From 8daa83a594a2e98f39d764422bfbdbc62c9efd44 Mon Sep 17 00:00:00 2001 From: Daniel Baumann Date: Fri, 19 Apr 2024 19:20:00 +0200 Subject: Adding upstream version 2:4.20.0+dfsg. Signed-off-by: Daniel Baumann --- source4/setup/provision_dns_add_samba.ldif | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 source4/setup/provision_dns_add_samba.ldif (limited to 'source4/setup/provision_dns_add_samba.ldif') diff --git a/source4/setup/provision_dns_add_samba.ldif b/source4/setup/provision_dns_add_samba.ldif new file mode 100644 index 0000000..7fb2e78 --- /dev/null +++ b/source4/setup/provision_dns_add_samba.ldif @@ -0,0 +1,16 @@ +# NOTE: This account is SAMBA4 specific! +# we have it to avoid the need for the bind daemon to +# have access to the whole secrets.keytab for the domain, +# otherwise bind could impersonate any user +dn: CN=dns-${HOSTNAME},CN=Users,${DOMAINDN} +objectClass: top +objectClass: person +objectClass: organizationalPerson +objectClass: user +description: DNS Service Account for ${HOSTNAME} +userAccountControl: 512 +accountExpires: 9223372036854775807 +sAMAccountName: dns-${HOSTNAME} +servicePrincipalName: DNS/${DNSNAME} +clearTextPassword:: ${DNSPASS_B64} +isCriticalSystemObject: TRUE -- cgit v1.2.3