Product SiteDocumentation Site

Chapter 3. Setting up Systems as FreeIPA Clients

3.1. What Happens in Client Setup
3.2. Supported Platforms for FreeIPA Clients
3.3. System Ports
3.4. Configuring a Fedora System as a FreeIPA Client
3.5. Manually Configuring a Linux Client
3.6. Setting up a Linux Client Through Kickstart
3.7. Configuring a Microsoft Windows System to Join the FreeIPA Realm
3.8. Configuring a Solaris System as a FreeIPA Client
3.8.1. Configuring Solaris 10
3.8.2. Configuring Solaris 9
3.9. Configuring an HP-UX System as a FreeIPA Client
3.9.1. Configuring NTP
3.9.2. Configuring LDAP Authentication
3.9.3. Configuring Kerberos
3.9.4. Configuring PAM
3.9.5. Configuring SSH
3.9.6. Configuring Access Control
3.9.7. Testing the Configuration
3.10. Configuring an AIX System as a FreeIPA Client
3.10.1. Prerequisites
3.10.2. Configuring the AIX Client
3.11. Troubleshooting Client Installations
3.11.1. The client can't resolve reverse hostnames when using an external DNS.
3.11.2. The client is not added to the DNS zone.
3.12. Uninstalling a FreeIPA Client
A client is any system which is a member of the FreeIPA domain. While this is frequently a Fedora system (and FreeIPA has special tools to make configuring Fedora clients very simple), machines with other operating systems can also be added to the FreeIPA domain.
One important aspect of a FreeIPA client is that only the system configuration determines whether the system is part of the domain. (The configuration includes things like belonging to the Kerberos domain, DNS domain, and having the proper authentication and certificate setup.)


FreeIPA does not require any sort of agent or daemon running on a client for the client to join the domain. However, for the best management options, security, and performance, clients should run the System Security Services Daemon (SSSD).
For more information on SSSD, see the SSSD project page.
This chapter explains how to configure a system to join a FreeIPA domain.


Clients can only be configured after at least one FreeIPA server has been installed.

3.1. What Happens in Client Setup

Whether the client configuration is performed automatically on Fedora systems using the client setup script or manually on other systems, the general process of configuring a machine to serve as a FreeIPA client is mostly the same, with slight variation depending on the platform:
  • Retrieve the CA certificate for the FreeIPA CA.
  • Create a separate Kerberos configuration to test the provided credentials. This enables a Kerberos connection to the FreeIPA XML-RPC server, necessary to join the FreeIPA client to the FreeIPA domain. This Kerberos configuration is ultimately discarded.
    Setting up the Kerberos configuration includes specifying the realm and domain details, and default ticket attributes. Forwardable tickets are configured by default, which facilitates connection to the administration interface from any operating system, and also provides for auditing of administration operations. For example, this is the Kerberos configuration for Fedora systems:
    default_realm = EXAMPLE.COM
    dns_lookup_realm = false
    dns_lookup_kdc = false
    rdns = false
    forwardable = yes
    ticket_lifetime = 24h
          kdc =
          admin_server =
    [domain_realm] = EXAMPLE.COM = EXAMPLE.COM
  • Run the ipa-join command to perform the actual join
  • Obtain a service principal for the host service and installs it into /etc/krb5.keytab. For example, host/
  • Enable certmonger, retrieve an SSL server certificate, and install the certificate in /etc/pki/nssdb.
  • Disable the nscd daemon.
  • Configures SSSD or LDAP/KRB5, including NSS and PAM configuration files.
  • Configures an OpenSSH server and client, as well as enabling the host to create DNS SSHFP records.
  • Configure NTP.