Tested with Travis CI
- Overview
- Module Description - What the module does and why it is useful
- Setup - The basics of getting started with yp
- Usage - Configuration options and additional functionality
- Reference - An under-the-hood peek at what the module is doing and how
- Limitations - OS compatibility, etc.
- Development - Guide for contributing to the module
This module manages YP/NIS.
This module can configure the YP/NIS domain, manage the ypbind daemon to
bind a client to a YP server and create and maintain master & slave YP servers
using ypserv and associated daemons. It can also in the special case of
OpenBSD manage the ypldap daemon to fetch YP maps from LDAP.
- The package(s) providing YP support.
- Managing the necessary configuration to bind a client to a YP domain.
- Updating the client to use the YP maps. Either:
- Adding traditional
+::...entries to the bottom of/etc/passwd,/etc/group. - Updating
/etc/nsswitch.confand PAM.
- Adding traditional
- Managing the necessary configuration for building YP maps on a standalone or master YP server.
- On a slave YP server transferring YP maps from a master YP server.
- The services controlling the
ypbind,ypserv&ypldapdaemons.
class { '::yp':
domain => 'example.com',
}Parameters within yp:
The YP/NIS domain.
The base YP directory, usually /var/yp.
Parameters within yp::bind:
The YP/NIS domain.
An array of YP servers to use, if left empty will default to broadcasting.
Whether to manage a package or not. Some operating systems have ypbind as
part of the base system.
The name of the package to install that provides the ypbind daemon.
The name of the service managing ypbind.
Parameters within yp::ldap:
The base DN from which to perform all LDAP queries.
The YP/NIS domain for which to provide maps fetched from LDAP.
The LDAP server to use.
The Distinguiѕhed Name to use to bind to the LDAP server.
The password to use when binding to the LDAP server.
The location of the configuration file, usually /etc/ypldap.conf.
A hash of YP map attributes that should not be looked up from LDAP, but
hardcoded to a particular value. Keys should be one or more of name,
passwd, uid, gid, gecos, home, shell, change, expire, class,
groupname, grouppasswd, groupgid, or groupmembers. The defaults are:
{
'passwd' => '*',
'change' => '0',
'expire' => '0',
'class' => 'ldap',
'grouppasswd' => '*',
}This blanks out any passwords, disables any account or password expiry and
places all users into the ldap login class.
Values in this parameter will be used in preference to any provided by
ldap_attributes or list_attributes.
The base DN from which to perform group LDAP queries, if different from
base_dn.
The LDAP search filter to use when searching for groups, defaults to
(objectClass=posixGroup).
How often to refresh the maps from LDAP, defaults to 60 seconds.
A hash of YP map attributes that should be looked up from regular LDAP
attributes. Keys should be one or more of name, passwd, uid, gid,
gecos, home, shell, change, expire, class, groupname,
grouppasswd, groupgid, or groupmembers. The defaults are:
{
'name' => 'uid',
'uid' => 'uidNumber',
'gid' => 'gidNumber',
'gecos' => 'cn',
'home' => 'homeDirectory',
'shell' => 'loginShell',
'groupname' => 'cn',
'groupgid' => 'gidNumber',
}These map to the standard RFC 2307(bis) attributes.
Values in this parameter have the lowest precedence compared to
fixed_attributes and list_attributes.
A hash of YP map attributes that should be looked up from regular LDAP
attributes but in the case of multiple values should be joined together with
commas. Keys should be one or more of name, passwd, uid, gid,
gecos, home, shell, change, expire, class, groupname,
grouppasswd, groupgid, or groupmembers. The defaults are:
{
'groupmembers' => 'memberUid',
}This maps to the standard RFC 2307(bis) attributes.
Values in this parameter take precedence over any defined in ldap_attributes.
The list of YP maps to provide based on LDAP searches. The defaults are
passwd.byname, passwd.byuid, group.byname, group.bygid, and
netid.byname.
The name of the service managing ypldap.
The LDAP search filter to use when searching for users, defaults to
(objectClass=posixAccount).
Parameters within yp::serv:
The YP/NIS domain.
Does this platform provide a ypxfrd daemon to help map transfers.
Whether to manage a package or not. Some operating systems have ypserv as
part of the base system.
The YP maps to build, passwd.byname, group.bygid, etc. The default is to
try and build all supported maps which often includes some esoteric ones.
The file extension added to compiled maps, often .db.
If this is a slave YP server, the IP address of the master.
Whether to merge group passwords into the group maps.
Whether to merge user passwords into the passwd maps, on some platforms this
allows a separate shadow.byname map to be created.
Any GID lower than this will not be included in the group maps. Defaults to 1000.
Any UID lower than this will not be included in the passwd maps. Defaults to 1000.
The name of the package to install that provides the ypserv daemon.
The name of the service managing yppasswdd.
The name of the service managing ypserv.
The name of the service managing ypxfrd.
If this is a master server, specify the slaves which will be notified when a map is updated.
The base YP directory, usually /var/yp.
Set the YP domain:
class { '::yp':
domain => 'example.com',
}Bind a client to a YP domain using three YP servers:
include ::portmap
class { '::yp':
domain => 'example.com',
}
class { '::yp::bind':
domain => 'example.com',
servers => ['192.0.2.1', '192.0.2.2', '192.0.2.3'],
}
Class['::portmap'] ~> Class['::yp::bind'] <~ Class['::yp']Create a standalone YP server:
include ::portmap
class { '::yp':
domain => 'example.com',
}
class { '::yp::serv':
domain => 'example.com',
}
Class['::portmap'] ~> Class['::yp::serv'] <- Class['::yp']Create a master YP server with two additional slaves:
include ::portmap
class { '::yp':
domain => 'example.com',
}
class { '::yp::serv':
domain => 'example.com',
maps => [
'passwd.byname',
'passwd.byuid',
'group.bygid',
'group.byname',
'netid.byname',
],
slaves => ['192.0.2.2', '192.0.2.3'],
}
Class['::portmap'] ~> Class['::yp::serv'] <- Class['::yp']Create a slave YP server pointing at the above master YP server:
include ::portmap
class { '::yp':
domain => 'example.com',
}
class { '::yp::serv':
domain => 'example.com',
maps => [
'passwd.byname',
'passwd.byuid',
'group.bygid',
'group.byname',
'netid.byname',
],
master => '192.0.2.1',
}
class { '::yp::bind':
domain => 'example.com',
}
Class['::portmap'] ~> Class['::yp::serv'] <- Class['::yp']
Class['::yp::serv'] -> Class['::yp::bind'] <~ Class['::yp']For OpenBSD only, set up ypldap to create YP maps from an LDAP server and
also bind to it. This is the equivalent to PAM/LDAP:
include ::portmap
class { '::yp::ldap':
base_dn => 'dc=example,dc=com',
bind_dn => 'cn=ypldap,dc=example,dc=com',
bind_pw => 'password',
domain => 'example.com',
server => '192.0.2.1',
}
class { '::yp':
domain => 'example.com',
}
class { '::yp::bind':
domain => 'example.com',
}
Class['::portmap'] ~> Class['::yp::ldap'] ~> Class['::yp::bind'] <~ Class['::yp']yp: Main class for configuring the YP/NIS domain.yp::bind: Main class for installing and managingypbinddaemon.yp::ldap: Main class for installing and managingypldapdaemon.yp::serv: Main class for installing and managingypservdaemon.
yp::config: Handles YP/NIS configuration.yp::params: Different configuration data for different systems.yp::bind::config: Handlesypbindconfiguration.yp::bind::install: Handlesypbindinstallation.yp::bind::service: Handles starting theypbinddaemon.yp::ldap::config: Handlesypldapconfiguration.yp::ldap::service: Handles starting theypldapdaemon.yp::serv::config: Handlesypservconfiguration.yp::serv::install: Handlesypservinstallation.yp::serv::service: Handles starting theypservdaemon.
yp::serv::map: Handles creating or transferring YP maps.
This module was primarily written with deploying ypldap on OpenBSD in mind
however to do that I realised I had classes for everything bar ypserv so I
added that and made sure it was portable enough to work on one other OS. It
works however I don't expect many people to still be using traditional YP/NIS.
This module has been built on and tested against Puppet 3.0 and higher.
The module has been tested on:
- OpenBSD 5.7/5.8/5.9
- RedHat/CentOS Enterprise Linux 7
Testing on other platforms has been light and cannot be guaranteed.
Please log issues or pull requests at github.