mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2026-07-29 23:58:23 -05:00
Remove is_fips_enabled checks in installers and ipactl
https://fedorahosted.org/freeipa/ticket/5695 Reviewed-By: Tomas Krizek <tkrizek@redhat.com>
This commit is contained in:
committed by
Martin Basti
parent
8d3bea8acc
commit
08c71703a4
@@ -543,9 +543,6 @@ def main():
|
|||||||
elif args[0] != "start" and args[0] != "stop" and args[0] != "restart" and args[0] != "status":
|
elif args[0] != "start" and args[0] != "stop" and args[0] != "restart" and args[0] != "status":
|
||||||
raise IpactlError("Unrecognized action [" + args[0] + "]", 2)
|
raise IpactlError("Unrecognized action [" + args[0] + "]", 2)
|
||||||
|
|
||||||
if tasks.is_fips_enabled():
|
|
||||||
raise IpactlError("Starting IPA server in FIPS mode is not supported")
|
|
||||||
|
|
||||||
# check if IPA is configured at all
|
# check if IPA is configured at all
|
||||||
try:
|
try:
|
||||||
check_IPA_configuration()
|
check_IPA_configuration()
|
||||||
|
|||||||
@@ -1953,11 +1953,6 @@ def install_check(options):
|
|||||||
"You must be root to run ipa-client-install.",
|
"You must be root to run ipa-client-install.",
|
||||||
rval=CLIENT_INSTALL_ERROR)
|
rval=CLIENT_INSTALL_ERROR)
|
||||||
|
|
||||||
if tasks.is_fips_enabled():
|
|
||||||
raise ScriptError(
|
|
||||||
"Installing IPA client in FIPS mode is not supported",
|
|
||||||
rval=CLIENT_INSTALL_ERROR)
|
|
||||||
|
|
||||||
tasks.check_selinux_status()
|
tasks.check_selinux_status()
|
||||||
|
|
||||||
if is_ipa_client_installed(fstore, on_master=options.on_master):
|
if is_ipa_client_installed(fstore, on_master=options.on_master):
|
||||||
|
|||||||
@@ -304,10 +304,6 @@ def install_check(installer):
|
|||||||
external_ca_file = installer._external_ca_file
|
external_ca_file = installer._external_ca_file
|
||||||
http_ca_cert = installer._ca_cert
|
http_ca_cert = installer._ca_cert
|
||||||
|
|
||||||
if tasks.is_fips_enabled():
|
|
||||||
raise RuntimeError(
|
|
||||||
"Installing IPA server in FIPS mode is not supported")
|
|
||||||
|
|
||||||
tasks.check_selinux_status()
|
tasks.check_selinux_status()
|
||||||
|
|
||||||
if options.master_password:
|
if options.master_password:
|
||||||
|
|||||||
@@ -527,10 +527,6 @@ def check_remote_version(api):
|
|||||||
|
|
||||||
|
|
||||||
def common_check(no_ntp):
|
def common_check(no_ntp):
|
||||||
if tasks.is_fips_enabled():
|
|
||||||
raise RuntimeError(
|
|
||||||
"Installing IPA server in FIPS mode is not supported")
|
|
||||||
|
|
||||||
tasks.check_selinux_status()
|
tasks.check_selinux_status()
|
||||||
|
|
||||||
if is_ipa_configured():
|
if is_ipa_configured():
|
||||||
@@ -646,7 +642,12 @@ def install_check(installer):
|
|||||||
filename = installer.replica_file
|
filename = installer.replica_file
|
||||||
installer._enrollment_performed = False
|
installer._enrollment_performed = False
|
||||||
|
|
||||||
# check FIPS, selinux status, http and DS ports, NTP conflicting services
|
if tasks.is_fips_enabled():
|
||||||
|
raise RuntimeError(
|
||||||
|
"Installing IPA server in FIPS mode on domain level 0 is not "
|
||||||
|
"supported")
|
||||||
|
|
||||||
|
# check selinux status, http and DS ports, NTP conflicting services
|
||||||
common_check(options.no_ntp)
|
common_check(options.no_ntp)
|
||||||
|
|
||||||
client_fstore = sysrestore.FileStore(paths.IPA_CLIENT_SYSRESTORE)
|
client_fstore = sysrestore.FileStore(paths.IPA_CLIENT_SYSRESTORE)
|
||||||
@@ -942,7 +943,7 @@ def promote_check(installer):
|
|||||||
installer._enrollment_performed = False
|
installer._enrollment_performed = False
|
||||||
installer._top_dir = tempfile.mkdtemp("ipa")
|
installer._top_dir = tempfile.mkdtemp("ipa")
|
||||||
|
|
||||||
# check FIPS, selinux status, http and DS ports, NTP conflicting services
|
# check selinux status, http and DS ports, NTP conflicting services
|
||||||
common_check(options.no_ntp)
|
common_check(options.no_ntp)
|
||||||
|
|
||||||
client_fstore = sysrestore.FileStore(paths.IPA_CLIENT_SYSRESTORE)
|
client_fstore = sysrestore.FileStore(paths.IPA_CLIENT_SYSRESTORE)
|
||||||
|
|||||||
Reference in New Issue
Block a user