diff --git a/roles/ipa-krb5/templates/krb5.conf.j2 b/roles/ipa-krb5/templates/krb5.conf.j2 index a52e9548dfdbd02c32f8f8c3c7a60816c9634c51..a05c78293d7e89c258a4d811238b17c68b1948d9 100644 --- a/roles/ipa-krb5/templates/krb5.conf.j2 +++ b/roles/ipa-krb5/templates/krb5.conf.j2 @@ -22,7 +22,7 @@ includedir {{ krb5_include_d }} admin_server = {{ server }}:749 kpasswd_server = {{ server }}:464 {% endfor %} -{% if krb5_no_default_domain | bool %} +{% if krb5_default_domain | bool %} default_domain = {{ krb5_realm | lower }} {% endif %} {% if krb5_pkinit_anchors is defined %} diff --git a/roles/ipaclient/tasks/install.yml b/roles/ipaclient/tasks/install.yml index 2ad4eb63124e48c2bfa61412d7d85b347ee7f843..6b78cb948a5aa26441885958400a7a8ee470eb1e 100644 --- a/roles/ipaclient/tasks/install.yml +++ b/roles/ipaclient/tasks/install.yml @@ -198,7 +198,7 @@ krb5_realm: "{{ ipadiscovery.realm }}" krb5_dns_lookup_realm: "{{ 'false' if not ipadiscovery.dnsok or not ipadiscovery.kdc else 'true' }}" krb5_dns_lookup_kdc: "{{ 'false' if not ipadiscovery.dnsok or not ipadiscovery.kdc else 'true' }}" - krb5_no_default_domain: "{{ 'true' if ipadiscovery.domain != ipadiscovery.client_domain else 'false' }}" + krb5_default_domain: "{{ 'true' if not ipadiscovery.dnsok or not ipadiscovery.kdc else 'false' }}" krb5_pkinit_anchors: "FILE:/etc/ipa/ca.crt" when: not ipaclient_on_master | bool and ipadiscovery.ipa_python_version <= 40400 @@ -210,7 +210,7 @@ krb5_realm: "{{ ipadiscovery.realm }}" krb5_dns_lookup_realm: "{{ 'false' if not ipadiscovery.dnsok or not ipadiscovery.kdc else 'true' }}" krb5_dns_lookup_kdc: "{{ 'false' if not ipadiscovery.dnsok or not ipadiscovery.kdc else 'true' }}" - krb5_no_default_domain: "{{ 'true' if ipadiscovery.domain != ipadiscovery.client_domain else 'false' }}" + krb5_default_domain: "{{ 'true' if not ipadiscovery.dnsok or not ipadiscovery.kdc else 'false' }}" krb5_dns_canonicalize_hostname: "false" krb5_pkinit_pool: "FILE:/var/lib/ipa-client/pki/ca-bundle.pem" krb5_pkinit_anchors: "FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem"