Troubleshooting

Trust setup validation failed

If the trust setup fails during validation, check the following:
  • DNS resolution: Run the nslookup <AD_FQDN> <DNS_IP> command to ensure that the DNS server IP address you provided can resolve the Active Directory domain.
  • Reverse DNS: Ensure that reverse DNS is configured for the KDC IP address.
  • Network connectivity: Verify that FreeIPA instances can reach the AD Domain Controller on ports 88 (Kerberos), 389 (LDAP), and 53 (DNS).
  • FreeIPA status: The environment's FreeIPA status must be Available before trust can be configured.

Trust setup failed

If the trust setup fails after validation:
  • Package availability: Ensure that the FreeIPA image includes the ipa-server-trust-ad package.
  • Load balancer: FreeIPA must have a load balancer configured.
  • KDC reachability: Verify that the KDC FQDN and IP address are correct and that FreeIPA can establish a connection to the Domain Controller.

Retrying after failure

If trust setup fails, the environment status returns to Available with the trust in a failed state. You can retry the trust setup by clicking Add Trust again from the FreeIPA Trust tab.