diff --git a/ldap/manifests/init.pp b/ldap/manifests/init.pp index 73b2505..3c21bf5 100644 --- a/ldap/manifests/init.pp +++ b/ldap/manifests/init.pp @@ -125,59 +125,6 @@ class ldap::auth inherits ldap::client { "get ssl != on", ], } } - Debian: { - package {[ "libnss-ldap", - "libpam-ldap" ]: - ensure => installed, - } -## Debian lacks some lenses. nss-ldap-conf and pam_ldap-conf needs corresponding files -## to /usr/share/augeas/lenses/dist/spacevars.aug. More info at: -## https://github.com/jwm/augeas/commit/8f768f45779048cbd95b5b7d71682b808d41bfd3 -## There isn't lens for nsswitch.conf either. nss-ldap-conf and pam_ldap-conf are tested, nsswitch isn't. -# augeas { "nss-ldap-conf": -# context => "/files/etc/libnss-ldap.conf", -# changes => [ "set uri '${ldap_uri}'", -# "set base ${ldap_basedn}", -# "set nss_paged_results yes", -# "set pam_password exop", -# "rm rootbinddn", -# "set ssl on", ], -# onlyif => [ "get uri != '${ldap_uri}'", -# "get base != ${ldap_basedn}", -# "get nss_paged_results != yes", -# "get pam_password != exop", -# "get rootbinddn == 'cn=manager,dc=example,dc=net'", -# "get ssl != on", ], -# require => Package["libnss-ldap"], -# } -# augeas { "pam_ldap-conf": -# context => "/files/etc/pam_ldap.conf", -# changes => [ "set uri '${ldap_uri}'", -# "set base ${ldap_basedn}", -# "set nss_paged_results yes", -# "set pam_password exop", -# "rm rootbinddn", -# "set ssl on", ], -# onlyif => [ "get uri != '${ldap_uri}'", -# "get base != ${ldap_basedn}", -# "get nss_paged_results != yes", -# "get pam_password != exop", -# "get rootbinddn == 'cn=manager,dc=example,dc=net'", -# "get ssl != on", ], -# require => Package["libpam-ldap"], -# } -# augeas { "nsswitch-conf": -# context => "/files/etc/nsswitch.conf", -# changes => [ "set passwd: 'files ldap'", -# "set group: 'files ldap'", -# "set shadow: 'files ldap'", ], -# onlyif => [ "get passwd: != 'files ldap'", -# "get group: != 'files ldap'", -# "get shadow: != 'files ldap'", ], -# require => [ Augeas["pam_ldap-conf"], -# Augeas["nss-ldap-conf"], ], -# } - } OpenBSD: { if ! $ldap_login_umask { $ldap_login_umask = "077"