1
|
Script started on ven 03 mar 2017 14:49:27 CET
|
2
|
root@server:~# fuss-server create
|
3
|
WARNING:root:Interface is not available
|
4
|
WARNING:root:Interface is not available
|
5
|
################################################################################
|
6
|
Please insert Local network address
|
7
|
|
8
|
The format is netaddr/cidr, ex. 192.168.1.0/24
|
9
|
Your choice? 10.0.0.0/8
|
10
|
################################################################################
|
11
|
Please insert Domain name
|
12
|
|
13
|
The domain for this network, ex. 'institute.lan'
|
14
|
Your choice? scuola.lan
|
15
|
################################################################################
|
16
|
Please insert Windows Workgroup
|
17
|
|
18
|
The Windows WorkGroup for this network, ex. 'institute'
|
19
|
Your choice? scuola
|
20
|
################################################################################
|
21
|
Please insert DHCP Server Range
|
22
|
|
23
|
The IP range of address given by the DHCP Server, ex. '192.168.1.10 192.168.1.100'
|
24
|
Your choice? 10.0.0.10 10.0.0.100
|
25
|
################################################################################
|
26
|
Please insert Master password
|
27
|
|
28
|
The master password for this server
|
29
|
Password:
|
30
|
################################################################################
|
31
|
Please insert Locality
|
32
|
|
33
|
Locality e/o address name, ex. 'Bolzano'
|
34
|
Your choice? Bolzano
|
35
|
################################################################################
|
36
|
Please insert WAN Interface
|
37
|
|
38
|
The WAN interface(s) of the server, ex. 'eth0'
|
39
|
Your choice? eth0
|
40
|
################################################################################
|
41
|
Please insert LAN Interfaces
|
42
|
|
43
|
The LAN interface(s) of the server, ex. 'eth1 eth2'
|
44
|
Your choice? eth1
|
45
|
|
46
|
PLAY [Configure a FUSS Server.] ************************************************
|
47
|
|
48
|
TASK [setup] *******************************************************************
|
49
|
[0;32mok: [localhost][0m
|
50
|
|
51
|
TASK [common : Clean package list] *********************************************
|
52
|
|
53
|
TASK [common : Install base packages] ******************************************
|
54
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
55
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
56
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
57
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
58
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
59
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
60
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
61
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
62
|
|
63
|
TASK [common : Install package jed,less,screen,links,wget,rsync,bzip2,unzip,strace,lsof by apt] ***
|
64
|
[0;32mok: [localhost][0m
|
65
|
|
66
|
TASK [common : register packages] **********************************************
|
67
|
|
68
|
TASK [common : Install package tcpdump,netcat,iputils-arping,nmap,iproute2,mtr-tiny,traceroute by apt] ***
|
69
|
[0;32mok: [localhost][0m
|
70
|
|
71
|
TASK [common : register packages] **********************************************
|
72
|
|
73
|
TASK [common : Install package netmask,iptraf-ng,dnsutils,python-ipaddr by apt]
|
74
|
[0;32mok: [localhost][0m
|
75
|
|
76
|
TASK [common : register packages] **********************************************
|
77
|
|
78
|
TASK [common : Install package iotop,iftop,atop,hdparm,pciutils by apt] ********
|
79
|
[0;32mok: [localhost][0m
|
80
|
|
81
|
TASK [common : register packages] **********************************************
|
82
|
|
83
|
TASK [common : Install package apt-listchanges,sudo,molly-guard by apt] ********
|
84
|
[0;32mok: [localhost][0m
|
85
|
|
86
|
TASK [common : register packages] **********************************************
|
87
|
|
88
|
TASK [common : Install package apticron,witalian,easy-rsa,ssl-cert by apt] *****
|
89
|
[0;32mok: [localhost][0m
|
90
|
|
91
|
TASK [common : register packages] **********************************************
|
92
|
|
93
|
TASK [common : Install package tiger,chkrootkit,libpam-cracklib by apt] ********
|
94
|
[0;32mok: [localhost][0m
|
95
|
|
96
|
TASK [common : register packages] **********************************************
|
97
|
|
98
|
TASK [common : Install package openssl,clusterssh,fuse by apt] *****************
|
99
|
[0;32mok: [localhost][0m
|
100
|
|
101
|
TASK [common : register packages] **********************************************
|
102
|
|
103
|
TASK [common : Read all interface addresses + subnet] **************************
|
104
|
[0;33mchanged: [localhost] => (item=eth0)[0m
|
105
|
[0;33mchanged: [localhost] => (item=eth1)[0m
|
106
|
|
107
|
TASK [common : Load all network configuration into yaml] ***********************
|
108
|
[0;32mok: [localhost][0m
|
109
|
|
110
|
TASK [common : Set common facts] ***********************************************
|
111
|
[0;32mok: [localhost][0m
|
112
|
|
113
|
TASK [common : Set additional convenience facts] *******************************
|
114
|
[0;32mok: [localhost][0m
|
115
|
|
116
|
TASK [common : Create Credentials directory] ***********************************
|
117
|
[0;33mchanged: [localhost][0m
|
118
|
|
119
|
TASK [common : Check permissions on configuration file] ************************
|
120
|
[0;33mchanged: [localhost][0m
|
121
|
|
122
|
TASK [ssl-ca-init : Create CA directory on server] *****************************
|
123
|
[0;33mchanged: [localhost][0m
|
124
|
|
125
|
TASK [ssl-ca-init : Generate Certificates with issue-host-ssl-cert script] *****
|
126
|
[0;32mok: [localhost] => (item= creating server.scuola.lan-cert.pem and server.scuola.lan-key.pem) => {
|
127
|
"item": " creating server.scuola.lan-cert.pem and server.scuola.lan-key.pem",
|
128
|
"msg": " creating server.scuola.lan-cert.pem and server.scuola.lan-key.pem"
|
129
|
}[0m
|
130
|
|
131
|
TASK [ssl-ca-init : Copy CA data on the server CA directory] *******************
|
132
|
[0;33mchanged: [localhost][0m
|
133
|
|
134
|
TASK [ssl-ca-init : install SSL CA file] ***************************************
|
135
|
[0;33mchanged: [localhost][0m
|
136
|
|
137
|
TASK [ssl-ca-init : install SSL cert file] *************************************
|
138
|
[0;33mchanged: [localhost][0m
|
139
|
|
140
|
TASK [ssl-ca-init : install SSL key file] **************************************
|
141
|
[0;33mchanged: [localhost][0m
|
142
|
|
143
|
TASK [ldap-base : fail] ********************************************************
|
144
|
[0;36mskipping: [localhost][0m
|
145
|
|
146
|
TASK [ldap-base : include] *****************************************************
|
147
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
148
|
|
149
|
TASK [ldap-base : Install package ldap-utils by apt] ***************************
|
150
|
[0;32mok: [localhost][0m
|
151
|
|
152
|
TASK [ldap-base : register packages] *******************************************
|
153
|
|
154
|
TASK [ldap-base : install SSL CA certificate] **********************************
|
155
|
[0;32mok: [localhost][0m
|
156
|
|
157
|
TASK [ldap-base : Setup /etc/ldap/ldap.conf] ***********************************
|
158
|
[0;33mchanged: [localhost][0m
|
159
|
|
160
|
TASK [slapd : fail] ************************************************************
|
161
|
[0;36mskipping: [localhost][0m
|
162
|
|
163
|
TASK [slapd : Look if slapd.conf file is already there] ************************
|
164
|
[0;32mok: [localhost][0m
|
165
|
|
166
|
TASK [slapd : Preseed debconf slapd admin password, first time] ****************
|
167
|
[0;33mchanged: [localhost][0m
|
168
|
|
169
|
TASK [slapd : Preseed debconf slapd admin password, second time] ***************
|
170
|
[0;33mchanged: [localhost][0m
|
171
|
|
172
|
TASK [slapd : Preseed debconf LDAP base DN] ************************************
|
173
|
[0;33mchanged: [localhost][0m
|
174
|
|
175
|
TASK [slapd : include] *********************************************************
|
176
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
177
|
|
178
|
TASK [slapd : Install package slapd,slapd-smbk5pwd,gosa-schema by apt] *********
|
179
|
[0;32mok: [localhost][0m
|
180
|
|
181
|
TASK [slapd : register packages] ***********************************************
|
182
|
|
183
|
TASK [slapd : Generate hashed password] ****************************************
|
184
|
[0;32mok: [localhost][0m
|
185
|
|
186
|
TASK [slapd : Is there slapd.d directory] **************************************
|
187
|
[0;32mok: [localhost][0m
|
188
|
|
189
|
TASK [slapd : Stopping slapd server] *******************************************
|
190
|
[0;33mchanged: [localhost][0m
|
191
|
|
192
|
TASK [slapd : Move away slapd.d directory] *************************************
|
193
|
[0;33mchanged: [localhost][0m
|
194
|
|
195
|
TASK [slapd : Give slapd user access to server certificate key] ****************
|
196
|
[0;33mchanged: [localhost][0m
|
197
|
|
198
|
TASK [slapd : adding ldaps:/// to SLAPD_SERVICES in /etc/default/slapd] ********
|
199
|
[0;33mchanged: [localhost][0m
|
200
|
|
201
|
TASK [slapd : Setup /etc/ldap/slapd.conf] **************************************
|
202
|
[0;33mchanged: [localhost][0m
|
203
|
|
204
|
TASK [slapd : Starting slapd server] *******************************************
|
205
|
[0;33mchanged: [localhost][0m
|
206
|
|
207
|
TASK [slapd : include] *********************************************************
|
208
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
209
|
|
210
|
TASK [slapd : Install package ldapvi by apt] ***********************************
|
211
|
[0;32mok: [localhost][0m
|
212
|
|
213
|
TASK [slapd : register packages] ***********************************************
|
214
|
|
215
|
TASK [slapd : Setup .ldapvirc] *************************************************
|
216
|
[0;33mchanged: [localhost][0m
|
217
|
|
218
|
TASK [slapd : include] *********************************************************
|
219
|
[0;36mincluded: /usr/share/fuss-server/includes/install-package-apt.yml for localhost[0m
|
220
|
|
221
|
TASK [slapd : Install package smbldap-tools,samba-common-bin,python-smbpasswd by apt] ***
|
222
|
[0;32mok: [localhost][0m
|
223
|
|
224
|
TASK [slapd : register packages] ***********************************************
|
225
|
|
226
|
TASK [slapd : Setup /etc/smbldap-tools/smbldap_bind.conf] **********************
|
227
|
[0;33mchanged: [localhost][0m
|
228
|
|
229
|
TASK [slapd : Get SID value] ***************************************************
|
230
|
[0;32mok: [localhost][0m
|
231
|
|
232
|
TASK [slapd : Setup /etc/smbldap-tools/smbldap.conf] ***************************
|
233
|
[0;33mchanged: [localhost][0m
|
234
|
|
235
|
TASK [slapd : Check if DIT is already done] ************************************
|
236
|
[0;32mok: [localhost][0m
|
237
|
|
238
|
TASK [slapd : Get hashed password from /etc/ldap/slapd.conf (for idempotency)] *
|
239
|
[0;32mok: [localhost][0m
|
240
|
|
241
|
TASK [slapd : debug] ***********************************************************
|
242
|
[0;32mok: [localhost] => {
|
243
|
"msg": "Hashed pass = {u'changed': False, u'end': u'2017-03-03 14:50:06.775500', 'failed': False, u'stdout': u'{SSHA}EwEUDDMBm8sux5+Os5dm7sDs/giJ3uFv', u'cmd': u\"grep '# rootpw' /etc/ldap/slapd.conf|awk '{print $3}'\", u'rc': 0, u'start': u'2017-03-03 14:50:06.770599', u'stderr': u'', u'delta': u'0:00:00.004901', 'stdout_lines': [u'{SSHA}EwEUDDMBm8sux5+Os5dm7sDs/giJ3uFv'], 'failed_when_result': False, u'warnings': []}"
|
244
|
}[0m
|
245
|
|
246
|
TASK [slapd : Copy DIT template] ***********************************************
|
247
|
[0;33mchanged: [localhost][0m
|
248
|
|
249
|
TASK [slapd : Create DIT] ******************************************************
|
250
|
[0;31mfatal: [localhost]: FAILED! => {"changed": false, "cmd": "ldapadd -c -Y EXTERNAL -H ldapi:/// -f /etc/fuss-server//Credentials/init_tree.ldif", "delta": "0:00:00.016511", "end": "2017-03-03 14:50:07.144943", "failed": true, "failed_when_result": true, "rc": 32, "start": "2017-03-03 14:50:07.128432", "stderr": "SASL/EXTERNAL authentication started\nSASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth\nSASL SSF: 0\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)\nldap_add: No such object (32)", "stdout": "adding new entry \"ou=Users,dc=scuola,dc=lan\"\n\nadding new entry \"ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"ou=Computers,dc=scuola,dc=lan\"\n\nadding new entry \"ou=Idmap,dc=scuola,dc=lan\"\n\nadding new entry \"sambaDomainName=scuola,dc=scuola,dc=lan\"\n\nadding new entry \"uid=admin,ou=Users,dc=scuola,dc=lan\"\n\nadding new entry \"uid=nobody,ou=Users,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Domain Admins,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Domain Users,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Domain Guests,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Domain Computers,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Administrators,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Account Operators,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Print Operators,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Backup Operators,ou=Groups,dc=scuola,dc=lan\"\n\nadding new entry \"cn=Replicators,ou=Groups,dc=scuola,dc=lan\"", "stdout_lines": ["adding new entry \"ou=Users,dc=scuola,dc=lan\"", "", "adding new entry \"ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"ou=Computers,dc=scuola,dc=lan\"", "", "adding new entry \"ou=Idmap,dc=scuola,dc=lan\"", "", "adding new entry \"sambaDomainName=scuola,dc=scuola,dc=lan\"", "", "adding new entry \"uid=admin,ou=Users,dc=scuola,dc=lan\"", "", "adding new entry \"uid=nobody,ou=Users,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Domain Admins,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Domain Users,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Domain Guests,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Domain Computers,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Administrators,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Account Operators,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Print Operators,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Backup Operators,ou=Groups,dc=scuola,dc=lan\"", "", "adding new entry \"cn=Replicators,ou=Groups,dc=scuola,dc=lan\""], "warnings": []}[0m
|
251
|
|
252
|
RUNNING HANDLER [slapd : restart slapd with slapd.conf] ************************
|
253
|
[0;33mchanged: [localhost][0m
|
254
|
to retry, use: --limit @/usr/share/fuss-server/create.retry
|
255
|
|
256
|
PLAY RECAP *********************************************************************
|
257
|
[0;31mlocalhost[0m : [0;32mok=60 [0m [0;33mchanged=23 [0m unreachable=0 [0;31mfailed=1 [0m
|
258
|
|
259
|
root@server:~# exit
|
260
|
|
261
|
Script done on ven 03 mar 2017 14:50:10 CET
|