29.6. Configuring an existing IdM DNS server to use eDNS
You can enable DNS-over-TLS (DoT) on an existing Identity Management (IdM) server by reconfiguring the integrated DNS service. Use the ipa-dns-install utility with DoT-specific options to update the DNS configuration without reinstalling the server.
Prerequisites
- You have root access to the IdM server.
- DNS is already installed on the IdM server.
Procedure
Optional: Verify that your IdM server uses integrated DNS:
$ ipa server-role-find --role 'DNS server' --------------------- 1 server role matched --------------------- Server name: server.idm.example.com Role name: DNS server Role status: enabled ---------------------------- Number of entries returned 1 ----------------------------Install the
ipa-server-encrypted-dnspackage on your IdM server:# dnf install ipa-server-encrypted-dnsUpdate the integrated DNS service to enable DoT and configure DoT policy and forwarders:
# ipa-dns-install --dns-over-tls --dot-forwarder "<server_ip>#<dns_server_hostname>" --dns-policy enforced -UFor a complete list of options see the
ipa-dns-install(1)man page on your system.Add the
dns-over-tlsservice to the systemfirewallto open port 853/TCP for DoT traffic:# firewall-cmd --add-service=dns-over-tls
Verification
Verify that the firewall allows DoT traffic:
# firewall-cmd --list-services