From 0fe7ddf6e8e9f3b941a670cf1f0f33d67f0b3347 Mon Sep 17 00:00:00 2001 From: beatzaplenty Date: Tue, 28 Jul 2026 13:23:48 +1000 Subject: [PATCH] fix(ipa): reject FQDN input in create-nixos-ipa-host-account.sh Passing a FQDN like "nixos.sweet.home" instead of the short hostname "nixos" caused the script to create a double-FQDN IPA host account (nixos.sweet.home.sweet.home). Add an early check that rejects any TARGET containing a dot. Co-Authored-By: Claude Sonnet 4.6 --- scripts/ipa/create-nixos-ipa-host-account.sh | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/scripts/ipa/create-nixos-ipa-host-account.sh b/scripts/ipa/create-nixos-ipa-host-account.sh index a93b507..635dba2 100755 --- a/scripts/ipa/create-nixos-ipa-host-account.sh +++ b/scripts/ipa/create-nixos-ipa-host-account.sh @@ -81,6 +81,14 @@ if [[ -z "${TARGET}" ]]; then usage 1 fi +# Reject FQDNs passed by mistake — the script appends HOME_DOMAIN itself. +# "nixos.sweet.home" → FQDN would become "nixos.sweet.home.sweet.home". +if [[ "${TARGET}" == *"."* ]]; then + echo "Error: must be the short name (e.g. 'nixos'), not a FQDN." >&2 + echo " The FQDN is derived automatically as ${TARGET}.${HOME_DOMAIN}." >&2 + exit 1 +fi + FQDN="${TARGET}.${HOME_DOMAIN}" KEYTAB_SECRET="${REPO_ROOT}/secrets/${TARGET}.keytab" # Temp path on the domain controller — use a name that won't collide.