mirror of
https://github.com/freeipa/ansible-freeipa.git
synced 2026-03-26 21:33:05 +00:00
node and the credential cache is copied to the managed node ipahost module is also using facts gathered from the server to find the domain and realm.
22 lines
661 B
INI
22 lines
661 B
INI
[ipaclients]
|
|
ipaclient.ipadomain.com
|
|
|
|
[ipaservers]
|
|
ipaserver.ipadomain.com
|
|
|
|
[ipaclients:vars]
|
|
ipaclient_domain=ipadomain.com
|
|
ipaclient_realm=IPADOMAIN.COM
|
|
ipaclient_server=ipaserver.ipadomain.com
|
|
ipaclient_extraargs=[ '--kinit-attempts=3', '--mkhomedir']
|
|
# if neither ipaclient_password nor ipaclient_keytab is defined,
|
|
# the enrollement will create a OneTime Password and enroll with this OTP
|
|
# In this case ipaserver_password or ipaserver_keytab is required
|
|
#ipaclient_principal=admin
|
|
#ipaclient_password=SecretPassword123
|
|
#ipaclient_keytab=/tmp/krb5.keytab
|
|
ipaserver_principal=admin
|
|
#ipaserver_password=SecretPassword123
|
|
ipaserver_keytab=files/admin.keytab
|
|
|