Freeipa client uninstall and reinstall

If you are changing ipa domains on a client, you first uninstall the client.

ipa-client-install --uninstall

Then you install in the new domain. (The lack of options here indicates it will search dns, so make sure your _kerberos entries are correct!)

ipa-client-install --mkhomedir --force-ntpd --enable-dns-updates

If you have problems with user accounts on the client for the new domain, it’s possible you need to manually clear out the sss cache to remove traces of the old domain.

rm -rf /var/lib/sss/db/*
systemctl restart sssd.service

References

Weblinks

  1. https://serverfault.com/questions/582854/how-to-reset-keytab-for-freeipa-server-and-client#583319
Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s