37 lines
928 B
YAML
37 lines
928 B
YAML
---
|
|
- name: Install packages
|
|
ansible.builtin.package:
|
|
name: "{{ item }}"
|
|
state: installed
|
|
with_items:
|
|
- krb5-server
|
|
- krb5-server-ldap
|
|
|
|
- name: Create kdc config
|
|
ansible.builtin.template:
|
|
dest: /var/kerberos/krb5kdc/kdc.conf
|
|
src: kdc.conf.j2
|
|
mode: "0600"
|
|
owner: root
|
|
group: "{{ ansible_wheel }}"
|
|
|
|
- name: Store kdc and kadmin LDAP credentials
|
|
ansible.builtin.command:
|
|
argv:
|
|
- kdb5_ldap_util
|
|
- stashsrvpw
|
|
- "uid=krb5kadmin,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
|
|
stdin: |
|
|
{{ kerberos_kadmin_pass }}
|
|
{{ kerberos_kadmin_pass }}
|
|
creates: "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm | lower() }}"
|
|
no_log: true
|
|
|
|
- name: Store kdc master key
|
|
ansible.builtin.command:
|
|
argv:
|
|
- kdb5_util
|
|
- stash
|
|
stdin: "{{ kerberos_master_pass }}"
|
|
creates: "/var/kerberos/krb5kdc/.k5.{{ kerberos_realm }}"
|
|
no_log: true
|