ansible/roles/kadmin/tasks/main.yml

37 lines
928 B
YAML

---
- name: Install packages
ansible.builtin.package:
name: "{{ item }}"
state: installed
with_items:
- krb5-server
- krb5-server-ldap
- name: Create kdc config
ansible.builtin.template:
dest: /var/kerberos/krb5kdc/kdc.conf
src: kdc.conf.j2
mode: "0600"
owner: root
group: "{{ ansible_wheel }}"
- name: Store kdc and kadmin LDAP credentials
ansible.builtin.command:
argv:
- kdb5_ldap_util
- stashsrvpw
- "uid=krb5kadmin,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
stdin: |
{{ kerberos_kadmin_pass }}
{{ kerberos_kadmin_pass }}
creates: "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm | lower() }}"
no_log: true
- name: Store kdc master key
ansible.builtin.command:
argv:
- kdb5_util
- stash
stdin: "{{ kerberos_master_pass }}"
creates: "/var/kerberos/krb5kdc/.k5.{{ kerberos_realm }}"
no_log: true