aboutsummaryrefslogtreecommitdiffstats
path: root/roles/local_homedirs/tasks
diff options
context:
space:
mode:
authorStonewall Jackson <stonewall@sacredheartsc.com>2023-04-18 23:49:21 -0400
committerStonewall Jackson <stonewall@sacredheartsc.com>2023-04-18 23:49:21 -0400
commit63d6f82c5b3436a62b3bd035b70139cfcff683e0 (patch)
tree9ee5786f6d985e2b8abbbc2cea576586d8ab30ef /roles/local_homedirs/tasks
parent8f1961a8aa9f8194368d3a0c761443fd66eb6a10 (diff)
downloadselfhosted-63d6f82c5b3436a62b3bd035b70139cfcff683e0.tar.gz
selfhosted-63d6f82c5b3436a62b3bd035b70139cfcff683e0.zip
local_homedirs: fixes for kwallet
Diffstat (limited to 'roles/local_homedirs/tasks')
-rw-r--r--roles/local_homedirs/tasks/main.yml22
1 files changed, 22 insertions, 0 deletions
diff --git a/roles/local_homedirs/tasks/main.yml b/roles/local_homedirs/tasks/main.yml
index 7e90959..2a5859f 100644
--- a/roles/local_homedirs/tasks/main.yml
+++ b/roles/local_homedirs/tasks/main.yml
@@ -26,6 +26,20 @@
when: local_homedir_sefcontext.changed
tags: selinux
+- name: copy kwallet script
+ copy:
+ src: '{{ local_homedir_kwallet_script[1:] }}'
+ dest: '{{ local_homedir_kwallet_script }}'
+ mode: 0555
+ setype: xdm_unconfined_exec_t
+
+- name: set xdm_unconfined_exec_t sefcontext on kwallet script
+ sefcontext:
+ target: '{{ local_homedir_kwallet_script }}'
+ state: present
+ setype: xdm_unconfined_exec_t
+ tags: selinux
+
- name: copy profile script
copy:
src: etc/profile.d/local-homedirs.sh
@@ -65,6 +79,14 @@
- auth optional pam_env.so conffile={{ local_homedir_pam_env_path }}
when: "'sddm' in ansible_facts.packages"
+- name: modify sddm PAM configuration for kwallet
+ lineinfile:
+ path: /etc/pam.d/sddm
+ line: auth optional pam_exec.so {{ local_homedir_kwallet_script }}
+ insertafter: auth\s+optional\s+pam_kwallet\.so$
+ state: present
+ when: "'sddm' in ansible_facts.packages"
+
- name: modify pam configs for sshd
lineinfile:
path: /etc/pam.d/sshd