From 0261e875679f1bf63c8d689da7fc7e014597885d Mon Sep 17 00:00:00 2001 From: Stonewall Jackson Date: Sat, 4 Feb 2023 01:23:43 -0500 Subject: initial commit --- roles/freeipa_system_account/defaults/main.yml | 1 + roles/freeipa_system_account/tasks/main.yml | 14 ++++++++++++++ 2 files changed, 15 insertions(+) create mode 100644 roles/freeipa_system_account/defaults/main.yml create mode 100644 roles/freeipa_system_account/tasks/main.yml (limited to 'roles/freeipa_system_account') diff --git a/roles/freeipa_system_account/defaults/main.yml b/roles/freeipa_system_account/defaults/main.yml new file mode 100644 index 0000000..21c0ab2 --- /dev/null +++ b/roles/freeipa_system_account/defaults/main.yml @@ -0,0 +1 @@ +system_account_expiration: 20380119031407Z diff --git a/roles/freeipa_system_account/tasks/main.yml b/roles/freeipa_system_account/tasks/main.yml new file mode 100644 index 0000000..8da9fde --- /dev/null +++ b/roles/freeipa_system_account/tasks/main.yml @@ -0,0 +1,14 @@ +- name: create freeipa system account for LDAP binds + ldap_entry: + dn: 'uid={{ system_account_username }},{{ freeipa_sysaccount_basedn }}' + objectClass: + - account + - simplesecurityobject + attributes: + uid: '{{ system_account_username }}' + userPassword: '{{ system_account_password }}' + passwordExpirationTime: '{{ system_account_expiration }}' + nsIdleTimeout: 0 + bind_dn: cn=Directory Manager + bind_pw: '{{ freeipa_ds_password }}' + server_uri: ldaps://{{ ipa_host }} -- cgit