# Se connecter avec un utilisateur IPAsshjdupont@client.example.com
# Vรฉrifier l'authentificationidjdupont
getentpasswdjdupont
8. HBAC (Host-Based Access Control)
# Crรฉer une rรจgleipahbacrule-addallow_developers
# Ajouter des utilisateurs/groupesipahbacrule-add-userallow_developers--groups=developers
# Ajouter des hรดtesipahbacrule-add-hostallow_developers--hosts=devserver.example.com
# Ajouter des servicesipahbacrule-add-serviceallow_developers--hbacsvcs=sshd
# Activeripahbacrule-enableallow_developers
9. Sudo Rules
# Crรฉer une rรจgle sudoipasudorule-adddevelopers_sudo
# Ajouter des commandesipasudocmd-add/usr/bin/systemctl
ipasudorule-add-allow-commanddevelopers_sudo--sudocmds=/usr/bin/systemctl
# Ajouter des utilisateursipasudorule-add-userdevelopers_sudo--groups=developers
# Ajouter des hรดtesipasudorule-add-hostdevelopers_sudo--hosts=devserver.example.com
10. DNS
# Ajouter une zoneipadnszone-addinternal.example.com
# Ajouter un enregistrement Aipadnsrecord-addexample.comwebserver--a-rec=192.168.1.50
# Ajouter un CNAMEipadnsrecord-addexample.comwww--cname-rec=webserver.example.com.
# Lister les zonesipadnszone-find
11. Certificats
# Demander un certificatipa-getcertrequest\-f/etc/pki/tls/certs/server.crt\-k/etc/pki/tls/private/server.key\-NCN=server.example.com\-Dserver.example.com
# Lister les certificatsipa-getcertlist
# Statusipa-getcertstatus-f/etc/pki/tls/certs/server.crt
12. Rรฉplication (HA)
Second serveur IPA
# Sur le second serveurdnfinstall-yipa-serveripa-server-dns
ipa-replica-install\--setup-dns\--forwarder=8.8.8.8\--principal=admin\--admin-password=AdminPassword
Vรฉrifier la rรฉplication
ipa-replica-managelist
ipa-csreplica-managelist
13. Trust Active Directory
# Installer le composantdnfinstall-yipa-server-trust-ad
# Configurer le trustipa-adtrust-install
# Crรฉer le trustipatrust-add--type=adad.example.com--adminAdministrator--password
# Logsjournalctl-uipa
tail-f/var/log/dirsrv/slapd-EXAMPLE-COM/errors
tail-f/var/log/krb5kdc.log
# Test LDAPldapsearch-x-Hldap://ipa.example.com-b"dc=example,dc=com"# Test Kerberoskinitadmin
kvnoadmin@EXAMPLE.COM