slapd-ftmg.conf has credentials, lock down modes
authorPeter Palfrader <peter@palfrader.org>
Mon, 16 Sep 2019 11:57:24 +0000 (13:57 +0200)
committerPeter Palfrader <peter@palfrader.org>
Mon, 16 Sep 2019 11:57:24 +0000 (13:57 +0200)
modules/roles/manifests/sso.pp

index 6a119d4..4da64eb 100644 (file)
@@ -36,6 +36,8 @@ class roles::sso {
   file { '/etc/ldap/slapd-ftmg.conf':
     content => template('roles/sso/slapd-ftmg.conf.erb'),
     notify  => Service['slapd'],
+    group   => 'openldap',
+    mode    => '0440',
   }
   file { '/etc/default/slapd':
     source => 'puppet:///modules/roles/sso/default-slapd',