summaryrefslogtreecommitdiffstats
path: root/install/updates/61-trusts-s4u2proxy.update
diff options
context:
space:
mode:
authorAlexander Bokovoy <abokovoy@redhat.com>2012-10-08 13:27:16 +0300
committerRob Crittenden <rcritten@redhat.com>2012-10-09 18:15:01 -0400
commit0840b588d753e468ce16f47944e8a332864e3166 (patch)
tree228edc6cfb2fbb41458d3f05500b2378abc3118d /install/updates/61-trusts-s4u2proxy.update
parent00a54b8b7f1e6e157f4b5efe7f24462685194de5 (diff)
downloadfreeipa-0840b588d753e468ce16f47944e8a332864e3166.tar.gz
freeipa-0840b588d753e468ce16f47944e8a332864e3166.tar.xz
freeipa-0840b588d753e468ce16f47944e8a332864e3166.zip
Add cifs principal to S4U2Proxy targets only when running ipa-adtrust-install
Since CIFS principal is generated by ipa-adtrust-install and is only usable after setting CIFS configuration, there is no need to include it into default setup. This should fix upgrades from 2.2 to 3.0 where CIFS principal does not exist by default. https://fedorahosted.org/freeipa/ticket/3041
Diffstat (limited to 'install/updates/61-trusts-s4u2proxy.update')
-rw-r--r--install/updates/61-trusts-s4u2proxy.update9
1 files changed, 2 insertions, 7 deletions
diff --git a/install/updates/61-trusts-s4u2proxy.update b/install/updates/61-trusts-s4u2proxy.update
index 4a71148bc..7504a068e 100644
--- a/install/updates/61-trusts-s4u2proxy.update
+++ b/install/updates/61-trusts-s4u2proxy.update
@@ -1,12 +1,7 @@
-dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,$SUFFIX
-add: ipaAllowedTarget: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX'
-
dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX
default: objectClass: groupOfPrincipals
default: objectClass: top
default: cn: ipa-cifs-delegation-targets
-default: memberPrincipal: cifs/$FQDN@$REALM
-
-dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX
-add: memberPrincipal: cifs/$FQDN@$REALM
+dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,$SUFFIX
+add: ipaAllowedTarget: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX'