3 ܓi @sbddlZddlZddlmZmZmZmZGdddeZGdddeeZGdddeeeZ dS) N)Plugin RedHatPlugin DebianPlugin UbuntuPluginc@s0eZdZdZdZdZd ZdZddZd d Z dS) Krb5a:This plugin handles the collection of kerberos authentication config files and logging. Users should expect to see their krb5 config(s) in the final archive, along with krb5 logging and `klist` output. kdc configs and acls will also be collected from the distribution-spcecific kdc directory. zKerberos authenticationZkrb5identitysystemNcCs\|jdd|jd|jddg|j|jddd|jd |jd |jd dS) Nz/etc/krb5.confz/etc/krb5.conf.d/*z /kadm5.aclz /kdc.confz/var/log/kadmind.logz/var/log/krb5kdc.logZkerberos_kdc_log)Ztagsz klist -ket z/.k5*zklist -ket /etc/krb5.keytab)Z add_copy_speckdcdir collect_kinitadd_cmd_output)selfr /usr/lib/python3.6/krb5.pysetups  z Krb5.setupc Cstj}d}|j|rt|dddv}xn|D]f}tjd|tjrn|jdddd j}|j d |d Ptjd |tjr,|j d |d Pq,WWdQRXdS)a) Collect the kinit command output for the system with id_provider "AD" or "IPA" domains. While integrating the Linux M/c with AD the realmd will create a computer object on the AD side. The realmd and AD restrict the Hostname/SPN to 15 Characters. z/etc/sssd/sssd.confrzutf-8)encodingz\s*id_provider\s*=\s*ad.rNzMKRB5_TRACE=/dev/stdout kinit -k 'z$'z\s*id_provider\s*=\s*ipa') socketZgetfqdnZ path_isfileopenrematch IGNORECASEsplitupperr )r ZhostnameZ sssd_conffliner r rr +s     zKrb5.collect_kinit)rr) __name__ __module__ __qualname____doc__Z short_descZ plugin_nameZprofilesr rr r r r rrs rc@seZdZdZdZdS) RedHatKrb5 krb5-libs krb5-serverz/var/kerberos/krb5kdcN)r#r$)rrr packagesr r r r rr"Gsr"c@seZdZdZdZdS) UbuntuKrb5krb5-kdc krb5-config krb5-userz/var/lib/krb5kdcN)r'r(r))rrr r%r r r r rr&Msr&) rrZsos.report.pluginsrrrrrr"r&r r r r s 7