FreedomBox/actions/create-ldap-user
2015-07-13 19:50:58 +05:30

77 lines
2.0 KiB
Bash
Executable File

#!/bin/bash
#
# This file is part of Plinth.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
#
# Must be run as root.
username="$1"
password=$(slappasswd -s "$2")
cat <<EOF |ldapadd -Y EXTERNAL -H ldapi:///
dn: uid=$username,ou=users,dc=thisbox
objectClass: inetOrgPerson
uid: $username
sn: $username
cn: $username
userPassword: $password
EOF
uid_num=$(getent passwd | awk -F: '($3>=1000) && ($3<59999) && ($3>maxuid) { maxuid=$3; } END { print maxuid+1; }')
home_dir=/home/$username
cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: uid=$username,ou=users,dc=thisbox
changeType: modify
add: objectClass
objectClass: posixAccount
-
add: uidNumber
uidNumber: $uid_num
-
add: gidNumber
gidNumber: $uid_num
-
add: homeDirectory
homeDirectory: $home_dir
EOF
if [ $? -ne 0 ]; then
echo "Failed to create user"
exit 1
fi
# check if admin group exists
results=$(ldapsearch -Y EXTERNAL -H ldapi:/// -b 'ou=groups,dc=thisbox' -LLL "(cn=admin)" cn)
if [ -z "$results" ]; then
# create admin group, with new user as a member
cat <<EOF |ldapadd -Y EXTERNAL -H ldapi:///
dn: cn=admin,ou=groups,dc=thisbox
objectClass: groupOfUniqueNames
cn: admin
uniqueMember: uid=$username,ou=users,dc=thisbox
EOF
else
# add new user to existing admin group
cat <<EOF |ldapmodify -Y EXTERNAL -H ldapi:///
dn: cn=admin,ou=groups,dc=thisbox
changetype: modify
add: uniqueMember
uniqueMember: uid=$username,ou=users,dc=thisbox
EOF
fi