LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-23-2016, 10:50 AM   #1
maclux
LQ Newbie
 
Registered: Sep 2016
Posts: 2

Rep: Reputation: Disabled
IDM Servers & Clients in different Time Zones


First post; be easy on me.

Can IDM/IPA servers and clients be configured in different time zones as long as they are pointed to the same NTP servers?

We have a use case scenario that requires some clients and IPA servers to be configured within specific desperate time zones for application compatibility reasons. All IPA servers and clients will be in the same domain. There will be an IPA server at each site.

Will this have ill affects on Kerberos tickets etc or will the offset be considered/corrected at each host?

Thoughts, experiences and configuration examples?

Thank you
 
Old 09-23-2016, 07:51 PM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939
So far as I know, the custom in such situations is to act on UTC ... Universal Time. Time is presented to end-users and such in terms of the correct time-zone (and time-of-year), but internally it is absolute.
 
1 members found this post helpful.
Old 09-26-2016, 12:16 PM   #3
maclux
LQ Newbie
 
Registered: Sep 2016
Posts: 2

Original Poster
Rep: Reputation: Disabled
Thanks for the reply sundialsvcs

I was able to mimic the use case scenario in a lab and it worked fine. From what I found in testing, time zone does not have an effect on Kerberos etc. since the time zone offset appears to be managed at each host. So as long as the time skew does not go beyond 5 minutes, all is well.

Site A
IPASRV1 in CT
IPACLT1 client in CT
ADDC in EST (AD/IPA One Way Trust) (configured to sync with external time servers)

Site B
IPASRV2 in UTC
IPACLT2 client in UTC



NTP Server Poll Settings: /etc/ntp.conf

Pointed IPASRV1 to ADDC
Pointed IPACLT1 to IPASRV1
Pointed IPASRV2 to IPASRV1
Pointed IPACLT2 to IPASRV2

Of course you could/should add redundancy to the configuration by adding all 3 servers to ntp.conf on each host.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
domain zones and servers goncalopp Linux - Server 0 02-23-2012 07:15 AM
[SOLVED] Zones are not getting updated at slave servers pratapsingh Linux - Server 7 02-20-2011 11:08 AM
Synchronizing DNS Servers - automatically create new zones assi Linux - Networking 3 03-21-2009 10:58 AM
Mirror DNS Zones/named (4 different servers/locations) ftw Linux - Networking 5 03-15-2006 07:41 AM
computer maintenance & time zones rblampain Linux - Hardware 0 01-10-2006 11:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration