mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-25 16:31:08 -06:00
2da6d6e746
A forwardable ticket is still required but we no longer need to send the TGT to the IPA server. A new flag, --delegate, is available if the old behavior is required. Set the minimum n-v-r for mod_auth_kerb and krb5-server to pick up needed patches for S4U2Proxy to work. https://fedorahosted.org/freeipa/ticket/1098 https://fedorahosted.org/freeipa/ticket/2246
406 lines
8.8 KiB
Plaintext
406 lines
8.8 KiB
Plaintext
dn: cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: accounts
|
|
|
|
dn: cn=users,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: users
|
|
|
|
dn: cn=groups,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: groups
|
|
|
|
dn: cn=services,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: services
|
|
|
|
dn: cn=computers,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: computers
|
|
|
|
dn: cn=hostgroups,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: hostgroups
|
|
|
|
dn: cn=alt,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
cn: alt
|
|
|
|
dn: cn=ng,cn=alt,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
cn: ng
|
|
|
|
dn: cn=automount,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
cn: automount
|
|
|
|
dn: cn=default,cn=automount,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
cn: default
|
|
|
|
dn: automountmapname=auto.master,cn=default,cn=automount,$SUFFIX
|
|
changetype: add
|
|
objectClass: automountMap
|
|
automountMapName: auto.master
|
|
|
|
dn: automountmapname=auto.direct,cn=default,cn=automount,$SUFFIX
|
|
changetype: add
|
|
objectClass: automountMap
|
|
automountMapName: auto.direct
|
|
|
|
dn: description=/- auto.direct,automountmapname=auto.master,cn=default,cn=automount,$SUFFIX
|
|
changetype: add
|
|
objectClass: automount
|
|
automountKey: /-
|
|
automountInformation: auto.direct
|
|
description: /- auto.direct
|
|
|
|
dn: cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: hbac
|
|
|
|
dn: cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: hbacservices
|
|
|
|
dn: cn=hbacservicegroups,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: hbacservicegroups
|
|
|
|
dn: cn=sudo,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: sudo
|
|
|
|
dn: cn=sudocmds,cn=sudo,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: sudocmds
|
|
|
|
dn: cn=sudocmdgroups,cn=sudo,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: sudocmdgroups
|
|
|
|
dn: cn=sudorules,cn=sudo,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: sudorules
|
|
|
|
dn: cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: etc
|
|
|
|
dn: cn=sysaccounts,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: sysaccounts
|
|
|
|
dn: cn=entitlements,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: entitlements
|
|
|
|
dn: cn=ipa,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: ipa
|
|
|
|
dn: cn=masters,cn=ipa,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: masters
|
|
|
|
dn: cn=replicas,cn=ipa,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: replicas
|
|
|
|
dn: cn=dna,cn=ipa,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: dna
|
|
|
|
dn: cn=posix-ids,cn=dna,cn=ipa,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: posix-ids
|
|
|
|
dn: cn=s4u2proxy,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
cn: s4u2proxy
|
|
|
|
dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: ipaKrb5DelegationACL
|
|
objectClass: groupOfPrincipals
|
|
objectClass: top
|
|
cn: ipa-http-delegation
|
|
memberPrincipal: HTTP/$HOST@$REALM
|
|
ipaAllowedTarget: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX
|
|
|
|
dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: groupOfPrincipals
|
|
objectClass: top
|
|
cn: ipa-ldap-delegation-targets
|
|
memberPrincipal: ldap/$HOST@$REALM
|
|
|
|
dn: uid=admin,cn=users,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: person
|
|
objectClass: posixaccount
|
|
objectClass: krbprincipalaux
|
|
objectClass: krbticketpolicyaux
|
|
objectClass: inetuser
|
|
objectClass: ipaobject
|
|
objectClass: ipasshuser
|
|
uid: admin
|
|
krbPrincipalName: admin@$REALM
|
|
cn: Administrator
|
|
sn: Administrator
|
|
uidNumber: $IDSTART
|
|
gidNumber: $IDSTART
|
|
homeDirectory: /home/admin
|
|
loginShell: /bin/bash
|
|
gecos: Administrator
|
|
nsAccountLock: FALSE
|
|
ipaUniqueID: autogenerate
|
|
|
|
dn: cn=admins,cn=groups,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: groupofnames
|
|
objectClass: posixgroup
|
|
objectClass: ipausergroup
|
|
objectClass: ipaobject
|
|
cn: admins
|
|
description: Account administrators group
|
|
gidNumber: $IDSTART
|
|
member: uid=admin,cn=users,cn=accounts,$SUFFIX
|
|
nsAccountLock: FALSE
|
|
ipaUniqueID: autogenerate
|
|
|
|
dn: cn=ipausers,cn=groups,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: groupofnames
|
|
objectClass: nestedgroup
|
|
objectClass: ipausergroup
|
|
objectClass: posixgroup
|
|
objectClass: ipaobject
|
|
gidNumber: eval($IDSTART+1)
|
|
description: Default group for all users
|
|
cn: ipausers
|
|
ipaUniqueID: autogenerate
|
|
|
|
dn: cn=editors,cn=groups,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: groupofnames
|
|
objectClass: posixgroup
|
|
objectClass: ipausergroup
|
|
objectClass: ipaobject
|
|
gidNumber: eval($IDSTART+2)
|
|
description: Limited admins who can edit other users
|
|
cn: editors
|
|
ipaUniqueID: autogenerate
|
|
|
|
dn: cn=sshd,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: sshd
|
|
description: sshd
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=ftp,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: ftp
|
|
description: ftp
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=su,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: su
|
|
description: su
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=login,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: login
|
|
description: login
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=su-l,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: su-l
|
|
description: su with login shell
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=sudo,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: sudo
|
|
description: sudo
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=sudo-i,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: sudo-i
|
|
description: sudo-i
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=gdm,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: gdm
|
|
description: gdm
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=gdm-password,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: gdm-password
|
|
description: gdm-password
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=kdm,cn=hbacservices,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectclass: ipahbacservice
|
|
objectclass: ipaobject
|
|
cn: kdm
|
|
description: kdm
|
|
ipauniqueid:autogenerate
|
|
|
|
dn: cn=Sudo,cn=hbacservicegroups,cn=hbac,$SUFFIX
|
|
changetype: add
|
|
objectClass: ipaobject
|
|
objectClass: ipahbacservicegroup
|
|
objectClass: nestedGroup
|
|
objectClass: groupOfNames
|
|
objectClass: top
|
|
cn: Sudo
|
|
ipauniqueid:autogenerate
|
|
description: Default group of Sudo related services
|
|
member: cn=sudo,cn=hbacservices,cn=hbac,$SUFFIX
|
|
member: cn=sudo-i,cn=hbacservices,cn=hbac,$SUFFIX
|
|
|
|
dn: cn=ipaConfig,cn=etc,$SUFFIX
|
|
changetype: add
|
|
objectClass: nsContainer
|
|
objectClass: top
|
|
objectClass: ipaGuiConfig
|
|
objectClass: ipaConfigObject
|
|
ipaUserSearchFields: uid,givenname,sn,telephonenumber,ou,title
|
|
ipaGroupSearchFields: cn,description
|
|
ipaSearchTimeLimit: 2
|
|
ipaSearchRecordsLimit: 100
|
|
ipaHomesRootDir: /home
|
|
ipaDefaultLoginShell: /bin/sh
|
|
ipaDefaultPrimaryGroup: ipausers
|
|
ipaMaxUsernameLength: 32
|
|
ipaPwdExpAdvNotify: 4
|
|
ipaGroupObjectClasses: top
|
|
ipaGroupObjectClasses: groupofnames
|
|
ipaGroupObjectClasses: nestedgroup
|
|
ipaGroupObjectClasses: ipausergroup
|
|
ipaGroupObjectClasses: ipaobject
|
|
ipaUserObjectClasses: top
|
|
ipaUserObjectClasses: person
|
|
ipaUserObjectClasses: organizationalperson
|
|
ipaUserObjectClasses: inetorgperson
|
|
ipaUserObjectClasses: inetuser
|
|
ipaUserObjectClasses: posixaccount
|
|
ipaUserObjectClasses: krbprincipalaux
|
|
ipaUserObjectClasses: krbticketpolicyaux
|
|
ipaUserObjectClasses: ipaobject
|
|
ipaUserObjectClasses: ipasshuser
|
|
ipaDefaultEmailDomain: $DOMAIN
|
|
ipaMigrationEnabled: FALSE
|
|
ipaConfigString: AllowNThash
|
|
ipaSELinuxUserMapOrder: guest_u:s0$$xguest_u:s0$$user_u:s0-s0:c0.c1023$$staff_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023
|
|
ipaSELinuxUserMapDefault: guest_u:s0
|
|
|
|
dn: cn=cosTemplates,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
objectclass: top
|
|
objectclass: nsContainer
|
|
cn: cosTemplates
|
|
|
|
# templates for this cos definition are managed by the pwpolicy plugin
|
|
dn: cn=Password Policy,cn=accounts,$SUFFIX
|
|
changetype: add
|
|
description: Password Policy based on group membership
|
|
objectClass: top
|
|
objectClass: ldapsubentry
|
|
objectClass: cosSuperDefinition
|
|
objectClass: cosClassicDefinition
|
|
cosTemplateDn: cn=cosTemplates,cn=accounts,$SUFFIX
|
|
cosAttribute: krbPwdPolicyReference override
|
|
cosSpecifier: memberOf
|
|
|
|
dn: cn=selinux,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: selinux
|
|
|
|
dn: cn=usermap,cn=selinux,$SUFFIX
|
|
changetype: add
|
|
objectClass: top
|
|
objectClass: nsContainer
|
|
cn: usermap
|
|
|