Chapter 31. Uninstalling the integrated IdM DNS service from an IdM server
If your Identity Management (IdM) deployment includes multiple servers with integrated DNS, you might choose to remove the DNS service from one of them. While it is possible to add the DNS role to an IdM server using the ipa-dns-install command, IdM does not support removing the DNS role independently as the command does not have an --uninstall option.
This limitation applies to all IdM server roles, that is CA server, KRA server, AD trust agent, and AD trust controller. To remove any of these roles, you must fully decommission the replica and then reinstall it, this time without the unwanted role — for example, without integrated DNS.
Prerequisites
- You have integrated DNS installed on an IdM server.
- This is not the last integrated DNS service in your IdM topology.
Procedure
- Identify the redundant DNS service and follow the procedure in Uninstalling an IdM server on the IdM replica that hosts this service.
- On the same host, follow the procedure in either Without integrated DNS, with an integrated CA as the root CA or Without integrated DNS, with an external CA as the root CA, depending on your use case.