So, my situation:
I have 2 FreeIPA servers in AWS.
I want want to load balance the WebUI (basically for the user's self-service). Not the
KDC, or LDAP or anything else, just the WebUI. Mainly because my hostnames are absolutely
horrible and extremely difficult to remember.
What I done so far is:
- Create an ALB in AWS pointing to the 2 instances.
- The ALB listens on port 80
- The ALB forwards traffic to port 443
It looks like it's OK for the moment, although I believe the best approach would be to
create a new certificate in the FreeIPA servers that would include the ALB hostname and
use HTTPS end to end. (but that's another story).