3 ܓi @ sb d dl Z d dlZd dlmZmZmZmZ G dd deZG dd deeZG dd deeeZ dS ) N)PluginRedHatPluginDebianPluginUbuntuPluginc @ s0 e Zd ZdZdZdZdZdZdd Zd d Z dS )Krb5a: This plugin handles the collection of kerberos authentication config files and logging. Users should expect to see their krb5 config(s) in the final archive, along with krb5 logging and `klist` output. kdc configs and acls will also be collected from the distribution-spcecific kdc directory. zKerberos authenticationZkrb5identitysystemNc C s\ | j dd| j d| j ddg | j | j ddd | jd | j d | jd d S )Nz/etc/krb5.confz/etc/krb5.conf.d/*z /kadm5.aclz /kdc.confz/var/log/kadmind.logz/var/log/krb5kdc.logZkerberos_kdc_log)Ztagszklist -ket z/.k5*zklist -ket /etc/krb5.keytab)Z add_copy_speckdcdir collect_kinitadd_cmd_output)self r /usr/lib/python3.6/krb5.pysetup s z Krb5.setupc C s t j }d}| j|rt|dddv}xn|D ]f}tjd|tjrn|jdd dd j }| j d | d P tjd|tjr,| j d | d P q,W W dQ R X dS )a) Collect the kinit command output for the system with id_provider "AD" or "IPA" domains. While integrating the Linux M/c with AD the realmd will create a computer object on the AD side. The realmd and AD restrict the Hostname/SPN to 15 Characters. z/etc/sssd/sssd.confrzutf-8)encodingz\s*id_provider\s*=\s*ad.r N zMKRB5_TRACE=/dev/stdout kinit -k 'z$'z\s*id_provider\s*=\s*ipa') socketZgetfqdnZpath_isfileopenrematch IGNORECASEsplitupperr )r ZhostnameZ sssd_conffliner r r r + s zKrb5.collect_kinit)r r ) __name__ __module____qualname____doc__Z short_descZplugin_nameZprofilesr r r r r r r r s r c @ s e Zd ZdZdZdS ) RedHatKrb5 krb5-libskrb5-serverz/var/kerberos/krb5kdcN)r# r$ )r r r packagesr r r r r r" G s r" c @ s e Zd ZdZdZdS ) UbuntuKrb5krb5-kdckrb5-config krb5-userz/var/lib/krb5kdcN)r' r( r) )r r r r% r r r r r r&