mirror of
https://git.lapiole.org/dani/ansible-roles.git
synced 2025-07-26 15:55:56 +02:00
Update to 2021-12-01 19:13
This commit is contained in:
5
roles/wb_ad_auth/templates/krb5.conf
Normal file
5
roles/wb_ad_auth/templates/krb5.conf
Normal file
@@ -0,0 +1,5 @@
|
||||
[libdefaults]
|
||||
default_realm = {{ ad_realm | upper }}
|
||||
dns_lookup_realm = false
|
||||
dns_lookup_kdc = true
|
||||
rdns = false
|
5
roles/wb_ad_auth/templates/krb5.conf.j2
Normal file
5
roles/wb_ad_auth/templates/krb5.conf.j2
Normal file
@@ -0,0 +1,5 @@
|
||||
[libdefaults]
|
||||
default_realm = {{ ad_realm }}
|
||||
dns_lookup_realm = false
|
||||
dns_lookup_kdc = true
|
||||
rdns = false
|
24
roles/wb_ad_auth/templates/sssd.conf.j2
Normal file
24
roles/wb_ad_auth/templates/sssd.conf.j2
Normal file
@@ -0,0 +1,24 @@
|
||||
[sssd]
|
||||
services = nss, pam
|
||||
config_file_version = 2
|
||||
domains = {{ ad_realm }}
|
||||
|
||||
[nss]
|
||||
shell_fallback = /bin/false
|
||||
|
||||
[pam]
|
||||
|
||||
[domain/{{ ad_realm }}]
|
||||
id_provider = ad
|
||||
ad_hostname = {{ ansible_hostname }}.{{ ad_realm | lower }}
|
||||
fallback_homedir = /home/%d/%u
|
||||
default_shell = /bin/false
|
||||
cache_credentials = true
|
||||
enumerate = true
|
||||
access_provider = ad
|
||||
ad_access_filter = {{ ad_access_filter }}
|
||||
{% if ad_ldap_group_search_base is defined %}
|
||||
ldap_group_search_base = {{ ad_ldap_group_search_base }}
|
||||
{% elif ad_ignore_groups | length > 0 %}
|
||||
ldap_group_search_base = {{ ad_ldap_base }}?sub?(!(|(cn={{ ad_ignore_groups | join(')(cn=') }})))
|
||||
{% endif %}
|
Reference in New Issue
Block a user