Currently the mechanism by which DS and Apache get service keytabs during replica install differ in domain level 0 and 1, respectively (e.g. in DL1 directory server requests keytab from remote master, in DL0 KDC installer generates it).
This makes it hard to abstract domain-level specific behavior from the replica installer(s).
Both domain levels should have a common mechanism to request service keytabs so that amount of domain-level specific behavior is kept at minimum. This may require more substantial modifications in replica installation workflows.
Part of the installer refactoring effort.
master:
The related patches were pushed as part of #6392
Metadata Update from @mbabinsk: - Issue assigned to mbabinsk - Issue set to the milestone: FreeIPA 4.5
Log in to comment on this ticket.