You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
59 lines
1.7 KiB
59 lines
1.7 KiB
5 years ago
|
[sssd]
|
||
|
services = nss, pam, pac
|
||
|
config_file_version = 2
|
||
|
domains = {{ ad_realm | upper }}{% for domain in ad_trusted_domains %}, {{ domain.name | upper }}{% endfor %}
|
||
|
|
||
|
default_domain_suffix = {{ ad_realm | upper }}
|
||
|
|
||
|
[nss]
|
||
|
shell_fallback = /bin/false
|
||
|
|
||
|
[pam]
|
||
|
|
||
|
[domain/{{ ad_realm | upper }}]
|
||
|
id_provider = ad
|
||
|
access_provider = ad
|
||
|
ad_hostname = {{ ansible_hostname }}.{{ ad_realm | lower }}
|
||
|
fallback_homedir = /home/%d/%u
|
||
|
default_shell = /bin/false
|
||
|
cache_credentials = true
|
||
|
krb5_store_password_if_offline = true
|
||
|
ad_access_filter = {{ ad_access_filter }}
|
||
|
{% if ad_ldap_user_search_base is defined %}
|
||
|
ldap_user_search_base = {{ ad_ldap_user_search_base }}
|
||
|
{% endif %}
|
||
|
{% if ad_ldap_group_search_base is defined %}
|
||
|
ldap_group_search_base = {{ ad_ldap_group_search_base }}
|
||
|
{% endif %}
|
||
|
{% if ad_samba_secrets.stat.exists %}
|
||
|
# Membership password is updated with net ads
|
||
|
ad_maximum_machine_account_password_age = 0
|
||
|
{% endif %}
|
||
|
{% if ad_enumerate %}
|
||
|
enumerate = true
|
||
|
{% endif %}
|
||
|
|
||
|
{% for domain in ad_trusted_domains %}
|
||
|
|
||
|
|
||
|
[domain/{{ domain.name | upper }}]
|
||
|
id_provider = ad
|
||
|
access_provider = ad
|
||
|
fallback_homedir = /home/%d/%u
|
||
|
default_shell = /bin/false
|
||
|
cache_credentials = true
|
||
|
krb5_store_password_if_offline = true
|
||
|
ldap_krb5_keytab = /var/lib/sss/keytabs/{{ domain.name | upper }}.keytab
|
||
|
krb5_keytab = /var/lib/sss/keytabs/{{ domain.name | upper }}.keytab
|
||
|
{% if domain.enumerate %}
|
||
|
enumerate = true
|
||
|
{% endif %}
|
||
|
ad_access_filter = {{ domain.access_filter }}
|
||
|
{% if domain.ldap_user_search_base is defined and domain.ldap_user_search_base %}
|
||
|
ldap_user_search_base = {{ domain.ldap_user_search_base }}
|
||
|
{% endif %}
|
||
|
{% if domain.ldap_group_search_base is defined and domain.ldap_group_search_base %}
|
||
|
ldap_group_search_base = {{ domain.ldap_group_search_base }}
|
||
|
{% endif %}
|
||
|
{% endfor %}
|