Description

This tool is used to create users in SUSE Manager Server based on LDAP/AD groups. For each LDAP/AD group a role within SUSE Manager Server is defined. Also, the tool will check if existing users still have the role they should have, and, if not, it will be corrected. The same for if a user is disabled, it will be enabled again. If a users is not present in the LDAP/AD groups anymore, it will be disabled or deleted, depending on the configuration.

The code is written for Python 3.6 (the default with SLES15.x), but will also work with newer versions. And works against SUSE Manger 4.3 and 5.x

Goals

Create a python and/or golang utility that will manage users in SUSE Manager based on LDAP/AD group-membership. In a configuration file is defined which roles the members of a group will get.

Table of contents

Installation

To install this project, perform the following steps:

  • Be sure that python 3.6 is installed and also the module python3-PyYAML. Also the ldap3 module is needed:

bash zypper in python3 python3-PyYAML pip install yaml

  • On the server or PC, where it should run, create a directory. On linux, e.g. /opt/sm-ldap-users

  • Copy all the file to this directory.

  • Edit the configsm.yaml. All parameters should be entered. Tip: for the ldap information, the best would be to use the same as for SSSD.

  • Be sure that the file sm-ldap-users.py is executable. It would be good to change the owner to root:root and only root can read and execute:

bash chmod 600 * chmod 700 sm-ldap-users.py chown root:root *

Usage

This is very simple. Once the configsm.yaml contains the correct information, executing the following will do the magic:

bash /sm-ldap-users.py

repository link

https://github.com/mbrookhuis/sm-ldap-users

Looking for hackers with the skills:

uyuni susemanager

This project is part of:

Hack Week 24

Activity

  • 6 months ago: juliogonzalezgil liked this project.
  • 6 months ago: mbrookhuis added keyword "uyuni" to this project.
  • 6 months ago: mbrookhuis added keyword "susemanager" to this project.
  • 7 months ago: drrobk liked this project.
  • 7 months ago: imabreuferreira joined this project.
  • 7 months ago: wombelix liked this project.
  • 7 months ago: kevinm left this project.
  • 7 months ago: kevinm joined this project.
  • 7 months ago: emendonca joined this project.
  • 7 months ago: mbrookhuis started this project.
  • 7 months ago: mbrookhuis liked this project.
  • 7 months ago: mbrookhuis originated this project.

  • Comments

    • emendonca
      7 months ago by emendonca | Reply

      I can help with the Python part, SUSE Manager API and LDAP queries.

    • mbrookhuis
      6 months ago by mbrookhuis | Reply

      Hi @emendonca, I totally missed you comment. Sorry and my apologies.

      I have uploaded the project, please have a look and I am looking forward for your comments.

    Similar Projects

    This project is one of its kind!