2019-02-05 08:35:45 +01:00
|
|
|
---
|
|
|
|
# Install LDAP client packages
|
|
|
|
- name: Install LDAP client packages
|
|
|
|
apt:
|
|
|
|
name: "{{ item }}"
|
|
|
|
state: present
|
2019-03-03 09:00:29 +01:00
|
|
|
update_cache: true
|
2019-02-05 08:35:45 +01:00
|
|
|
with_items:
|
|
|
|
- nslcd
|
|
|
|
- libnss-ldapd
|
|
|
|
- libpam-ldapd
|
2019-03-03 19:28:57 +01:00
|
|
|
register: apt_result
|
|
|
|
retries: 3
|
|
|
|
until: apt_result is succeeded
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# Reduce LDAP load
|
|
|
|
# For the moment it is broken on Stretch when using PHP7.3
|
2019-03-02 13:31:51 +01:00
|
|
|
# - name: Install LDAP cache package
|
|
|
|
# apt:
|
|
|
|
# name: nscd
|
|
|
|
# state: present
|
2019-03-03 09:00:29 +01:00
|
|
|
# update_cache: true
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# Configure /etc/nslcd.conf
|
|
|
|
- name: Configure nslcd LDAP credentials
|
|
|
|
template:
|
|
|
|
src: nslcd.conf.j2
|
|
|
|
dest: /etc/nslcd.conf
|
|
|
|
mode: 0600
|
2019-02-19 10:49:18 +01:00
|
|
|
notify: Restart nslcd service
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# Configure /etc/nsswitch.conf
|
|
|
|
- name: Configure NSS to use LDAP
|
|
|
|
lineinfile:
|
|
|
|
dest: /etc/nsswitch.conf
|
|
|
|
regexp: "^{{ item.key }}:"
|
|
|
|
line: "{{ item.value }}"
|
|
|
|
with_dict:
|
2019-03-02 12:16:43 +01:00
|
|
|
passwd: 'passwd: files ldap'
|
|
|
|
group: 'group: files ldap'
|
|
|
|
shadow: 'shadow: files ldap'
|
2019-02-05 08:35:45 +01:00
|
|
|
sudoers: 'sudoers: files ldap'
|
2019-02-19 10:49:18 +01:00
|
|
|
notify: Restart nslcd service
|