Add LDAP client config and enable pam_umask.

This commit is contained in:
Andreas B. Mundt 2019-12-13 18:41:34 +01:00
parent 98b8d5d6ff
commit 572dd5a3b0
2 changed files with 29 additions and 0 deletions

View file

@ -33,6 +33,23 @@
- nfs-common - nfs-common
state: latest state: latest
- name: add URI to ldap.conf
lineinfile:
dest: /etc/ldap/ldap.conf
line: "URI ldap://ldap/"
insertafter: "#URI.*"
- name: add BASE to ldap.conf
lineinfile:
dest: /etc/ldap/ldap.conf
line: "BASE {{ basedn }}"
insertafter: "#BASE.*"
- name: enable pam_umask
lineinfile:
dest: /etc/pam.d/common-session
line: "session optional pam_umask.so usergroups"
## oddjob-mkhomedir works only with sec=sys for the NFSv4 share ## oddjob-mkhomedir works only with sec=sys for the NFSv4 share
- name: install extra packages from stable - name: install extra packages from stable

View file

@ -69,6 +69,18 @@
replace: '\1 ldap' replace: '\1 ldap'
when: not slapd.stat.exists when: not slapd.stat.exists
- name: add URI to ldap.conf
lineinfile:
dest: /etc/ldap/ldap.conf
line: "URI ldapi:///"
insertafter: "#URI.*"
- name: add BASE to ldap.conf
lineinfile:
dest: /etc/ldap/ldap.conf
line: "BASE {{ basedn }}"
insertafter: "#BASE.*"
####################################################################################### #######################################################################################
## Use the admin password saved to file from now on (available also after installation): ## Use the admin password saved to file from now on (available also after installation):
- name: slurp admin password - name: slurp admin password