| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 1 | # lib/ldap | 
|  | 2 | # Functions to control the installation and configuration of **ldap** | 
|  | 3 |  | 
| Dean Troyer | cc6b443 | 2013-04-08 15:38:03 -0500 | [diff] [blame] | 4 | # ``lib/keystone`` calls the entry points in this order: | 
|  | 5 | # install_ldap() | 
| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 6 |  | 
|  | 7 | # Save trace setting | 
|  | 8 | XTRACE=$(set +o | grep xtrace) | 
|  | 9 | set +o xtrace | 
|  | 10 |  | 
| Dean Troyer | cc6b443 | 2013-04-08 15:38:03 -0500 | [diff] [blame] | 11 |  | 
|  | 12 | # Functions | 
|  | 13 | # --------- | 
|  | 14 |  | 
| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 15 | # install_ldap | 
|  | 16 | # install_ldap() - Collect source and prepare | 
|  | 17 | function install_ldap() { | 
|  | 18 | echo "Installing LDAP inside function" | 
|  | 19 | echo "LDAP_PASSWORD is $LDAP_PASSWORD" | 
|  | 20 | echo "os_VENDOR is $os_VENDOR" | 
|  | 21 | printf "installing" | 
|  | 22 | if is_ubuntu; then | 
| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 23 | LDAP_OLCDB_NUMBER=1 | 
|  | 24 | LDAP_ROOTPW_COMMAND=replace | 
|  | 25 | sudo DEBIAN_FRONTEND=noninteractive apt-get install slapd ldap-utils | 
|  | 26 | #automatically starts LDAP on ubuntu so no need to call start_ldap | 
| Vincent Untz | 3f34d9a | 2013-03-12 17:57:36 +0100 | [diff] [blame] | 27 | elif is_fedora || is_suse; then | 
| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 28 | LDAP_OLCDB_NUMBER=2 | 
|  | 29 | LDAP_ROOTPW_COMMAND=add | 
|  | 30 | start_ldap | 
|  | 31 | fi | 
|  | 32 |  | 
|  | 33 | printf "generate password file" | 
|  | 34 | SLAPPASS=`slappasswd -s $LDAP_PASSWORD` | 
|  | 35 |  | 
|  | 36 | printf "secret is $SLAPPASS\n" | 
|  | 37 | #create manager.ldif | 
|  | 38 | TMP_MGR_DIFF_FILE=`mktemp -t manager_ldiff.$$.XXXXXXXXXX.ldif` | 
|  | 39 | sed -e "s|\${LDAP_OLCDB_NUMBER}|$LDAP_OLCDB_NUMBER|" -e "s|\${SLAPPASS}|$SLAPPASS|" -e "s|\${LDAP_ROOTPW_COMMAND}|$LDAP_ROOTPW_COMMAND|" $FILES/ldap/manager.ldif.in >> $TMP_MGR_DIFF_FILE | 
|  | 40 |  | 
|  | 41 | #update ldap olcdb | 
|  | 42 | sudo ldapmodify -Y EXTERNAL -H ldapi:/// -f $TMP_MGR_DIFF_FILE | 
|  | 43 |  | 
| Brad Topol | 0c2c3fc | 2013-03-19 03:01:30 -0500 | [diff] [blame] | 44 | # On fedora we need to manually add cosine and inetorgperson schemas | 
|  | 45 | if is_fedora; then | 
|  | 46 | sudo ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/cosine.ldif | 
|  | 47 | sudo ldapadd -Y EXTERNAL -H ldapi:/// -f /etc/openldap/schema/inetorgperson.ldif | 
|  | 48 | fi | 
|  | 49 |  | 
| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 50 | # add our top level ldap nodes | 
| Dean Troyer | cc6b443 | 2013-04-08 15:38:03 -0500 | [diff] [blame] | 51 | if ldapsearch -x -w $LDAP_PASSWORD -H ldap://localhost -D dc=Manager,dc=openstack,dc=org -x -b dc=openstack,dc=org | grep -q "Success"; then | 
| Brad Topol | f127e2f | 2013-01-22 10:17:50 -0600 | [diff] [blame] | 52 | printf "LDAP already configured for OpenStack\n" | 
|  | 53 | if [[ "$KEYSTONE_CLEAR_LDAP" == "yes" ]]; then | 
|  | 54 | # clear LDAP state | 
|  | 55 | clear_ldap_state | 
|  | 56 | # reconfigure LDAP for OpenStack | 
|  | 57 | ldapadd -c -x -H ldap://localhost -D dc=Manager,dc=openstack,dc=org -w $LDAP_PASSWORD -f  $FILES/ldap/openstack.ldif | 
|  | 58 | fi | 
|  | 59 | else | 
|  | 60 | printf "Configuring LDAP for OpenStack\n" | 
|  | 61 | ldapadd -c -x -H ldap://localhost -D dc=Manager,dc=openstack,dc=org -w $LDAP_PASSWORD -f  $FILES/ldap/openstack.ldif | 
|  | 62 | fi | 
|  | 63 | } | 
|  | 64 |  | 
|  | 65 | # start_ldap() - Start LDAP | 
|  | 66 | function start_ldap() { | 
|  | 67 | sudo service slapd restart | 
|  | 68 | } | 
|  | 69 |  | 
|  | 70 |  | 
|  | 71 | # stop_ldap() - Stop LDAP | 
|  | 72 | function stop_ldap() { | 
|  | 73 | sudo service slapd stop | 
|  | 74 | } | 
|  | 75 |  | 
|  | 76 | # clear_ldap_state() - Clear LDAP State | 
|  | 77 | function clear_ldap_state() { | 
|  | 78 | ldapdelete -x -w $LDAP_PASSWORD -H ldap://localhost -D dc=Manager,dc=openstack,dc=org -x -r "dc=openstack,dc=org" | 
|  | 79 | } | 
|  | 80 |  | 
|  | 81 | # Restore xtrace | 
|  | 82 | $XTRACE | 
| Sean Dague | 584d90e | 2013-03-29 14:34:53 -0400 | [diff] [blame] | 83 |  | 
|  | 84 | # Local variables: | 
|  | 85 | # mode: shell-script | 
|  | 86 | # End: |