# FreeIPA: Use Red Hat Enteprise Linux documentation:

**URL:** <https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439>\
**Category:** Rocky Linux Help & Support\
**Created:** [April 5, 2023, 4:12am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439 "2023-04-05T04:12:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nasheayahu](https://avatars.discourse-cdn.com/v4/letter/n/50afbb/32.png) [@nasheayahu](https://forums.rockylinux.org/u/nasheayahu)\
**Post date:** [April 5, 2023, 4:12am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/1 "2023-04-05T04:12:09Z")

</div>

Will I be able to get help here installing FreeIPA using RHEL documentation? Because its stated,

> Upstream user guide is not maintained anymore as all effort is put into the Red Hat Enteprise Linux documentation. Bugs found in the documentation can be reported in Red Hat bugzilla

and will the same instructions work on Rocky?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [April 5, 2023, 4:13am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/2 "2023-04-05T04:13:57Z")

</div>

The information provided for FreeIPA in the Red Hat documentation will apply to Rocky Linux.

---

<div class="post-metadata">

**Author:** ![nasheayahu](https://avatars.discourse-cdn.com/v4/letter/n/50afbb/32.png) [@nasheayahu](https://forums.rockylinux.org/u/nasheayahu)\
**Post date:** [April 5, 2023, 7:03am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/3 "2023-04-05T07:03:26Z")

</div>

CHAPTER 5. INSTALLING AN IDM SERVER: WITHOUT  
INTEGRATED DNS, WITH AN INTEGRATED CA AS THE ROOT  
CA

I want to use pfSense DNS Resolver, but RHEL states,

> NOTE  
> Red Hat strongly recommends installing IdM-integrated DNS for basic usage within the  
> IdM deployment: When the IdM server also manages DNS, there is tight integration  
> between DNS and native IdM tools which enables automating some of the DNS record  
> management

I will not be deploying any servers outside my intranet, so will I still need to follow this recommendation?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [April 5, 2023, 7:28am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/4 "2023-04-05T07:28:20Z")

</div>

It doesn’t matter that you’re not going to have servers outside of your network. The assumption is that everything is internal anyway when you deploy a FreeIPA domain (similar to deploying an AD domain). Ultimately what matters is how all the components within FreeIPA work seamlessly together. This is why it’s recommended to use the integrated DNS.

I would highly recommend reading these pages:

[https://www.freeipa.org/page/Deployment\_Recommendations#DNS](https://www.freeipa.org/page/Deployment_Recommendations#DNS)

[https://www.freeipa.org/page/DNS](https://www.freeipa.org/page/DNS)

Long story short: If you decide to not use the internal DNS and opt to use another DNS server in its place, you will need to manage it yourself, including all the records as you make changes to your network and topology. Note that unbound (the default DNS resolver in pfsense) is not a replacement for bind.

---

<div class="post-metadata">

**Author:** ![nasheayahu](https://avatars.discourse-cdn.com/v4/letter/n/50afbb/32.png) [@nasheayahu](https://forums.rockylinux.org/u/nasheayahu)\
**Post date:** [April 5, 2023, 7:32am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/5 "2023-04-05T07:32:52Z")

</div>

> [@label](#):
>
> you will need to manage it yourself, including all the records as you make changes to your network and topology. Note that unbound (the default DNS resolver in pfsense) is not a replacement for bind.

I see, and I don’t want all that headache, I will go with the recommendation. 🤓 😀 👍

---

<div class="post-metadata">

**Author:** ![nasheayahu](https://avatars.discourse-cdn.com/v4/letter/n/50afbb/32.png) [@nasheayahu](https://forums.rockylinux.org/u/nasheayahu)\
**Post date:** [April 5, 2023, 7:56am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/6 "2023-04-05T07:56:47Z")

</div>

> FreeIPA should always have own primary domain, e.g. [example.com](http://example.com) or [ipa.example.com](http://ipa.example.com) which should not be shared with other Kerberos based identity management system as otherwise there will be collisions on Kerberos system level. For example, if both FreeIPA and Active Directory use the same domain, trusts will be never possible, as well as automatic client server discovery via DNS SRV records.

With this being said, I have no plans in my intranet of using any type of Windows AD, but I want to make sure in regards to pfSense. I have the domain name set to [kbbn-7.com](http://kbbn-7.com) and its not registered as a internet domain. Will this cause a collision when using it with FreeIPA or do I have to use another name?

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 3:19am UTC](https://forums.rockylinux.org/t/freeipa-use-red-hat-enteprise-linux-documentation/9439/7 "2023-08-25T03:19:13Z")

</div>


