If a new host object is created with 'ipa host-add' the new object does not have the objectclass KrbTicketPolicyAux. This causes issues if e.g. other flags should be added with kadmin.local
kadmin.local: modprinc +ok_as_delegate host/testhost.idm.com@IDM.COM modify_principal: Kerberos database internal error while modifying "host/testhost.idm.com@IDM.COM".
It looks like this is already fixed in FreeIPA v3.
Additional info: the directory server logs say:
[07/Jan/2013:10:49:41 -0500] - Entry "fqdn=testhost.idm.com,cn=computers,cn=accounts,dc=idm,dc=com" -- attribute "krbTicketFlags" not allowed
This is already fixed in v3. Closing. The instructions can be found on the mailing list: https://www.redhat.com/archives/freeipa-users/2013-January/msg00043.html
Workaround from the mailing list:
ipa host-mod --addattr='objectclass=krbTicketPolicyAux' testhost.idm.com
Metadata Update from @sbose: - Issue assigned to someone - Issue set to the milestone: FreeIPA 2.2 Stabilization
Login to comment on this ticket.