From a8d3bdb48da71dd65385e4355e46a595ef32dbe0 Mon Sep 17 00:00:00 2001 From: Kai Blin Date: Sun, 26 Jun 2011 00:36:25 +0200 Subject: s4 provision: split up DNS provisioning into generic and samba-specific ldifs Signed-off-by: Kai Blin --- source4/setup/provision_dns_add_samba.ldif | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 source4/setup/provision_dns_add_samba.ldif (limited to 'source4/setup/provision_dns_add_samba.ldif') diff --git a/source4/setup/provision_dns_add_samba.ldif b/source4/setup/provision_dns_add_samba.ldif new file mode 100644 index 0000000000..6c664d910b --- /dev/null +++ b/source4/setup/provision_dns_add_samba.ldif @@ -0,0 +1,17 @@ +# NOTE: This account is SAMBA4 specific! +# we have it to avoid the need for the bind daemon to +# have access to the whole secrets.keytab for the domain, +# otherwise bind could impersonate any user +dn: CN=dns-${HOSTNAME},CN=Users,${DOMAINDN} +objectClass: top +objectClass: person +objectClass: organizationalPerson +objectClass: user +description: DNS Service Account for ${HOSTNAME} +userAccountControl: 512 +accountExpires: 9223372036854775807 +sAMAccountName: dns-${HOSTNAME} +servicePrincipalName: DNS/${DNSNAME} +servicePrincipalName: DNS/${DNSDOMAIN} +clearTextPassword:: ${DNSPASS_B64} +isCriticalSystemObject: TRUE -- cgit