mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-30 10:47:08 -06:00
0840b588d7
Since CIFS principal is generated by ipa-adtrust-install and is only usable after setting CIFS configuration, there is no need to include it into default setup. This should fix upgrades from 2.2 to 3.0 where CIFS principal does not exist by default. https://fedorahosted.org/freeipa/ticket/3041
15 lines
560 B
Plaintext
15 lines
560 B
Plaintext
dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,$SUFFIX
|
|
changetype: modify
|
|
add: memberPrincipal
|
|
memberPrincipal: HTTP/$FQDN@$REALM
|
|
|
|
# ipa-cifs-delegation-targets needs to be an ipaAllowedTarget for HTTP
|
|
# delegation but we don't add it here as an LDIF because this entry may
|
|
# already exist from another replica, or previous install. If it is missing
|
|
# then it will be caught by the update file 61-trusts-s4u2proxy.update
|
|
|
|
dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX
|
|
changetype: modify
|
|
add: memberPrincipal
|
|
memberPrincipal: ldap/$FQDN@$REALM
|