29.10. Using Ansible to install an IdM client configured to use eDNS


You can use Ansible to install an IdM client with DNS-over-TLS (DoT) enabled. The example below applies the enforced DoT policy and requires the client to use eDNS queries exclusively.

Prerequisites

  • You are using Ansible version 2.15 or later.
  • You have installed the ansible-freeipa package.
  • The example assumes that the secret.yml Ansible vault stores your ipaadmin_password and that you have access to a file that stores the password protecting the secret.yml file.
  • You have configured the resolver for DNS over TLS on the client.

Procedure

  1. On the controller, create a playbook named install-client-edns.yml that includes a task to install an IdM client with eDNS enabled:

    ---
    - name: Playbook to configure an IdM client with eDNS enabled
      hosts: ipaclients
      become: true
      vars_files:
      - /home/user_name/MyPlaybooks/secret.yml
      vars:
        ipaadmin_password: "{{ ipaadmin_password }}"
        ipaclient_domain=idm.example.com
        ipaclient_dns_over_tls=true
    
      roles:
      - role: freeipa.ansible_freeipa.ipaclient

    If DNSSEC validation is turned off on the IdM server that the client is communicating with, you must also disable it on the client by setting ipaclient_no_dnssec_validation = true in the vars section of the playbook. Otherwise, DNS over TLS will not function correctly for the client.

  2. Run the Ansible playbook:

    $ ansible-playbook --vault-password-file=password_file -v -i ~/MyPlaybooks/inventory ~/MyPlaybooks/install-client-edns.yml

Verification

  1. On the IdM client, review /etc/unbound/unbound.conf:

    $ cat /etc/unbound/unbound.conf
  2. Verify that the configuration contains the IP address and host name of the IdM server.

Troubleshooting

  1. On the IdM client, run a DNS query to trigger traffic:

    $ dig <domain_name>
  2. Review the logs on the IdM server to verify that the query was routed through DoT.
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

关于红帽文档

Legal Notice

Theme

© 2026 Red Hat
返回顶部