It is possible to perform an ipa-client-install which results in a SASL Bind Failure due to reverse dns failing for the FreeIPA server.
I would like to request that a simple fwd/rev dns check be added to the client to simplify troubleshooting when faced with a condition like this.
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=798364
attachment freeipa-jraquino-0041-During-ipa-client-install-verify-forward-and-reve.patch
Ah great. A feature request has already been created.
Rename component.
Removing on_review flag as the patch is now stale, obsoleted.
removing assign status due to 2+ years inactivity
Metadata Update from @jraquino: - Issue assigned to someone - Issue set to the milestone: Ticket Backlog
The link to the patch jraquino posted appears to not be accessible.
The original post may need some clarification. Is it the reverse DNS of the server's hostname or the client's hostname? Are there any logs or messages that can be provided? Does this issue still happen with any current version of FreeIPA?
From a testing standpoint, I have FreeIPA in a container acting as a DNS server with a reverse DNS zone for the container subnet, and I am still able to have regular hosts not in that container subnet join the domain.
This issue may have been fixed at some point and not be an issue with any current version of FreeIPA.