1
0
mirror of https://pagure.io/fedora-qa/os-autoinst-distri-fedora.git synced 2024-11-21 21:43:08 +00:00

Disable dnssec on FreeIPA on Rawhide to avoid #2117859

I'd prefer not to have to do this, but having the tests fail on
every compose and Rawhide update test is just too distracting
to live with.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
This commit is contained in:
Adam Williamson 2022-08-18 14:29:44 -04:00
parent 5b897801bf
commit dc318983f1

View File

@ -34,10 +34,11 @@ sub run {
assert_script_run "systemctl restart firewalld.service";
# deploy the server
my $args = "-U --auto-forwarders --realm=TEST.OPENQA.FEDORAPROJECT.ORG --domain=test.openqa.fedoraproject.org --ds-password=monkeys123 --admin-password=monkeys123 --setup-dns --reverse-zone=2.16.172.in-addr.arpa --allow-zone-overlap";
# FIXME: this is a workaround for #1999321 - we just have to turn
# off dnssec on the server end to avoid hitting it
# FIXME: For upgrades to F>34, we turn off dnssec to avoid hitting
# #1999321. For all deployments on F>37, we turn it off to avoid
# hitting #2117859
my $relnum = get_release_number;
$args .= ' --no-dnssec-validation' if (get_var("UPGRADE") && $relnum > 34);
$args .= ' --no-dnssec-validation' if ($relnum > 37 || (get_var("UPGRADE") && $relnum > 34));
assert_script_run "ipa-server-install $args", 1200;
# enable and start the systemd service
assert_script_run "systemctl enable ipa.service";