FWIW if you use FreeIPA you will be able to join domains there and
use
DNS Dynamic Updates to update the DNS when some IP address change
letting hosts manage themselves mostly.
Simo.
I tested FreeIPA thoroughly. The problem is we want the same domain on
the Linux servers,
and I want to use the AD Kerberos as authentication provider.
But the freeipa client always resolves to the KDC of AD, what is
causing a lot of trouble.
The other issue is the DNS is a seperate appliance managed by another team.
So I went with OpenLDAP.
And on the client
LDAP as ID provider
Kerberos on AD as auth provider