ipa/client: sssd drop in needs to be same permission as sssd.conf also

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
This commit is contained in:
Kevin Fenzi 2025-02-16 14:35:32 -08:00
parent 258fa9fd14
commit d3975febbe

View file

@ -74,7 +74,7 @@
run_once: yes
- name: Ensure that nss knows to skip certain users (f41/rhel)
ansible.builtin.template: src=fedora-nss-ignore.conf.j2 dest=/etc/sssd/conf.d/fedora-nss-ignore.conf mode=600 owner=root group=sssd
ansible.builtin.template: src=fedora-nss-ignore.conf.j2 dest=/etc/sssd/conf.d/fedora-nss-ignore.conf mode=640 owner=root group=sssd
tags:
- ipa/client
- config