2018-12-01 00:31:11 +00:00
|
|
|
---
|
|
|
|
- block:
|
|
|
|
- name: Install required packages
|
|
|
|
package:
|
|
|
|
name: "{{ item }}"
|
|
|
|
state: present
|
|
|
|
with_items:
|
|
|
|
- openldap-servers
|
|
|
|
- openldap-clients
|
|
|
|
|
2018-12-01 14:51:13 +00:00
|
|
|
- name: Ensure base directories exists at '{{ ldap_proxy_base_dir }}'
|
|
|
|
file:
|
|
|
|
path: "{{ item }}"
|
|
|
|
state: directory
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
with_items:
|
|
|
|
- "{{ ldap_proxy_base_dir }}"
|
|
|
|
- "{{ ldap_proxy_acl_file | dirname }}"
|
|
|
|
|
2018-12-01 00:31:11 +00:00
|
|
|
- name: Deploy environment file
|
|
|
|
template:
|
|
|
|
src: "etc/sysconfig/slapd.j2"
|
|
|
|
dest: "/etc/sysconfig/slapd"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0644
|
|
|
|
notify: __slapd_restart
|
|
|
|
|
2018-12-01 14:51:13 +00:00
|
|
|
- name: Deploy config file to '{{ ldap_proxy_base_dir }}/slapd.conf'
|
2018-12-01 00:31:11 +00:00
|
|
|
template:
|
|
|
|
src: "etc/openldap/slapd.conf.j2"
|
2018-12-01 14:51:13 +00:00
|
|
|
dest: "{{ ldap_proxy_base_dir }}/slapd.conf"
|
2018-12-01 00:31:11 +00:00
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0644
|
|
|
|
notify: __slapd_restart
|
2018-12-01 01:03:29 +00:00
|
|
|
|
2018-12-01 14:51:13 +00:00
|
|
|
- name: Deploy access control file '{{ ldap_proxy_acl_file }}'
|
2018-12-01 14:37:47 +00:00
|
|
|
template:
|
|
|
|
src: "etc/openldap/slapd.access.j2"
|
2018-12-01 14:51:13 +00:00
|
|
|
dest: "{{ ldap_proxy_acl_file }}"
|
2018-12-01 14:37:47 +00:00
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0644
|
|
|
|
notify: __slapd_restart
|
|
|
|
|
2018-12-12 21:08:46 +00:00
|
|
|
- name: Deploy custom ldap schemas
|
2018-12-12 21:23:54 +00:00
|
|
|
copy:
|
2018-12-12 21:08:46 +00:00
|
|
|
src: "{{ item }}"
|
|
|
|
dest: "/etc/openldap/schema/{{ item | basename }}"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0644
|
|
|
|
with_items: "{{ ldap_proxy_custom_schemas }}"
|
|
|
|
notify: __slapd_restart
|
|
|
|
|
2018-12-01 01:03:29 +00:00
|
|
|
- name: Open ports in iptables
|
|
|
|
iptables_raw:
|
|
|
|
name: "{{ item.name }}"
|
|
|
|
rules: "{{ item.rules }}"
|
|
|
|
state: "{{ item.state }}"
|
|
|
|
weight: "{{ item.weight|default(omit) }}"
|
|
|
|
table: "{{ item.table|default(omit) }}"
|
|
|
|
with_items: "{{ ldap_proxy_open_ports }}"
|
|
|
|
loop_control:
|
|
|
|
label: "{{item.name}}"
|
|
|
|
when: ldap_proxy_iptables_enabled
|
2018-12-01 00:31:11 +00:00
|
|
|
become: True
|
|
|
|
become_user: root
|