In a 'standard' freeipa setup with two freeipa masters that provide authoritative DNS for a zone (in this instance using the named-pkcs11 bind version) and no other DNS slaves:

When an IP address is changed in freeipa DNS for a host:

Question 1:  Does the 'notify' feature of bind9/named from one machine to the other accomplish any actual value (TTL related or otherwise) given they both rely on bind-dyndbldap and as such the dns change is migrated via ldap?   In other words, would any performance suffer if I just turned off notifies among the freeipa masters?

Question 2:  What is the sequence of operations when an IP address is changed in freeipa?  I expect it would be the first ldap db gets updated, then the replicas ldap dbs get updated, then after all ldaps are updated each of them tells 'their respective' bind instances to update.  Yes?  No?

Thanks!

Harry Coin


_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to