29.3. Configuring client and replica systems to use DoT exclusively


To enforce DoT communication, you must configure clients and replica systems to use a DoT-capable resolver. You must update the DNS settings in NetworkManager to enable eDNS communication. This configuration is only required when the --dns-policy is set to enforced.

Prerequisites

Procedure

  1. Copy the IdM server’s DoT certificate to the client and replica system.

    $ scp /etc/pki/tls/certs/bind_dot.crt <username>@<ip>:/etc/pki/ca-trust/source/anchors/
  2. Update the system-wide trust store configuration:

    # update-ca-trust extract
  3. On the client and replica system, install the dnsconfd package:

    # dnf install dnsconfd
  4. Generate the default configuration files for DoT on your system:

    dnsconfd config install
  5. Enable the dnsconfd service:

    # systemctl enable --now dnsconfd
  6. Reload NetworkManager to apply the configuration:

    # nmcli g reload
  7. Configure the system’s DNS settings in NetworkManager.

    # nmcli device modify <device_name> ipv4.dns dns+tls://<idm_server_ip>
    
    Connection successfully reapplied to device '<device_name>'.
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

关于红帽文档

通过我们的产品和服务,以及可以信赖的内容,帮助红帽用户创新并实现他们的目标。 了解我们当前的更新.

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

Theme

© 2026 Red Hat
返回顶部