Troubleshooting
Trust setup validation failed
If the trust setup fails during validation, check the following:
- DNS resolution: Run the nslookup <AD_FQDN> <DNS_IP> command to ensure that the DNS server IP address you provided can resolve the Active Directory domain.
- Reverse DNS: Ensure that reverse DNS is configured for the KDC IP address.
- Network connectivity: Verify that FreeIPA instances can reach the AD Domain Controller on ports 88 (Kerberos), 389 (LDAP), and 53 (DNS).
- FreeIPA status: The environment's FreeIPA status must be Available before trust can be configured.
Trust setup failed
If the trust setup fails after validation:
- Package availability: Ensure that the FreeIPA image includes the ipa-server-trust-ad package.
- Load balancer: FreeIPA must have a load balancer configured.
- KDC reachability: Verify that the KDC FQDN and IP address are correct and that FreeIPA can establish a connection to the Domain Controller.
Retrying after failure
If trust setup fails, the environment status returns to Available with the trust in a failed state. You can retry the trust setup by clicking Add Trust again from the FreeIPA Trust tab.
