This repository has been archived on 2026-08-17. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
debian-configuration/freeipa
beatzaplentyandClaude Sonnet 4.6 89cc8c8cc3 feat(freeipa): add domain-controller setup — Rocky Linux 9 + FreeIPA 4.13
Installs and documents the FreeIPA identity management server at
domain-controller.sweet.home (VMID 108, pve1). Provides Kerberos,
LDAP, and integrated DNS for the SWEET.HOME realm.

New section: freeipa/
- docs/install.md: full step-by-step reproduction procedure including
  Proxmox VM prep (Rocky Linux 9 GenericCloud, SeaBIOS, cloud-init),
  swap setup, static IP, /etc/hosts fix, ipa-server-install flags
- docs/pihole-dns.md: how to configure Pi-hole to forward sweet.home
  queries to the FreeIPA BIND instance
- scripts/install.sh: idempotent install script with pre-flight checks;
  reads passwords from env or interactive prompt (never commits them)
- scripts/configure-pihole-dns.sh: idempotent Pi-hole forwarder setup
- scripts/verify.sh: read-only health check (13 checks, 0 side effects)
- CLAUDE.md: host guardrails for domain-controller

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015Jbvxx4xbHVcx1NkK3vtmK
2026-07-27 07:22:05 +10:00
..

FreeIPA — domain-controller.sweet.home

FreeIPA 4.x identity management server providing Kerberos, LDAP, and integrated DNS for the sweet.home LAN. Runs on Rocky Linux 9 in a Proxmox VM (VMID 108 on pve1.sweet.home).

Quick status

Item Value
Host domain-controller.sweet.home
IP 192.168.2.138 (static)
Realm SWEET.HOME
Domain sweet.home
IPA version 4.13.x (Rocky Linux 9)
Web UI https://domain-controller.sweet.home/ipa/ui/
VMID 108 on pve1.sweet.home
OS Rocky Linux 9 (GenericCloud image)

What it provides

  • Kerberos KDC — SSO tickets for the SWEET.HOME realm
  • LDAP directory — centralised user/group/host store (389-ds)
  • Integrated DNS — authoritative for sweet.home, forwarding everything else upstream to Pi-hole (192.168.2.253)
  • CA — self-signed CA issuing certs for IPA services
  • Web UI — at https://domain-controller.sweet.home/ipa/ui/

First-time use

# SSH to the server
ssh wayne@domain-controller

# Get a Kerberos ticket as admin
kinit admin

# List IPA users
ipa user-find

# Add a user
ipa user-add jdoe --first=John --last=Doe --password

# Check service health
ipactl status

Credentials

The admin Kerberos password and Directory Manager password were generated at install time. They are not stored in this repo — keep them in your password manager.

  • admin — used for day-to-day IPA management (kinit admin)
  • Directory Manager — low-level LDAP root, rarely needed

To reset the admin password (requires being logged in as admin):

kinit admin
ipa passwd admin

DNS integration with Pi-hole

Pi-hole must forward sweet.home DNS queries to this server so that Kerberos SRV records and IPA host records resolve correctly. Run scripts/configure-pihole-dns.sh once, or add the following to Pi-hole's custom DNS config manually:

server=/sweet.home/192.168.2.138

See docs/pihole-dns.md for the full setup.

Ports required (firewalld)

FreeIPA's firewalld config is applied by ipa-server-install automatically. The following ports must be reachable from LAN clients:

Port Proto Service
80 TCP HTTP (redirect to HTTPS)
443 TCP HTTPS / Web UI
389 TCP LDAP
636 TCP LDAPS
88 TCP+UDP Kerberos
464 TCP+UDP Kerberos password change
53 TCP+UDP DNS

Reproducing this setup

See docs/install.md for the full step-by-step install procedure, or run scripts/install.sh on a fresh Rocky Linux 9 VM with the correct hostname and IP already set.

Backup

The CA certificates (required for replicas) are at /root/cacert.p12 on the server, encrypted with the Directory Manager password. Back these up to a secure location.