diff --git a/config/krb5-cfg.yml b/config/krb5-cfg.yml new file mode 100644 index 0000000..0750406 --- /dev/null +++ b/config/krb5-cfg.yml @@ -0,0 +1,35 @@ +ldap_connection: + host: + port: 636 + auth: + method: :gssapi + hostname: + encryption: + method: :simple_tls + +ldap_users: + base: DC=,DC= + filter: CN=Users,DC=,DC= + name_attribute: sAMAccountName + uppercase_name: true + +ldap_groups: + base: DC=,DC= + filter: fruw.org + name_attribute: cn + uppercase_name: true + member_attribute: "memberuid" + +pg_connection: + host: + dbname: postgres + user: + +pg_users: + filter: oid IN (SELECT pam.member FROM pg_auth_members pam JOIN pg_roles pr ON pr.oid=pam.roleid WHERE pr.rolname='ldap_users') + create_options: LOGIN IN ROLE ldap_users + +pg_groups: + filter: oid IN (SELECT pam.member FROM pg_auth_members pam JOIN pg_roles pr ON pr.oid=pam.roleid WHERE pr.rolname='ldap_groups') + create_options: NOLOGIN IN ROLE ldap_groups + grant_options: