这个系列是笔者在为实验室搭建本地私有云的过程中所记载的笔记,看起来会比较杂乱 :)
为了保证FreeIPA服务的稳定性,我们需要为它添加一个replica作为主从备份.
Centos7 安装 FreeIPA Replica
centos7 + 4vCPU + 4G
Profile
- ip: 192.168.128.122/22
- hostname: ipa02.sonnyhcl.top
- kerberos realm: SONNYHCL.TOP
- dns domain: sonnyhcl.top
- admin server: ipa.sonnyhcl.top
- with DNS: yes
- forwarder: 127.0.0.1, 202.120.224.6, 202.120.224.26
安装步骤
设置 ipa02 的 DNS 记录
1 2 3 4
| 选择: 网络服务 -> DNS 区域 添加一个 192.168.128.0/22 的反向区域 128.168.192.in-addr.arpa. 点击 DNS 区域的 sonnyhcl.top. 进去这个子域内 增加一条 ipa02.sonnyhcl.top 的 A 记录,并且在 Create reverse 打勾,添加 IP 地址的反向记录
|
配置机器名 hostname
1 2
| sudo hostnamectl set-hostname ipa02.sonnyhcl.top
|
验证域名解析
配置 ipa02 dns 为 192.168.128.121 然后验证正反解
1 2
| dig +short ipa02.sonnyhcl.top A dig +short -x 192.168.128.122
|
配置 /etc/hosts
1 2
| echo "192.168.128.121 ipa.sonnyhcl.top ipa" | sudo tee -a /etc/hosts echo "192.168.128.122 ipa02.sonnyhcl.top ipa02" | sudo tee -a /etc/hosts
|
安装 FreeIPA Client
1 2
| - -- -- ---- -- .. -- . -- . -- ..
|
配置防火墙
1 2 3
| - -- ---,,,,,,, - -- - ---
|
安装 FreeIPA Replica
1 2
| sudo yum install ipa-server ipa-server-dns sudo ipa-replica-install
|
安装 FreeIPA CA Replica
安装 FreeIPA DNS Replica
检查所有服务运行状态
1 2 3 4 5 6 7 8 9 10 11
| Directory Service: RUNNING krb5kdc Service: RUNNING kadmin Service: RUNNING named Service: RUNNING httpd Service: RUNNING ipa-custodia Service: RUNNING ntpd Service: RUNNING pki-tomcatd Service: RUNNING ipa-otpd Service: RUNNING ipa-dnskeysyncd Service: RUNNING ipa: INFO: The ipactl command was successful
|
参考链接