Blame SOURCES/0004-Handle-kvno-increment-for-RODCs.patch

59dcbd
From 108d3fd58e16428316dae4a4c0601633d2903a4b Mon Sep 17 00:00:00 2001
59dcbd
From: Sumit Bose <sbose@redhat.com>
59dcbd
Date: Wed, 1 Nov 2017 17:14:05 +0100
59dcbd
Subject: [PATCH 4/4] Handle kvno increment for RODCs
59dcbd
59dcbd
Since the actual password change does not happen on the read-only domain
59dcbd
controller (RODC) the kvno change has to be replicated back which might
59dcbd
take some time. So we check the kvno before and after the change if we
59dcbd
are connected to a RODC and increment the kvno if needed.
59dcbd
---
59dcbd
 library/adenroll.c | 31 +++++++++++++++++++++++++++++++
59dcbd
 1 file changed, 31 insertions(+)
59dcbd
59dcbd
diff --git a/library/adenroll.c b/library/adenroll.c
59dcbd
index a15e4be..40c3920 100644
59dcbd
--- a/library/adenroll.c
59dcbd
+++ b/library/adenroll.c
59dcbd
@@ -1633,8 +1633,30 @@ enroll_join_or_update_tasks (adcli_enroll *enroll,
59dcbd
 		             adcli_enroll_flags flags)
59dcbd
 {
59dcbd
 	adcli_result res;
59dcbd
+	krb5_kvno old_kvno = -1;
59dcbd
 
59dcbd
 	if (!(flags & ADCLI_ENROLL_PASSWORD_VALID)) {
59dcbd
+
59dcbd
+		/* Handle kvno changes for read-only domain controllers
59dcbd
+		 * (RODC). Since the actual password change does not happen on
59dcbd
+		 * the RODC the kvno change has to be replicated back which
59dcbd
+		 * might take some time. So we check the kvno before and after
59dcbd
+		 * the change if we are connected to a RODC and increment the
59dcbd
+		 * kvno if needed. */
59dcbd
+		if (!adcli_conn_is_writeable (enroll->conn)) {
59dcbd
+			if (enroll->computer_attributes == NULL) {
59dcbd
+				res = retrieve_computer_account (enroll);
59dcbd
+				if (res != ADCLI_SUCCESS)
59dcbd
+					return res;
59dcbd
+			}
59dcbd
+			old_kvno = adcli_enroll_get_kvno (enroll);
59dcbd
+			_adcli_info ("Found old kvno '%d'", old_kvno);
59dcbd
+
59dcbd
+			ldap_msgfree (enroll->computer_attributes);
59dcbd
+			enroll->computer_attributes = NULL;
59dcbd
+			adcli_enroll_set_kvno (enroll, 0);
59dcbd
+		}
59dcbd
+
59dcbd
 		res = set_computer_password (enroll);
59dcbd
 		if (res != ADCLI_SUCCESS)
59dcbd
 			return res;
59dcbd
@@ -1651,6 +1673,15 @@ enroll_join_or_update_tasks (adcli_enroll *enroll,
59dcbd
 			return res;
59dcbd
 	}
59dcbd
 
59dcbd
+	/* Handle kvno changes for read-only domain controllers (RODC) */
59dcbd
+	if (!adcli_conn_is_writeable (enroll->conn) && old_kvno != -1 &&
59dcbd
+	    adcli_enroll_get_kvno (enroll) != 0 &&
59dcbd
+	    adcli_enroll_get_kvno (enroll) == old_kvno) {
59dcbd
+		enroll->kvno++;
59dcbd
+		_adcli_info ("No kvno change detected on read-only DC,  kvno "
59dcbd
+		             "will be incremented by 1 to '%d'", enroll->kvno);
59dcbd
+	}
59dcbd
+
59dcbd
 	/* We ignore failures of setting these fields */
59dcbd
 	update_and_calculate_enctypes (enroll);
59dcbd
 	update_computer_account (enroll);
59dcbd
-- 
59dcbd
2.13.6
59dcbd