Skip to content
Snippets Groups Projects
Commit 5f17e9a7 authored by Thomas Woerner's avatar Thomas Woerner
Browse files

roles/krb5: New krb5_no_default_domain setting

parent e65ba14e
No related branches found
No related tags found
No related merge requests found
...@@ -8,6 +8,7 @@ krb5_realm: ...@@ -8,6 +8,7 @@ krb5_realm:
krb5_servers: krb5_servers:
krb5_dns_lookup_realm: "false" krb5_dns_lookup_realm: "false"
krb5_dns_lookup_kdc: "false" krb5_dns_lookup_kdc: "false"
krb5_no_default_domain: "false"
krb5_default_ccache_name: KEYRING:persistent:%{uid} krb5_default_ccache_name: KEYRING:persistent:%{uid}
krb5_pkinit_anchors: FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem krb5_pkinit_anchors: FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem
......
...@@ -13,8 +13,9 @@ ...@@ -13,8 +13,9 @@
- name: Template krb5.conf - name: Template krb5.conf
template: template:
src: krb5.conf.j2 src: krb5.conf.j2
dest: /etc/krb5.conf dest: "{{ krb5_conf }}"
backup: yes backup: no
owner: root owner: root
group: root group: root
mode: 0644 mode: 0644
force: yes
\ No newline at end of file
...@@ -20,7 +20,9 @@ includedir {{ krb5_include_d }} ...@@ -20,7 +20,9 @@ includedir {{ krb5_include_d }}
admin_server = {{ server }}:749 admin_server = {{ server }}:749
kpasswd_server = {{ server }}:464 kpasswd_server = {{ server }}:464
{% endfor %} {% endfor %}
{% if krb5_no_default_domain | bool %}
default_domain = {{ krb5_realm | lower }} default_domain = {{ krb5_realm | lower }}
{% endif %}
pkinit_anchors = {{ krb5_pkinit_anchors }} pkinit_anchors = {{ krb5_pkinit_anchors }}
pkinit_pool = {{ krb5_pkinit_pool }} pkinit_pool = {{ krb5_pkinit_pool }}
} }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment