diff options
Diffstat (limited to 'zarb-ml/mageia-sysadm/attachments/20110113/68ffbda3/attachment.html')
-rw-r--r-- | zarb-ml/mageia-sysadm/attachments/20110113/68ffbda3/attachment.html | 132 |
1 files changed, 132 insertions, 0 deletions
diff --git a/zarb-ml/mageia-sysadm/attachments/20110113/68ffbda3/attachment.html b/zarb-ml/mageia-sysadm/attachments/20110113/68ffbda3/attachment.html new file mode 100644 index 000000000..bb61b75c4 --- /dev/null +++ b/zarb-ml/mageia-sysadm/attachments/20110113/68ffbda3/attachment.html @@ -0,0 +1,132 @@ +<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" +"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd"> +<html xmlns="http://www.w3.org/1999/xhtml"> +<head><meta http-equiv="content-type" content="text/html; charset=utf-8" /> +<title>[779] allow to use multiple group for the access with pam</title> +</head> +<body> + +<style type="text/css"><!-- +#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; } +#msg dl.meta dt { float: left; width: 6em; font-weight: bold; } +#msg dt:after { content:':';} +#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; } +#msg dl a { font-weight: bold} +#msg dl a:link { color:#fc3; } +#msg dl a:active { color:#ff0; } +#msg dl a:visited { color:#cc6; } +h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; } +#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; } +#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; } +#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; } +#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; } +#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; } +#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; } +#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; } +#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; } +#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; } +#logmsg pre { background: #eee; padding: 1em; } +#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;} +#logmsg dl { margin: 0; } +#logmsg dt { font-weight: bold; } +#logmsg dd { margin: 0; padding: 0 0 0.5em 0; } +#logmsg dd:before { content:'\00bb';} +#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; } +#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; } +#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; } +#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; } +#logmsg table th.Corner { text-align: left; } +#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; } +#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; } +#patch { width: 100%; } +--></style> +<div id="msg"> +<dl class="meta"> +<dt>Revision</dt> <dd>779</dd> +<dt>Author</dt> <dd>misc</dd> +<dt>Date</dt> <dd>2011-01-13 19:12:31 +0100 (Thu, 13 Jan 2011)</dd> +</dl> + +<h3>Log Message</h3> +<pre>allow to use multiple group for the access with pam</pre> + +<h3>Modified Paths</h3> +<ul> +<li><a href="#puppetmodulespammanifestsinitpp">puppet/modules/pam/manifests/init.pp</a></li> +<li><a href="#puppetmodulespamtemplatessystemauth">puppet/modules/pam/templates/system-auth</a></li> +</ul> + +</div> +<div id="patch"><pre> +<a id="puppetmodulespammanifestsinitpp">Modified: puppet/modules/pam/manifests/init.pp</a> +=================================================================== +--- puppet/modules/pam/manifests/init.pp 2011-01-13 18:12:29 UTC (rev 778) ++++ puppet/modules/pam/manifests/init.pp 2011-01-13 18:12:31 UTC (rev 779) +@@ -43,13 +43,20 @@ + content => template("pam/ldap.conf") + } + } ++ ++ define multiple_ldap_access($access_classes) { ++ include base ++ } + +- # beware , this two classes are exclusive ++ # beware , this two classes are exclusives ++ # if you need multiple group access, you need to define you own class ++ # of access + + # for server where only admins can connect + class admin_access { +- $access_class = "admin" +- include base ++ multiple_ldap_access { "admin_access": ++ access_classes => ['mga-sysadmin'] ++ } + } + + # for server where people can connect with ssh ( git, svn ) +@@ -59,8 +66,11 @@ + # user, and erase the password ( see pam_auth.c in openssh code, seek badpw ) + # so the file must exist + # permission to use svn, git, etc must be added separatly ++ + include restrictshell::shell +- $access_class = "committers" +- include base ++ ++ multiple_ldap_access { "committers_access": ++ access_classes => ['mga-commiters'] ++ } + } + } + +<a id="puppetmodulespamtemplatessystemauth">Modified: puppet/modules/pam/templates/system-auth</a> +=================================================================== +--- puppet/modules/pam/templates/system-auth 2011-01-13 18:12:29 UTC (rev 778) ++++ puppet/modules/pam/templates/system-auth 2011-01-13 18:12:31 UTC (rev 779) +@@ -9,13 +9,13 @@ + + + account sufficient pam_localuser.so +-<%- if access_class == 'admin' -%> +-account required pam_succeed_if.so quiet user ingroup mga-sysadmin ++# not sure if the following bring something useful ++account required pam_ldap.so ++<%- if access_classes -%> ++<%- access_classes.each { |ldap_group| -%> ++account sufficient pam_succeed_if.so quiet user ingroup <%= ldap_group %> ++<%- } -%> + <%- end -%> +-<%- if access_class == 'committers' -%> +-account required pam_succeed_if.so quiet user ingroup mga-committers +-<%- end -%> +-account sufficient pam_ldap.so + account required pam_deny.so + + + +</pre></div> + +</body> +</html>
\ No newline at end of file |