mirror of
https://github.com/freeipa/ansible-freeipa.git
synced 2026-07-25 00:44:42 +00:00
Merge pull request #1206 from rjeffman/ipaserver_fix_deploy_EL8
ipaserver: Fix deployment after Bronze-bit fix
This commit is contained in:
@@ -131,7 +131,8 @@ from ansible.module_utils.basic import AnsibleModule
|
|||||||
from ansible.module_utils.ansible_ipa_server import (
|
from ansible.module_utils.ansible_ipa_server import (
|
||||||
check_imports,
|
check_imports,
|
||||||
MAX_DOMAIN_LEVEL, AnsibleModuleLog, options, sysrestore, paths,
|
MAX_DOMAIN_LEVEL, AnsibleModuleLog, options, sysrestore, paths,
|
||||||
api_Backend_ldap2, ds_init_info, redirect_stdout, setup_logging
|
api_Backend_ldap2, ds_init_info, redirect_stdout, setup_logging,
|
||||||
|
krbinstance, service
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
@@ -221,6 +222,16 @@ def main():
|
|||||||
with redirect_stdout(ansible_log):
|
with redirect_stdout(ansible_log):
|
||||||
ds.change_admin_password(options.admin_password)
|
ds.change_admin_password(options.admin_password)
|
||||||
|
|
||||||
|
# Force KDC to refresh the cached value of ipaKrbAuthzData by restarting.
|
||||||
|
# ipaKrbAuthzData has to be set with "MS-PAC" to trigger PAC generation,
|
||||||
|
# which is required to handle S4U2Proxy with the Bronze-Bit fix.
|
||||||
|
# Not doing so would cause API malfunction for around a minute, which is
|
||||||
|
# long enough to cause the hereafter client installation to fail.
|
||||||
|
krb = krbinstance.KrbInstance(fstore)
|
||||||
|
krb.set_output(ansible_log)
|
||||||
|
service.print_msg("Restarting the KDC")
|
||||||
|
krb.restart()
|
||||||
|
|
||||||
# done ##########################################################
|
# done ##########################################################
|
||||||
|
|
||||||
ansible_module.exit_json(changed=True)
|
ansible_module.exit_json(changed=True)
|
||||||
|
|||||||
Reference in New Issue
Block a user