add gssapi auth support for ldap server

This commit is contained in:
Timo Makinen 2019-06-06 01:58:04 +03:00
parent 9cd3910f42
commit d512c8b8bd
2 changed files with 10 additions and 0 deletions

View file

@ -1,5 +1,6 @@
---
dependencies:
- {role: kerberos/client}
- {role: ldap/client}
- {role: saslauthd}

View file

@ -4,6 +4,7 @@
name: "{{ item }}"
state: installed
with_items:
- cyrus-sasl-gssapi
- openldap-servers
- ldapvi
@ -173,3 +174,11 @@
name: slapd
state: started
enabled: true
- name: create slapd keytab
import_role:
name: kerberos/keytab
vars:
keytab: /etc/openldap/slapd.keytab
principals: ["ldap/{{ inventory_hostname }}@{{ kerberos_realm }}"]
group: ldap