From 77b42f82b26299a525052c5dcebcbaaef3cf1d50 Mon Sep 17 00:00:00 2001 From: Jonas Gunz Date: Thu, 9 Sep 2021 21:57:57 +0200 Subject: add sssd --- roles/sssd/tasks/main.yml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 roles/sssd/tasks/main.yml (limited to 'roles/sssd/tasks') diff --git a/roles/sssd/tasks/main.yml b/roles/sssd/tasks/main.yml new file mode 100644 index 0000000..b50cac6 --- /dev/null +++ b/roles/sssd/tasks/main.yml @@ -0,0 +1,38 @@ +--- +- name: Install packages + apt: + name: + - sssd + - libpam-sss + - libnss-sss + update_cache: yes + become: yes + +- name: Install SSSD Config file + template: + src: sssd.conf.j2 + dest: /etc/sssd/sssd.conf + mode: '600' + become: yes + notify: Restart sssd + +- name: Create LDAP Config dir + file: + path: /etc/ldap + state: directory + become: yes + +- name: Install ldap.conf + copy: + content: 'TLS_CACERT /etc/ssl/certs/ca-certificates.crt' + dest: /etc/ldap/ldap.conf + become: yes + notify: Restart sssd + +- name: Auto-create Homedir + lineinfile: + path: /etc/pam.d/common-session + regex: '^session required pam_mkhomedir\.so' + line: 'session required pam_mkhomedir.so skel=/etc/skel/ umask=0022' + insertafter: '^session optional pam_sss\.so' + become: yes -- cgit v1.2.3