summaryrefslogtreecommitdiffstats
path: root/server
diff options
context:
space:
mode:
authorSimon Rettberg2014-01-21 13:39:26 +0100
committerSimon Rettberg2014-01-21 13:39:26 +0100
commit35393114bfc88490aaf8e9eac4f6808dc849844e (patch)
tree0f901e5aca2072b0f243aae183f533a70b60eb0a /server
parent[rfs-stage32] Append stage4 at the end of the aufs stack again and just copy ... (diff)
downloadtm-scripts-35393114bfc88490aaf8e9eac4f6808dc849844e.tar.gz
tm-scripts-35393114bfc88490aaf8e9eac4f6808dc849844e.tar.xz
tm-scripts-35393114bfc88490aaf8e9eac4f6808dc849844e.zip
<freiburg config> Add nslcd startup
Diffstat (limited to 'server')
l---------[-rw-r--r--]server/modules/pam-freiburg/etc/ldap/ldap.conf8
-rw-r--r--server/modules/pam-freiburg/etc/nslcd.conf8
l---------server/modules/pam-freiburg/etc/systemd/system/getty.target.wants/nslcd.service1
3 files changed, 10 insertions, 7 deletions
diff --git a/server/modules/pam-freiburg/etc/ldap/ldap.conf b/server/modules/pam-freiburg/etc/ldap/ldap.conf
index 809065cc..6050948a 100644..120000
--- a/server/modules/pam-freiburg/etc/ldap/ldap.conf
+++ b/server/modules/pam-freiburg/etc/ldap/ldap.conf
@@ -1,7 +1 @@
-URI ldaps://bv1.ruf.uni-freiburg.de ldaps://bv2.ruf.uni-freiburg.de ldaps://bv3.ruf.uni-freiburg.de
-BASE ou=people,dc=uni-freiburg,dc=de
-TLS_REQCERT allow
-nss_base_passwd ou=people,dc=uni-freiburg,dc=de?one?rufdienst=ldap*)(&(rufclienthome=*)(rufstatus=enabled)
-nss_base_group ou=group,dc=uni-freiburg,dc=de?one
-nss_map_attribute homeDirectory rufClientHome
-
+../ldap.conf \ No newline at end of file
diff --git a/server/modules/pam-freiburg/etc/nslcd.conf b/server/modules/pam-freiburg/etc/nslcd.conf
new file mode 100644
index 00000000..e98e1675
--- /dev/null
+++ b/server/modules/pam-freiburg/etc/nslcd.conf
@@ -0,0 +1,8 @@
+# Cannot be a symlink to ldap.conf, as nslcd refuses to start if there are unknown options in this file...
+URI ldaps://bv1.ruf.uni-freiburg.de ldaps://bv2.ruf.uni-freiburg.de ldaps://bv3.ruf.uni-freiburg.de
+BASE ou=people,dc=uni-freiburg,dc=de
+BIND_TIMELIMIT 5
+TIMELIMIT 10
+TLS_REQCERT allow
+
+nss_initgroups_ignoreusers avahi,avahi-autoipd,backup,bin,colord,daemon,distccd,games,git,gnats,hplip,irc,kdm,kernoops,libuuid,lightdm,list,lp,mail,man,messagebus,news,ntp,proxy,pulse,root,rtkit,saned,speech-dispatcher,sshd,statd,sync,sys,syslog,usbmux,uucp,whoopsie,www-data
diff --git a/server/modules/pam-freiburg/etc/systemd/system/getty.target.wants/nslcd.service b/server/modules/pam-freiburg/etc/systemd/system/getty.target.wants/nslcd.service
new file mode 120000
index 00000000..17c13d96
--- /dev/null
+++ b/server/modules/pam-freiburg/etc/systemd/system/getty.target.wants/nslcd.service
@@ -0,0 +1 @@
+../nslcd.service \ No newline at end of file