https://fedorahosted.org/freeipa/ticket/5518

Patch attached.
From d8bdb84de46923182b9d5b67e8ee6eba80aab396 Mon Sep 17 00:00:00 2001
From: Martin Basti <mba...@redhat.com>
Date: Tue, 8 Mar 2016 18:29:47 +0100
Subject: [PATCH] krb5conf: use 'true' instead of 'yes' for forwardable option

'yes' is also valid value in krb5.conf but we should be consistent and
use only 'true' as we do for other options.

https://fedorahosted.org/freeipa/ticket/5518
---
 client/ipa-client-install           | 2 +-
 install/share/krb5.conf.template    | 2 +-
 install/tools/ipa-replica-conncheck | 2 +-
 3 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/client/ipa-client-install b/client/ipa-client-install
index 48c325f53c295a5e30a9a59f357f8561d9875400..f42d877559365af3d8def3cab9b204cdb5eb919e 100755
--- a/client/ipa-client-install
+++ b/client/ipa-client-install
@@ -1069,7 +1069,7 @@ def configure_krb5_conf(cli_realm, cli_domain, cli_server, cli_kdc, dnsok,
         libopts.append({'name':'dns_lookup_kdc', 'type':'option', 'value':'true'})
     libopts.append({'name':'rdns', 'type':'option', 'value':'false'})
     libopts.append({'name':'ticket_lifetime', 'type':'option', 'value':'24h'})
-    libopts.append({'name':'forwardable', 'type':'option', 'value':'yes'})
+    libopts.append({'name':'forwardable', 'type':'option', 'value':'true'})
     libopts.append({'name':'udp_preference_limit', 'type':'option', 'value':'0'})
 
     # Configure KEYRING CCACHE if supported
diff --git a/install/share/krb5.conf.template b/install/share/krb5.conf.template
index 6cb5ee34704cd6158e882bfa89fc597f3ff1bb0f..92431d3fde6afecd0e74803e18724379e8746f9b 100644
--- a/install/share/krb5.conf.template
+++ b/install/share/krb5.conf.template
@@ -11,7 +11,7 @@ includedir /var/lib/sss/pubconf/krb5.include.d/
  dns_lookup_kdc = true
  rdns = false
  ticket_lifetime = 24h
- forwardable = yes
+ forwardable = true
  udp_preference_limit = 0
 $OTHER_LIBDEFAULTS
 [realms]
diff --git a/install/tools/ipa-replica-conncheck b/install/tools/ipa-replica-conncheck
index ba7538ac7848e680ae670d45ae5a88178d3bb32f..d88291e55cdee7ea959d73f7535dd3db4ca2c31d 100755
--- a/install/tools/ipa-replica-conncheck
+++ b/install/tools/ipa-replica-conncheck
@@ -249,7 +249,7 @@ def configure_krb5_conf(realm, kdc, filename):
     libdefaults.append({'name':'dns_lookup_kdc', 'type':'option', 'value':'true'})
     libdefaults.append({'name':'rdns', 'type':'option', 'value':'false'})
     libdefaults.append({'name':'ticket_lifetime', 'type':'option', 'value':'24h'})
-    libdefaults.append({'name':'forwardable', 'type':'option', 'value':'yes'})
+    libdefaults.append({'name':'forwardable', 'type':'option', 'value':'true'})
     libdefaults.append({'name':'udp_preference_limit', 'type':'option', 'value':'0'})
 
     opts.append({'name':'libdefaults', 'type':'section', 'value': libdefaults})
-- 
2.5.0

-- 
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Reply via email to