Implement Kerberos KDC-LDAP server role.

This commit is contained in:
Andreas B. Mundt 2019-11-17 11:40:22 +01:00
parent 0597d178e0
commit 18067d8df3
8 changed files with 208 additions and 2 deletions

View file

@ -0,0 +1,4 @@
## access controls for the Kerberos KDC
root/admin@{{ ldap_domain | upper }} *
*@{{ ldap_domain | upper }} cil
*/*@{{ ldap_domain | upper }} i

View file

@ -0,0 +1,15 @@
[kdcdefaults]
kdc_ports = 750,88
[realms]
{{ ldap_domain | upper }} = {
admin_keytab = FILE:/etc/krb5kdc/kadm5.keytab
acl_file = /etc/krb5kdc/kadm5.acl
key_stash_file = /etc/krb5kdc/stash
kdc_ports = 750,88
max_life = 10h 0m 0s
max_renewable_life = 7d 0h 0m 0s
master_key_type = des3-hmac-sha1
#supported_enctypes = aes256-cts:normal aes128-cts:normal
default_principal_flags = +preauth
}

View file

@ -0,0 +1,26 @@
[libdefaults]
default_realm = {{ ldap_domain | upper }}
[realms]
{{ ldap_domain | upper }} = {
kdc = {{ ansible_hostname }}
admin_server = {{ ansible_hostname }}
database_module = LDAP
}
[domain_realm]
.{{ ldap_domain }} = {{ ldap_domain | upper }}
{{ ldap_domain }} = {{ ldap_domain | upper }}
[dbdefaults]
ldap_kerberos_container_dn = cn=kerberos,{{ basedn }}
[dbmodules]
LDAP = {
db_library = kldap
ldap_kdc_dn = cn=kdc,cn=kerberos,{{ basedn }}
ldap_kadmind_dn = cn=kadmin,cn=kerberos,{{ basedn }}
ldap_service_password_file = /etc/krb5kdc/service.keyfile
ldap_servers = ldapi:///
ldap_conns_per_server = 5
}