Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-1359

Getting "can't open file" for ipadnszone.py module when using fapolicyd

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Undefined Undefined
    • None
    • rhel-9.0.0
    • fapolicyd
    • None
    • None
    • rhel-security-special-projects
    • ssg_security
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None
    • 0

      Description of problem:
      When attempting to use the ipadnszone module on a RHEL 9.0 server that has fapolicyd running I am receiving:

      module_stdout": "/usr/bin/python3: can't open file '/home/<user>/.ansible/tmp/ansible-tmp-1652812850.798601-56968-125412819555844/AnsiballZ_ipadnszone.py': [Errno 1] Operation not permitted\r\n", "msg": "MODULE FAILURE\nSee stdout/stderr for the exact error", "rc": 2

      Version-Release number of selected component (if applicable):
      RHEL 9.0
      ansible-freeipa-1.7.0-1.fc35
      ansible-core-2.12.5-1.fc35

      How reproducible:
      everytime

      Steps to Reproduce:
      1. install/enable/start fapolicyd
      2. attempt to run module against a RHEL 9 server

      Actual results:
      fails

      Expected results:
      succeeds

      Additional info:
      Role I am trying to run, it succeeds on RHEL 7&8:

      • name: Allow PTR Sync on forward zone
        ipadnszone:
        ipaadmin_password: "{{ ipaadmin_password }}"
        name: "{{ ipaserver_domain }}"
        allow_sync_ptr: true
        dynamic_update: true
        state: present
      • name: Allow PTR Sync on reverse zone
        ipadnszone:
        ipaadmin_password: "{{ ipaadmin_password }}"
        name: "{{ ipaserver_reverse_zones }}"
        allow_sync_ptr: true
        dynamic_update: true
        state: present

              rsroka@redhat.com Radovan Sroka (Inactive)
              rhn-support-mralph Mike Ralph
              Radovan Sroka Radovan Sroka (Inactive)
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: