 Feb 2023 18:55:10 +0000 (19:55 +0100)
personal_infra/puppet/modules/freeipa/manifests/server.pp [new file with mode: 0644]
personal_infra/puppet/site/nc1.pdp7.net.pp
personal_infra/setup_ipa_replicas.md [new file with mode: 0644]

diff --git a/personal_infra/puppet/modules/freeipa/manifests/server.pp b/personal_infra/puppet/modules/freeipa/manifests/server.pp
new file mode 100644 (file)
index 0000000..6a96fc9
--- /dev/null
@@ -0,0 +1,3 @@
+class freeipa::server {
+  package {['ipa-server', 'ipa-server-dns']:}
+}
index b314dfc029c05f229e45692d6dcb7bcda073a9bd..e6939c8e200f58d9bdde98d0a743743e34d37aa7 100644 (file)
@@ -1,2 +1,3 @@
 node 'nc1.pdp7.net' {
+  class {'freeipa::server':}
 }
diff --git a/personal_infra/setup_ipa_replicas.md b/personal_infra/setup_ipa_replicas.md
new file mode 100644 (file)
index 0000000..683c956
--- /dev/null
@@ -0,0 +1,7 @@
+Update and reboot all IPA servers
+https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/thread/2WMK5QOAI4TYF23UKODW3M6WB65BJCHT/
+
+firewall-cmd --permanent --add-port={80/tcp,443/tcp,389/tcp,636/tcp,88/tcp,88/udp,464/tcp,464/udp,53/
+firewall-cmd --reload
+ipa-client-install -p principal --domain=ipa.pdp7.net -W  --mkhomedir --ntp-pool=pool.ntp.org --force-join
+ipa-replica-install --ip-address=thishostaddress -n ipa.pdp7.net -P alex --setup-ca --setup-dns --forwarder=upstreamdnsforthishost