29.11. Using Ansible to install an IdM replica configured to use eDNS


Learn how to use Ansible to install an IdM replica with eDNS in an environment where the IdM server has DoT enabled.

When you install the replica with the integrated DNS service, the replica uses the same configuration as the IdM server. It runs BIND to handle incoming DNS queries, including encrypted queries, and uses unbound for outgoing encrypted DNS traffic.

When you install the replica without the integrated DNS service, the replica inherits the client-side configuration. It uses unbound with a DoT forwarder to send encrypted DNS queries to the IdM DNS server.

Prerequisites

  • You are using Ansible version 2.15 or later.
  • You have installed the ansible-freeipa package.
  • The example assumes that the secret.yml Ansible vault stores your ipaadmin_password and that you have access to a file that stores the password protecting the secret.yml file.

Procedure

  1. On the controller, create a playbook named install-replica-edns.yml that includes a task to install an IdM replica with eDNS enabled:

    ---
    - name: Playbook to configure an IdM replica with eDNS enabled
      hosts: ipareplicas
      become: true
      vars_files:
      - /home/user_name/MyPlaybooks/secret.yml
      vars:
        ipaadmin_password: "{{ ipaadmin_password }}"
        ipareplica_domain=idm.example.com
        ipareplica_dns_over_tls=true
    
      roles:
      - role: freeipa.ansible_freeipa.ipareplica

    If DNSSEC validation is turned off on the IdM server that the replica is communicating with, you must also disable it on the replica by setting ipaclient_no_dnssec_validation = true in the vars section of the playbook. Otherwise, DNS over TLS will not function correctly for the replica.

    To install integrated IdM DNS on the IdM replica, add ipareplica_setup_dns=true and ipareplica_dot_forwarders="<server_ip>#<dns_server_hostname>" to the list of variables.

  2. Run the Ansible playbook:

    $ ansible-playbook --vault-password-file=password_file -v -i ~/MyPlaybooks/inventory ~/MyPlaybooks/install-replica-edns.yml

Verification

  • On the IdM server, list all replicas in the topology:

    # ipa-replica-manage list-ruv
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

关于红帽文档

Legal Notice

Theme

© 2026 Red Hat
返回顶部