FreeIPA : Installer not resolving domain name from hosts file

Mustafa Mujahid asked:

I have been having an issue while installing FreeIPA. The problem is that every time I run the installer the FreeIPA application does not read from the host file rather tries to resolve the domain name (my machine’s hostname) with a DNS query. I’m Working with CentOS Linux release 7.3.1611 (Core)

Following are the entries in my /etc/hosts file :

[[email protected] ~]# cat /etc/hosts   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1         localhost localhost.localdomain localhost6 localhost6.localdomain6 ipa

Entries in /etc/resolve.conf

[[email protected] ~]# cat /etc/resolv.conf 
# Generated by NetworkManager

If I add a DNS entry in the above, the domain is resolved from that DNS and following error is observed as would be expected if an external DNS is queried.

Please provide a realm name [EXAMPLE.COM]: 
Checking DNS domain, please wait ...
ipa.ipapython.install.cli.install_tool(Server): ERROR    DNS zone already exists in DNS and is handled by server(s):,

So I choose not to add a DNS and use an empty resolve.conf file as shown above. I have also tried setting the nameserver to my machines IP but to no luck.

To get it to force read from my hosts file I changed the nsswitch config to only read from the hosts file but that was still in vain. kindly see below the my /etc/nsswitch configuration.

[[email protected] ~]# grep hosts /etc/nsswitch.conf
hosts:      files

Running the installer

[[email protected] ~]# ipa-server-install --setup-dns -a <passwd> -p <passwd>

now with the current config returns the following :

Please provide a realm name [EXAMPLE.COM]: 
Checking DNS domain, please wait ...
Please provide the IP address to be used for this host name:

So again, the hosts file was ignored and installer asks for an IP against the domain.

Following are some test which show hostname to IP resolution is succesful

[[email protected] ~]# ping
PING ( 56(84) bytes of data.
64 bytes from ( icmp_seq=1 ttl=64 time=0.126 ms
--- ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.126/0.126/0.126/0.000 ms

[[email protected] ~]# getent hosts ipa

[[email protected] ~]# telnet

Apologies for the long post, I’m quite stuck with this and I’m having trouble figuring out what I’m missing. Any assistance on this issue would be greatly appreciated. Thankyou.

PS : The setup is not for a live environment, its for testing purposes.

My answer:

You cannot use a domain name that someone else controls. If you attempt to do so, you get the errors shown here.

Instead, use a subdomain of your own domain name. If you do not have a domain name, one can be obtained very cheaply from numerous domain registrars.

View the full question and any other answers on Server Fault.

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.