diff options
author | Romain Gonçalves <me@rgoncalves.se> | 2021-07-29 17:00:20 +0200 |
---|---|---|
committer | Romain Gonçalves <me@rgoncalves.se> | 2021-07-29 17:00:20 +0200 |
commit | b232b894c3cbe087c8d504e91637dcf62199eed1 (patch) | |
tree | ea72a7d1a7f63c6425ee46785e1cec924351b2c3 /roles/ldapd | |
parent | 22126073344e60c405d086df37b64da0c6d3c086 (diff) | |
download | infrastructure-b232b894c3cbe087c8d504e91637dcf62199eed1.tar.gz |
Bump to third revision of homelab
Diffstat (limited to 'roles/ldapd')
-rw-r--r-- | roles/ldapd/defaults/main.yml | 3 | ||||
-rw-r--r-- | roles/ldapd/tasks/main.yml | 22 | ||||
-rw-r--r-- | roles/ldapd/templates/etc-ldapd.conf.j2 | 23 |
3 files changed, 48 insertions, 0 deletions
diff --git a/roles/ldapd/defaults/main.yml b/roles/ldapd/defaults/main.yml new file mode 100644 index 0000000..3e86bfc --- /dev/null +++ b/roles/ldapd/defaults/main.yml @@ -0,0 +1,3 @@ +ldapd_user: _ldapd +ldapd_group: _ldapd +ldapd_dir: /data/ldap diff --git a/roles/ldapd/tasks/main.yml b/roles/ldapd/tasks/main.yml new file mode 100644 index 0000000..2866ba8 --- /dev/null +++ b/roles/ldapd/tasks/main.yml @@ -0,0 +1,22 @@ +- name: ensure ldapd db dir exists + file: + path: "{{ ldapd_dir }}" + owner: "{{ ldapd_user }}" + group: "{{ ldapd_group }}" + state: directory + mode: "0700" + +- name: generate ldapd configuration + template: + src: etc-ldapd.conf.j2 + dest: /etc/ldapd.conf + owner: "0" + group: "0" + mode: "0600" + +- name: enable and start ldapd + service: + name: ldapd + state: restarted + enabled: true + args: -r "{{ ldapd_dir }}" diff --git a/roles/ldapd/templates/etc-ldapd.conf.j2 b/roles/ldapd/templates/etc-ldapd.conf.j2 new file mode 100644 index 0000000..e08fa9c --- /dev/null +++ b/roles/ldapd/templates/etc-ldapd.conf.j2 @@ -0,0 +1,23 @@ + +# ldapd configuration +# manage by Ansible + +schema "/etc/ldap/core.schema" +schema "/etc/ldap/inetorgperson.schema" +schema "/etc/ldap/nis.schema" +schema "/etc/ldap/bsd.schema" + +{% for interface in ansible_interfaces %} +{% if "pflog" not in interface %} +listen on {{ interface }} +{% endif %} +{% endfor %} +listen on "/var/run/ldapi" + +namespace "dc=domain" { + rootdn "cn=admin,dc=domain" + + deny read,write access to subtree root by any + allow read,write access to subtree root by self + +} |