change kadmin to use different user than kdc when connecting to ldap
This commit is contained in:
parent
6c917dc696
commit
2374804bfd
2 changed files with 4 additions and 4 deletions
|
@ -17,8 +17,8 @@
|
||||||
group: "{{ ansible_wheel }}"
|
group: "{{ ansible_wheel }}"
|
||||||
notify: restart kdc
|
notify: restart kdc
|
||||||
|
|
||||||
- name: store ldap auth credentials
|
- name: store kdc and kadmin ldap auth credentials
|
||||||
shell: "( echo '{{ kerberos_kdc_pass }}' ; echo '{{ kerberos_kdc_pass }}' ) | kdb5_ldap_util stashsrvpw uid=krb5kdc,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
shell: "( echo '{{ kerberos_kdc_pass }}' ; echo '{{ kerberos_kdc_pass }}' ) | kdb5_ldap_util stashsrvpw uid=krb5kdc,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }} ; ( echo '{{ kerberos_kadmin_pass }}' ; echo '{{ kerberos_kadmin_pass }}' ) | kdb5_ldap_util stashsrvpw uid=krb5kadmin,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
||||||
args:
|
args:
|
||||||
creates: "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm|lower() }}"
|
creates: "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm|lower() }}"
|
||||||
no_log: true
|
no_log: true
|
||||||
|
|
|
@ -24,8 +24,8 @@
|
||||||
ldap.{{ kerberos_realm|lower() }} = {
|
ldap.{{ kerberos_realm|lower() }} = {
|
||||||
db_library = kldap
|
db_library = kldap
|
||||||
ldap_kerberos_container_dn = "ou=System,{{ ldap_basedn }}"
|
ldap_kerberos_container_dn = "ou=System,{{ ldap_basedn }}"
|
||||||
ldap_kdc_dn = "uid=krb5kdc,cn=FOO.SH,ou=System,{{ ldap_basedn }}"
|
ldap_kdc_dn = "uid=krb5kdc,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
||||||
ldap_kadmind_dn = "uid=krb5kdc,cn=FOO.SH,ou=System,{{ ldap_basedn }}"
|
ldap_kadmind_dn = "uid=krb5kadmin,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
||||||
ldap_service_password_file = "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm|lower() }}"
|
ldap_service_password_file = "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm|lower() }}"
|
||||||
ldap_servers = "{% for item in ldap_server %}ldaps://{{ item }} {% endfor %}"
|
ldap_servers = "{% for item in ldap_server %}ldaps://{{ item }} {% endfor %}"
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue