kdc: Move KDC to run in container
This commit is contained in:
parent
0c00037cf2
commit
9c083ebb81
10 changed files with 71 additions and 119 deletions
4
roles/kdc/templates/kdc-container.sysconfig.j2
Normal file
4
roles/kdc/templates/kdc-container.sysconfig.j2
Normal file
|
@ -0,0 +1,4 @@
|
|||
LDAP_BASEDN="{{ ldap_basedn }}"
|
||||
LDAP_BIND_PW="{{ kerberos_kdc_pass }}"
|
||||
KRB5_REALM="{{ kerberos_realm }}"
|
||||
KRB5_STASH_PW="{{ kerberos_master_pass }}"
|
|
@ -1,33 +0,0 @@
|
|||
[libdefaults]
|
||||
default_realm = {{ kerberos_realm }}
|
||||
|
||||
[logging]
|
||||
kdc = SYSLOG
|
||||
admin_server = SYSLOG
|
||||
|
||||
[kdcdefaults]
|
||||
# listen on localhost only
|
||||
kdc_listen = 127.0.0.1:88
|
||||
kdc_tcp_listen = 127.0.0.1:88
|
||||
|
||||
[realms]
|
||||
{{ kerberos_realm }} = {
|
||||
database_module = ldap.{{ kerberos_realm|lower() }}
|
||||
key_stash_file = "/var/kerberos/krb5kdc/.k5.{{ kerberos_realm }}"
|
||||
max_lifetime = 24h 0m 0s
|
||||
max_renewable_life = 7d 0h 0m 0s
|
||||
master_key_type = aes256-cts-hmac-sha1-96
|
||||
supported_enctypes = aes256-cts-hmac-sha1-96:normal
|
||||
}
|
||||
|
||||
[dbmodules]
|
||||
ldap.{{ kerberos_realm|lower() }} = {
|
||||
db_library = kldap
|
||||
disable_last_success = true
|
||||
disable_lockout = true
|
||||
ldap_kerberos_container_dn = "ou=System,{{ ldap_basedn }}"
|
||||
ldap_kdc_dn = "uid=krb5kdc,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
||||
ldap_kadmind_dn = "uid=krb5kadmin,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
||||
ldap_service_password_file = "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm|lower() }}"
|
||||
ldap_servers = "{% for item in ldap_server %}ldaps://{{ item }} {% endfor %}"
|
||||
}
|
|
@ -1,4 +0,0 @@
|
|||
[global]
|
||||
|
||||
[{{ kerberos_realm }}]
|
||||
kerberos = kerberos+tcp://localhost
|
|
@ -1,3 +0,0 @@
|
|||
location /KdcProxy {
|
||||
proxy_pass http://unix:/run/gunicorn/gunicorn-kdcproxy.sock:/KdcProxy;
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue