Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-78635

[ansible-freeipa] Add support for DNS-over-TLS for ipaclient, ipareplica and ipaserver roles - RHEL-10.1

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.1
    • rhel-10.1
    • ansible-freeipa
    • ansible-freeipa-1.15.0-1.el10
    • None
    • 1
    • rhel-idm-zta
    • ssg_idm
    • 21
    • 2
    • Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • IPA: RHELs Waiting for a BUILD
    • Technology Preview
    • None

      The ansible-freeipa PR https://github.com/freeipa/ansible-freeipa/pull/1340 provided a hotfix for client, replica and server deployments with FreeIPA PR https://github.com/freeipa/freeipa/pull/7343 applied.

      This ticket is about enabling the configuration of DNS-over-TLS.

       

      Command line installer options that need to be added:

      ipa-server-install/ipa-replica-install

          --dns-over-tls      Configure DNS over TLS

          --dot-forwarder=DOT_FORWARDERS
                              Add a DNS over TLS forwarder. This option can be used
                              multiple times
          --dns-over-tls-cert=DNS_OVER_TLS_CERT
                              Certificate to use for DNS over TLS. If empty, a new
                              certificate will be requested from IPA CA
          --dns-over-tls-key=DNS_OVER_TLS_KEY
                              Key for certificate specified in --dns-over-tls-cert
          --dns-policy={relaxed,enforced}
                              Encrypted DNS policy

      ipa-client-install

          --dns-over-tls      Configure DNS over TLS

              twoerner Thomas Woerner
              twoerner Thomas Woerner
              Thomas Woerner Thomas Woerner
              Varun Mylaraiah Varun Mylaraiah
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: