fix: disable kanidm anon account in kanidm unit
This commit is contained in:
@@ -81,9 +81,6 @@ let
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# disable anonymous account because it allows to freely iterate over all users on kanidm instance.
|
|
||||||
$KANIDM service-account validity expire-at anonymous epoch
|
|
||||||
|
|
||||||
# create a new token for kanidm
|
# create a new token for kanidm
|
||||||
if ! KANIDM_SERVICE_ACCOUNT_TOKEN_JSON="$($KANIDM service-account api-token generate --name idm_admin "${kanidmServiceAccountName}" "${kanidmServiceAccountTokenName}" ${lib.strings.optionalString isRW "--rw"} --output json)"
|
if ! KANIDM_SERVICE_ACCOUNT_TOKEN_JSON="$($KANIDM service-account api-token generate --name idm_admin "${kanidmServiceAccountName}" "${kanidmServiceAccountTokenName}" ${lib.strings.optionalString isRW "--rw"} --output json)"
|
||||||
then
|
then
|
||||||
|
@@ -234,7 +234,12 @@ let
|
|||||||
export KANIDM_URL="${cfg.provision.instanceUrl}"
|
export KANIDM_URL="${cfg.provision.instanceUrl}"
|
||||||
export KANIDM_SKIP_HOSTNAME_VERIFICATION="true"
|
export KANIDM_SKIP_HOSTNAME_VERIFICATION="true"
|
||||||
KANIDM_PASSWORD="$KANIDM_IDM_ADMIN_PASSWORD" ${cfg.package}/bin/kanidm login
|
KANIDM_PASSWORD="$KANIDM_IDM_ADMIN_PASSWORD" ${cfg.package}/bin/kanidm login
|
||||||
|
|
||||||
|
# disable anonymous account because it allows to freely iterate over all users on kanidm instance.
|
||||||
|
${cfg.package}/bin/kanidm service-account validity expire-at anonymous epoch
|
||||||
|
|
||||||
${createAndPopulateGroups}
|
${createAndPopulateGroups}
|
||||||
|
|
||||||
unset HOME
|
unset HOME
|
||||||
unset KANIDM_NAME
|
unset KANIDM_NAME
|
||||||
unset KANIDM_URL
|
unset KANIDM_URL
|
||||||
|
Reference in New Issue
Block a user