这个系列是笔者在为实验室搭建本地私有云的过程中所记载的笔记,看起来会比较杂乱 :)
为了保证FreeIPA服务的稳定性,我们需要为它添加一个replica作为主从备份.
Centos7 安装 FreeIPA Replica
centos7 + 4vCPU + 4G
Profile
-  ip: 192.168.128.122/22
 
-  hostname: ipa02.sonnyhcl.top
 
-  kerberos realm: SONNYHCL.TOP
 
-  dns domain: sonnyhcl.top
 
-  admin server: ipa.sonnyhcl.top
 
-  with DNS: yes
 
-  forwarder: 127.0.0.1, 202.120.224.6, 202.120.224.26
 
安装步骤
设置 ipa02 的 DNS 记录
1 2 3 4
   | 选择: 网络服务 -> DNS 区域 添加一个 192.168.128.0/22 的反向区域 128.168.192.in-addr.arpa. 点击 DNS 区域的 sonnyhcl.top. 进去这个子域内 增加一条 ipa02.sonnyhcl.top 的 A 记录,并且在 Create reverse 打勾,添加 IP 地址的反向记录
   | 
 
配置机器名 hostname
1 2
   | sudo hostnamectl set-hostname ipa02.sonnyhcl.top
 
   | 
 
验证域名解析
配置 ipa02 dns 为 192.168.128.121 然后验证正反解
1 2
   | dig +short ipa02.sonnyhcl.top A dig +short -x 192.168.128.122
   | 
 
配置 /etc/hosts
1 2
   | echo "192.168.128.121 ipa.sonnyhcl.top ipa" | sudo tee -a /etc/hosts echo "192.168.128.122 ipa02.sonnyhcl.top ipa02" | sudo tee -a /etc/hosts
   | 
 
安装 FreeIPA Client
1 2
   |    -  -- -- ---- -- .. -- . -- . -- ..
   | 
 
配置防火墙
1 2 3
   |  - -- ---,,,,,,,  - --  - ---
   | 
 
安装 FreeIPA Replica
1 2
   | sudo yum install ipa-server ipa-server-dns sudo ipa-replica-install
   | 
 
安装 FreeIPA CA Replica
安装 FreeIPA DNS Replica
检查所有服务运行状态
1 2 3 4 5 6 7 8 9 10 11
   | Directory Service: RUNNING krb5kdc Service: RUNNING kadmin Service: RUNNING named Service: RUNNING httpd Service: RUNNING ipa-custodia Service: RUNNING ntpd Service: RUNNING pki-tomcatd Service: RUNNING ipa-otpd Service: RUNNING ipa-dnskeysyncd Service: RUNNING ipa: INFO: The ipactl command was successful
   | 
 
参考链接