Este conteúdo não está disponível no idioma selecionado.
Chapter 5. Checking DNS records by using IdM Healthcheck
You can identify issues with DNS records in Identity Management (IdM) by using the Healthcheck tool. For general information about the tool, see Healthcheck in IdM.
5.1. DNS records healthcheck test Copiar o linkLink copiado para a área de transferência!
The Healthcheck tool includes the IPADNSSystemRecordsCheck test for checking that the expected DNS records required for autodiscovery are resolvable.
Specifically, the test checks the DNS records obtained by the ipa dns-update-system-records --dry-run command by using the first resolver specified in the /etc/resolv.conf file on the IdM server to which you are logged in.
You can find the IPADNSSystemRecordsCheck test under the ipahealthcheck.ipa.idns source of the output of the ipa-healthcheck --list-sources command.
5.2. Screening IdM DNS records by using the Healthcheck tool Copiar o linkLink copiado para a área de transferência!
You can run a standalone manual test to check DNS records on an Identity Management (IdM) server by using the Healthcheck tool.
The Healthcheck tool includes many tests. Results can be narrowed down by including only the DNS records tests by adding the --source ipahealthcheck.ipa.idns option.
Prerequisites
-
You have
rootprivileges.
Procedure
To run the DNS records test, enter:
# ipa-healthcheck --source ipahealthcheck.ipa.idnsThe
--source ipahealthcheck.ipa.idnsoption ensures that IdM Healthcheck only performs the DNS records test.If the record is resolvable, the test returns
SUCCESSas a result:{ "source": "ipahealthcheck.ipa.idns", "check": "IPADNSSystemRecordsCheck", "result": "SUCCESS", "uuid": "eb7a3b68-f6b2-4631-af01-798cac0eb018", "when": "20200415143339Z", "duration": "0.210471", "kw": { "key": "_ldap._tcp.idm.example.com.:server1.idm.example.com." } }The test returns a
WARNINGwhen, for example, the number of records does not match the expected number:
{ "source": "ipahealthcheck.ipa.idns", "check": "IPADNSSystemRecordsCheck", "result": "WARNING", "uuid": "972b7782-1616-48e0-bd5c-49a80c257895", "when": "20200409100614Z", "duration": "0.203049", "kw": { "msg": "Got {count} ipa-ca A records, expected {expected}", "count": 2, "expected": 1 } }