Blame SOURCES/ansible-freeipa-0.3.2-ipaclient-Do-not-fail-on-rmkeytab-error-7_rhbz#1931381.patch

05ba5a
From 976cd1baa70b3ac1a271a362163e469b8d54d04a Mon Sep 17 00:00:00 2001
05ba5a
From: Thomas Woerner <twoerner@redhat.com>
05ba5a
Date: Mon, 22 Feb 2021 13:28:04 +0100
05ba5a
Subject: [PATCH] ipaclient: Do not fail on rmkeytab error #7
05ba5a
05ba5a
Due to commit f3f9672d527008dc741ac90aa465bac842eea08d (ipa-rmkeytab: Check
05ba5a
return value of krb5_kt_(start|end)_seq_get) in IPA 4.9.2 there is a new
05ba5a
error reported for ipa-rmkeytab in case of a non existing keytab file.
05ba5a
Using ipa-rmkeytab now results in the error #7 in this case.
05ba5a
05ba5a
The client role is using ipa-rmkeytab and needs to ignore error #7 also.
05ba5a
05ba5a
Fixes: #510 (ipa-client installation with OTP is failed with error code 7
05ba5a
             (keytab: /usr/sbin/ipa-rmkeytab returned 7))
05ba5a
---
05ba5a
 roles/ipaclient/tasks/install.yml | 6 +++++-
05ba5a
 1 file changed, 5 insertions(+), 1 deletion(-)
05ba5a
05ba5a
diff --git a/roles/ipaclient/tasks/install.yml b/roles/ipaclient/tasks/install.yml
05ba5a
index fccc72e..23f9529 100644
05ba5a
--- a/roles/ipaclient/tasks/install.yml
05ba5a
+++ b/roles/ipaclient/tasks/install.yml
05ba5a
@@ -181,8 +181,12 @@
05ba5a
     # Do not fail on error codes 3 and 5:
05ba5a
     #   3 - Unable to open keytab
05ba5a
     #   5 - Principal name or realm not found in keytab
05ba5a
+    #   7 - Failed to set cursor, typically when errcode
05ba5a
+    #       would be issued in past
05ba5a
     failed_when: result_ipa_rmkeytab.rc != 0 and
05ba5a
-                 result_ipa_rmkeytab.rc != 3 and result_ipa_rmkeytab.rc != 5
05ba5a
+                 result_ipa_rmkeytab.rc != 3 and
05ba5a
+                 result_ipa_rmkeytab.rc != 5 and
05ba5a
+                 result_ipa_rmkeytab.rc != 7
05ba5a
     when: (ipaclient_use_otp | bool or ipaclient_force_join | bool) and not ipaclient_on_master | bool
05ba5a
 
05ba5a
   - name: Install - Backup and set hostname
05ba5a
-- 
05ba5a
2.29.2
05ba5a