diff options
author | Kai Blin <kai@samba.org> | 2011-06-26 00:36:25 +0200 |
---|---|---|
committer | Kai Blin <kai@samba.org> | 2011-07-07 00:10:27 +0200 |
commit | a8d3bdb48da71dd65385e4355e46a595ef32dbe0 (patch) | |
tree | e8e8f58c1a202ef15e8505fc220270b7edab0278 /source4/setup/provision_dns_add_samba.ldif | |
parent | 0b8184d9d40c6ccb10209973e6bbeccee4dc000a (diff) | |
download | samba-a8d3bdb48da71dd65385e4355e46a595ef32dbe0.tar.gz samba-a8d3bdb48da71dd65385e4355e46a595ef32dbe0.tar.bz2 samba-a8d3bdb48da71dd65385e4355e46a595ef32dbe0.zip |
s4 provision: split up DNS provisioning into generic and samba-specific ldifs
Signed-off-by: Kai Blin <kai@samba.org>
Diffstat (limited to 'source4/setup/provision_dns_add_samba.ldif')
-rw-r--r-- | source4/setup/provision_dns_add_samba.ldif | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/source4/setup/provision_dns_add_samba.ldif b/source4/setup/provision_dns_add_samba.ldif new file mode 100644 index 0000000000..6c664d910b --- /dev/null +++ b/source4/setup/provision_dns_add_samba.ldif @@ -0,0 +1,17 @@ +# NOTE: This account is SAMBA4 specific! +# we have it to avoid the need for the bind daemon to +# have access to the whole secrets.keytab for the domain, +# otherwise bind could impersonate any user +dn: CN=dns-${HOSTNAME},CN=Users,${DOMAINDN} +objectClass: top +objectClass: person +objectClass: organizationalPerson +objectClass: user +description: DNS Service Account for ${HOSTNAME} +userAccountControl: 512 +accountExpires: 9223372036854775807 +sAMAccountName: dns-${HOSTNAME} +servicePrincipalName: DNS/${DNSNAME} +servicePrincipalName: DNS/${DNSDOMAIN} +clearTextPassword:: ${DNSPASS_B64} +isCriticalSystemObject: TRUE |