[sssd] Optional enumerate

certbot_on_virtu
_shirenn 2021-06-21 12:11:16 +02:00
parent b444ba646f
commit df8baa6651
2 changed files with 4 additions and 2 deletions

View File

@ -1,6 +1,7 @@
glob_sssd: glob_sssd:
primary: primary:
domain: tealc.adm.crans.org domain: tealc.adm.crans.org
enumerate: "true"
servers: servers:
- "{{ query('ldap','ip','tealc','adm') | ipv4 | first }}" - "{{ query('ldap','ip','tealc','adm') | ipv4 | first }}"
- "{{ query('ldap','ip','sam','adm') | ipv4 | first }}" - "{{ query('ldap','ip','sam','adm') | ipv4 | first }}"
@ -9,6 +10,7 @@ glob_sssd:
base: "dc=crans,dc=org" base: "dc=crans,dc=org"
secondary: secondary:
domain: re2o-ldap.adm.crans.org domain: re2o-ldap.adm.crans.org
enumerate: "false"
base: "dc=crans,dc=org" base: "dc=crans,dc=org"
bind: bind:
dn: "cn=nslcd,ou=service-users,dc=crans,dc=org" dn: "cn=nslcd,ou=service-users,dc=crans,dc=org"

View File

@ -6,7 +6,7 @@ domains = {{ sssd.primary.domain }}, {{ sssd.secondary.domain }}
[domain/{{ sssd.primary.domain }}] [domain/{{ sssd.primary.domain }}]
ldap_access_filter = (objectClass=posixAccount) ldap_access_filter = (objectClass=posixAccount)
enumerate = true enumerate = {{ sssd.primary.enumerate }}
id_provider = ldap id_provider = ldap
auth_provider = ldap auth_provider = ldap
ldap_uri = ldaps://{{ sssd.primary.domain }} ldap_uri = ldaps://{{ sssd.primary.domain }}
@ -19,7 +19,7 @@ ldap_tls_reqcert = allow
[domain/{{ sssd.secondary.domain }}] [domain/{{ sssd.secondary.domain }}]
ldap_access_filter = (objectClass=posixAccount) ldap_access_filter = (objectClass=posixAccount)
enumerate = true enumerate = {{ sssd.secondary.enumerate }}
id_provider = ldap id_provider = ldap
auth_provider = ldap auth_provider = ldap
ldap_uri = ldaps://{{ sssd.secondary.domain }} ldap_uri = ldaps://{{ sssd.secondary.domain }}