/[adm]/puppet/modules/pam/manifests/init.pp
ViewVC logotype

Contents of /puppet/modules/pam/manifests/init.pp

Parent Directory Parent Directory | Revision Log Revision Log


Revision 785 - (show annotations) (download)
Thu Jan 13 19:41:24 2011 UTC (13 years, 3 months ago) by misc
File size: 1202 byte(s)
- allow to set access without forcing the restricted shell ( should
be done by openssh in fact, but that's easier to do like this for now )
1 class pam {
2
3 class base {
4 package { ["pam_ldap","nss_ldap","nscd"]:
5 ensure => installed,
6 }
7
8 service { nscd:
9 ensure => running,
10 path => '/etc/init.d/nscd',
11 }
12
13 file { "system-auth":
14 path => "/etc/pam.d/system-auth",
15 owner => root,
16 group => root,
17 mode => 644,
18 content => template("pam/system-auth")
19 }
20
21 file { "nsswitch.conf":
22 path => "/etc/nsswitch.conf",
23 owner => root,
24 group => root,
25 mode => 644,
26 content => template("pam/nsswitch.conf")
27 }
28
29 $ldap_password = extlookup("${fqdn}_ldap_password",'x')
30 file { "ldap.secret":
31 path => "/etc/ldap.secret",
32 owner => root,
33 group => root,
34 mode => 600,
35 content => $ldap_password
36 }
37
38 file { "ldap.conf":
39 path => "/etc/ldap.conf",
40 owner => root,
41 group => root,
42 mode => 644,
43 content => template("pam/ldap.conf")
44 }
45 }
46
47 define multiple_ldap_access($access_classes,$restricted_shell = false) {
48 if $restricted_shell {
49 include restricted_shell
50 }
51 include base
52 }
53 }

  ViewVC Help
Powered by ViewVC 1.1.30