diff --git a/roles/ldap/server/templates/slapd.conf.j2 b/roles/ldap/server/templates/slapd.conf.j2 index 0fd38b7..2deba52 100644 --- a/roles/ldap/server/templates/slapd.conf.j2 +++ b/roles/ldap/server/templates/slapd.conf.j2 @@ -168,6 +168,17 @@ access to dn.one=ou=People,{{ ldap_basedn }} attrs=loginShell by users read by * none +# allow reads to netgroups +# TODO: change that only sysadm + host certs can read +access to dn.sub=ou=Netgroup,ou=System,{{ ldap_basedn }} + by users read + by * none + +# allow reads to ou=System object itself +access to dn.base=ou=System,{{ ldap_basedn }} + by users read + by * none + # block rest of queries to ou=System tree access to dn.sub=ou=System,{{ ldap_basedn }} by * none