Restart slapd when keytab is available. HTTP service principal.

This commit is contained in:
Andreas B. Mundt 2020-03-16 19:36:19 +01:00
parent f0c65d3cce
commit 6f0197f693
2 changed files with 9 additions and 2 deletions

View file

@ -1,7 +1,11 @@
- name: restart slapd
systemd: name=slapd state=restarted enabled=yes
listen: "restart slapd"
- name: restart krb5-kdc
service: name=krb5-kdc state=restarted enabled=yes
systemd: name=krb5-kdc state=restarted enabled=yes
listen: "restart krb5-kdc"
- name: restart krb5-admin-server
service: name=krb5-admin-server state=restarted enabled=yes
systemd: name=krb5-admin-server state=restarted enabled=yes
listen: "restart krb5-admin-server"

View file

@ -173,6 +173,7 @@
with_items:
- host
- ldap
- HTTP
when: not krb5kdc.stat.exists
- name: add principal to the keytab
@ -180,6 +181,7 @@
with_items:
- host
- ldap
- HTTP
when: not krb5kdc.stat.exists
- name: allow slapd to read the keytab
@ -188,6 +190,7 @@
owner: root
group: openldap
mode: '0640'
notify: restart slapd
- name: "make 'kerberos' an alias hostname resolvable from the LAN"
replace: