From 5afff575c54ab5bc4c26c854b6ca90974abcd496 Mon Sep 17 00:00:00 2001 From: Timo Makinen Date: Fri, 14 Jun 2019 10:12:07 +0300 Subject: [PATCH] change cups authentication to use kerberos --- roles/cups/server/handlers/main.yml | 6 ++++++ roles/cups/server/tasks/main.yml | 7 +++++++ 2 files changed, 13 insertions(+) create mode 100644 roles/cups/server/handlers/main.yml diff --git a/roles/cups/server/handlers/main.yml b/roles/cups/server/handlers/main.yml new file mode 100644 index 0000000..7923ad8 --- /dev/null +++ b/roles/cups/server/handlers/main.yml @@ -0,0 +1,6 @@ +--- + +- name: restart cups + service: + name: cups + state: restarted diff --git a/roles/cups/server/tasks/main.yml b/roles/cups/server/tasks/main.yml index cc3a4f8..bd1bcbe 100644 --- a/roles/cups/server/tasks/main.yml +++ b/roles/cups/server/tasks/main.yml @@ -28,6 +28,13 @@ owner: root group: "{{ ansible_wheel }}" +- name: enable gssapi authentication from cups + lineinfile: + path: /etc/cups/cupsd.conf + regexp: "^DefaultAuthType .*" + line: "DefaultAuthType Negotiate" + notify: restart cups + - name: disable cups socket service systemd: name: cups.socket