2019-02-05 08:35:45 +01:00
|
|
|
---
|
|
|
|
# slapd is OpenLDAP server
|
|
|
|
- name: Install LDAP server
|
|
|
|
apt:
|
|
|
|
name: slapd
|
|
|
|
state: present
|
2019-03-03 09:00:29 +01:00
|
|
|
update_cache: true
|
2019-03-03 19:28:57 +01:00
|
|
|
register: apt_result
|
|
|
|
retries: 3
|
|
|
|
until: apt_result is succeeded
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# What is written after is really not a nice way to install a schema
|
|
|
|
# because the LDAP is being flushed away always...
|
|
|
|
# This is a problem in re2o installation method that may be fixed in the future.
|
|
|
|
|
|
|
|
# Much nicer than install_re2o.sh way
|
|
|
|
- name: Build schema
|
|
|
|
template:
|
|
|
|
src: schema.ldiff.j2
|
|
|
|
dest: /etc/ldap/schema.ldiff
|
|
|
|
mode: 0600
|
|
|
|
|
|
|
|
# Downtime!
|
|
|
|
- name: Stop LDAP server
|
2019-02-19 10:49:18 +01:00
|
|
|
service:
|
|
|
|
name: slapd
|
|
|
|
state: stopped
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# Cry a bit
|
|
|
|
- name: Remove old data
|
|
|
|
file: path={{ item }} state=absent
|
|
|
|
with_items:
|
|
|
|
- /etc/ldap/slapd.d
|
|
|
|
- /var/lib/ldap
|
|
|
|
|
|
|
|
# Cry a lot
|
|
|
|
- name: Recreate structure
|
|
|
|
file: path={{ item }} state=directory
|
|
|
|
with_items:
|
|
|
|
- /etc/ldap/slapd.d
|
|
|
|
- /var/lib/ldap
|
|
|
|
|
|
|
|
# Install schema as root
|
|
|
|
# We can't do a `become_user` here
|
|
|
|
- name: Install LDAP schema
|
2019-03-23 19:13:02 +01:00
|
|
|
command: slapadd -n 0 -l /etc/ldap/schema.ldiff -F /etc/ldap/slapd.d
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# then fix permissions
|
|
|
|
- name: Fix permissions
|
|
|
|
file:
|
|
|
|
path: "{{ item }}"
|
|
|
|
owner: openldap
|
|
|
|
group: openldap
|
2019-03-12 17:04:06 +01:00
|
|
|
recurse: true
|
2019-02-05 08:35:45 +01:00
|
|
|
with_items:
|
2019-03-23 19:13:02 +01:00
|
|
|
- /var/lib/ldap
|
|
|
|
- /etc/ldap/slapd.d
|
2019-02-05 08:35:45 +01:00
|
|
|
|
|
|
|
# Save the day
|
|
|
|
- name: Start LDAP server
|
|
|
|
service: name=slapd state=started
|