Skip to content
  • Thomas Woerner's avatar
    ansible_freeipa_module: Set KRB5CCNAME for api_connect (non root) · 871cce52
    Thomas Woerner authored
    In the case that the admin password has been set and become was not set
    the call to backend.connect in api_connect failed. The solution is simply
    to set os.environ["KRB5CCNAME"] in temp_kinit after kinit_password has
    been called using the temporary ccache. os.environ["KRB5CCNAME"] is not
    used automatically by api.Backend.[ldap2,rpcclient].connect. Afterwards
    os.environ["KRB5CCNAME"] is unset in temp_kdestroy if ccache_name is not
    None.
    
    Fixes: #249 (Kerberos errors while using the modules with a non-sudoer user)
    871cce52
Loading