nounou → _nounou
parent
385650b951
commit
eacbef7917
|
@ -6,7 +6,7 @@ interfaces:
|
||||||
|
|
||||||
loc_re2o:
|
loc_re2o:
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
version: master_freeradius_python3
|
version: master_freeradius_python3
|
||||||
settings_local_owner: www-data
|
settings_local_owner: www-data
|
||||||
settings_local_group: nounou
|
settings_local_group: _nounou
|
||||||
|
|
|
@ -22,7 +22,7 @@ loc_keepalived:
|
||||||
|
|
||||||
loc_re2o:
|
loc_re2o:
|
||||||
owner: freerad
|
owner: freerad
|
||||||
group: nounou
|
group: _nounou
|
||||||
version: master_freeradius_python3
|
version: master_freeradius_python3
|
||||||
settings_local_owner: freerad
|
settings_local_owner: freerad
|
||||||
settings_local_group: nounou
|
settings_local_group: _nounou
|
||||||
|
|
|
@ -5,13 +5,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: "2775"
|
mode: "2775"
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for scripts directory
|
- name: Set ACL for scripts directory
|
||||||
acl:
|
acl:
|
||||||
path: /usr/scripts
|
path: /usr/scripts
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -17,13 +17,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: '2775'
|
mode: '2775'
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for dns directory
|
- name: Set ACL for dns directory
|
||||||
acl:
|
acl:
|
||||||
path: /var/local/dns
|
path: /var/local/dns
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -17,13 +17,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: '2775'
|
mode: '2775'
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for firewall directory
|
- name: Set ACL for firewall directory
|
||||||
acl:
|
acl:
|
||||||
path: /var/local/firewall
|
path: /var/local/firewall
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -16,13 +16,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: '2775'
|
mode: '2775'
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for home directory
|
- name: Set ACL for home directory
|
||||||
acl:
|
acl:
|
||||||
path: /var/local/home
|
path: /var/local/home
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -5,13 +5,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: '2775'
|
mode: '2775'
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for re2o-dhcp directory
|
- name: Set ACL for re2o-dhcp directory
|
||||||
acl:
|
acl:
|
||||||
path: /var/local/re2o-services/dhcp
|
path: /var/local/re2o-services/dhcp
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -5,13 +5,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: '2775'
|
mode: '2775'
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for re2o-mail-server directory
|
- name: Set ACL for re2o-mail-server directory
|
||||||
acl:
|
acl:
|
||||||
path: /var/local/re2o-services/mail-server
|
path: /var/local/re2o-services/mail-server
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -5,13 +5,13 @@
|
||||||
state: directory
|
state: directory
|
||||||
mode: '2775'
|
mode: '2775'
|
||||||
owner: root
|
owner: root
|
||||||
group: nounou
|
group: _nounou
|
||||||
|
|
||||||
- name: Set ACL for re2o-notif-users directory
|
- name: Set ACL for re2o-notif-users directory
|
||||||
acl:
|
acl:
|
||||||
path: /var/local/re2o-services/notif-users
|
path: /var/local/re2o-services/notif-users
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -41,7 +41,7 @@
|
||||||
acl:
|
acl:
|
||||||
path: /var/www/re2o
|
path: /var/www/re2o
|
||||||
default: true
|
default: true
|
||||||
entity: nounou
|
entity: _nounou
|
||||||
etype: group
|
etype: group
|
||||||
permissions: rwx
|
permissions: rwx
|
||||||
state: query
|
state: query
|
||||||
|
|
|
@ -162,13 +162,13 @@ overlay syncprov
|
||||||
access to attrs=userPassword,shadowLastChange
|
access to attrs=userPassword,shadowLastChange
|
||||||
by anonymous auth
|
by anonymous auth
|
||||||
by self write
|
by self write
|
||||||
by set="[cn=nounou,ou=group,dc=crans,dc=org]/memberUid & user/uid" write
|
by set="[cn=_nounou,ou=group,dc=crans,dc=org]/memberUid & user/uid" write
|
||||||
by dn="cn=replicator,dc=crans,dc=org" read
|
by dn="cn=replicator,dc=crans,dc=org" read
|
||||||
by * none
|
by * none
|
||||||
|
|
||||||
access to attrs=loginShell,mail,telephoneNumber
|
access to attrs=loginShell,mail,telephoneNumber
|
||||||
by self write
|
by self write
|
||||||
by set="[cn=nounou,ou=group,dc=crans,dc=org]/memberUid & user/uid" write
|
by set="[cn=_nounou,ou=group,dc=crans,dc=org]/memberUid & user/uid" write
|
||||||
by dn="cn=replicator,dc=crans,dc=org" read
|
by dn="cn=replicator,dc=crans,dc=org" read
|
||||||
by * read
|
by * read
|
||||||
|
|
||||||
|
@ -186,7 +186,7 @@ access to dn.base="" by * read
|
||||||
# The admin dn has full write access, everyone else
|
# The admin dn has full write access, everyone else
|
||||||
# can read everything.
|
# can read everything.
|
||||||
access to *
|
access to *
|
||||||
by set="[cn=nounou,ou=group,dc=crans,dc=org]/memberUid & user/uid" write
|
by set="[cn=_nounou,ou=group,dc=crans,dc=org]/memberUid & user/uid" write
|
||||||
by dn="cn=replicator,dc=crans,dc=org" read
|
by dn="cn=replicator,dc=crans,dc=org" read
|
||||||
by * read
|
by * read
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
|
@ -1,3 +1,3 @@
|
||||||
{{ ansible_header | comment }}
|
{{ ansible_header | comment }}
|
||||||
# Group privilege specification
|
# Group privilege specification
|
||||||
%nounou ALL=(ALL:ALL) ALL
|
NOUNOU ALL=(ALL:ALL) ALL
|
||||||
|
|
|
@ -7,8 +7,8 @@ Defaults mail_badpass
|
||||||
Defaults secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
Defaults secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
||||||
|
|
||||||
# Host alias specification
|
# Host alias specification
|
||||||
User_Alias USERS= %user
|
User_Alias USERS= %_user
|
||||||
User_Alias NOUNOUS= %nounou
|
User_Alias NOUNOUS= %_nounou
|
||||||
|
|
||||||
# User alias specification
|
# User alias specification
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue