Compare commits
1 Commits
56a2c8464f
..
master
| Author | SHA1 | Date | |
|---|---|---|---|
| 6e086dbac0 |
@@ -3201,6 +3201,9 @@ samba_user: []
|
|||||||
|
|
||||||
base_home: /home
|
base_home: /home
|
||||||
|
|
||||||
|
# include vfs object 'virusfilter' to (private) homes shares
|
||||||
|
samba_homes_virusfilter: false
|
||||||
|
|
||||||
# remove_samba_users:
|
# remove_samba_users:
|
||||||
# - name: name1
|
# - name: name1
|
||||||
# - name: name2
|
# - name: name2
|
||||||
|
|||||||
@@ -495,6 +495,11 @@ samba_user:
|
|||||||
- gubitz-partner
|
- gubitz-partner
|
||||||
password: '20.mal-te/26%'
|
password: '20.mal-te/26%'
|
||||||
|
|
||||||
|
- name: jovis
|
||||||
|
groups:
|
||||||
|
- intern
|
||||||
|
password: '20.jo-vis_26!'
|
||||||
|
|
||||||
- name: hh-lucke
|
- name: hh-lucke
|
||||||
groups: []
|
groups: []
|
||||||
password: 'Ole20Steffen_17'
|
password: 'Ole20Steffen_17'
|
||||||
|
|||||||
@@ -643,6 +643,8 @@ samba_user:
|
|||||||
|
|
||||||
base_home: /data/home
|
base_home: /data/home
|
||||||
|
|
||||||
|
samba_homes_virusfilter: true
|
||||||
|
|
||||||
remove_samba_users:
|
remove_samba_users:
|
||||||
- name: howe-staff-1
|
- name: howe-staff-1
|
||||||
- name: gerhard
|
- name: gerhard
|
||||||
|
|||||||
@@ -1,24 +1,23 @@
|
|||||||
---
|
---
|
||||||
|
|
||||||
# ---
|
# ---
|
||||||
# Samba Server
|
# Samba Server
|
||||||
# ---
|
# ---
|
||||||
|
|
||||||
- name: (samba-install.yml) Ensure samba packages server are installed.
|
- name: (samba-config-server.yml) Ensure samba packages server are installed.
|
||||||
package:
|
package:
|
||||||
pkg: '{{ apt_install_server_samba }}'
|
pkg: "{{ apt_install_server_samba }}"
|
||||||
state: present
|
state: present
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
tags:
|
tags:
|
||||||
- samba-server
|
- samba-server
|
||||||
|
|
||||||
- name: (samba-install.yml) Ensure quarantine directory exists
|
- name: (samba-config-server.yml) Ensure quarantine directory exists
|
||||||
file:
|
file:
|
||||||
path: /data/samba/QUARANTINE
|
path: /data/samba/QUARANTINE
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: '0750'
|
mode: "0750"
|
||||||
state: directory
|
state: directory
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
@@ -37,7 +36,7 @@
|
|||||||
recurse: no
|
recurse: no
|
||||||
with_items: "{{ samba_shares }}"
|
with_items: "{{ samba_shares }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
label: '{{ item.name }}'
|
label: "{{ item.name }}"
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
tags:
|
tags:
|
||||||
@@ -47,9 +46,9 @@
|
|||||||
# Virusfilter (ClamAV) - only when at least one share has vfs_object_virusfilter: true
|
# Virusfilter (ClamAV) - only when at least one share has vfs_object_virusfilter: true
|
||||||
# ---
|
# ---
|
||||||
|
|
||||||
- name: (samba-install.yml) Ensure virusfilter (ClamAV) packages are installed
|
- name: (samba-config-server.yml) Ensure virusfilter (ClamAV) packages are installed
|
||||||
package:
|
package:
|
||||||
pkg: '{{ apt_install_server_samba_virusfilter }}'
|
pkg: "{{ apt_install_server_samba_virusfilter }}"
|
||||||
state: present
|
state: present
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
@@ -58,7 +57,7 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Check if ClamAV virus databases are present
|
- name: (samba-config-server.yml) Check if ClamAV virus databases are present
|
||||||
find:
|
find:
|
||||||
paths: /var/lib/clamav
|
paths: /var/lib/clamav
|
||||||
patterns:
|
patterns:
|
||||||
@@ -72,7 +71,7 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Stop clamav-freshclam service before initial database download
|
- name: (samba-config-server.yml) Stop clamav-freshclam service before initial database download
|
||||||
service:
|
service:
|
||||||
name: clamav-freshclam
|
name: clamav-freshclam
|
||||||
state: stopped
|
state: stopped
|
||||||
@@ -85,7 +84,20 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Download initial ClamAV virus databases via freshclam
|
- name: (samba-config-server.yml) Ensure clamav-daemon service is started before database update
|
||||||
|
service:
|
||||||
|
name: clamav-daemon
|
||||||
|
state: started
|
||||||
|
enabled: yes
|
||||||
|
failed_when: false
|
||||||
|
when:
|
||||||
|
- inventory_hostname in groups['samba_server']
|
||||||
|
- samba_shares | selectattr('vfs_object_virusfilter', 'defined') | selectattr('vfs_object_virusfilter', 'equalto', true) | list | length > 0
|
||||||
|
tags:
|
||||||
|
- samba-server
|
||||||
|
- samba-virusfilter
|
||||||
|
|
||||||
|
- name: (samba-config-server.yml) Download initial ClamAV virus databases via freshclam
|
||||||
command: freshclam
|
command: freshclam
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
@@ -95,13 +107,11 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Ensure clamav-daemon and clamav-freshclam services are enabled
|
- name: (samba-config-server.yml) Ensure clamav-daemon service is enabled and started
|
||||||
service:
|
service:
|
||||||
name: "{{ item }}"
|
name: clamav-daemon
|
||||||
|
state: started
|
||||||
enabled: yes
|
enabled: yes
|
||||||
loop:
|
|
||||||
- clamav-daemon
|
|
||||||
- clamav-freshclam
|
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
- samba_shares | selectattr('vfs_object_virusfilter', 'defined') | selectattr('vfs_object_virusfilter', 'equalto', true) | list | length > 0
|
- samba_shares | selectattr('vfs_object_virusfilter', 'defined') | selectattr('vfs_object_virusfilter', 'equalto', true) | list | length > 0
|
||||||
@@ -109,7 +119,19 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Ensure clamav user is member of all Samba groups
|
- name: (samba-config-server.yml) Ensure clamav-freshclam service is enabled and started
|
||||||
|
service:
|
||||||
|
name: clamav-freshclam
|
||||||
|
state: started
|
||||||
|
enabled: yes
|
||||||
|
when:
|
||||||
|
- inventory_hostname in groups['samba_server']
|
||||||
|
- samba_shares | selectattr('vfs_object_virusfilter', 'defined') | selectattr('vfs_object_virusfilter', 'equalto', true) | list | length > 0
|
||||||
|
tags:
|
||||||
|
- samba-server
|
||||||
|
- samba-virusfilter
|
||||||
|
|
||||||
|
- name: (samba-config-server.yml) Ensure clamav user is member of all Samba groups
|
||||||
user:
|
user:
|
||||||
name: clamav
|
name: clamav
|
||||||
groups: "{{ item.name }}"
|
groups: "{{ item.name }}"
|
||||||
@@ -126,17 +148,62 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Configure AppArmor local profile for clamd (data paths)
|
- name: (samba-config-server.yml) Ensure clamav user is member of all Samba user groups (homes virusfilter)
|
||||||
blockinfile:
|
user:
|
||||||
path: /etc/apparmor.d/local/usr.sbin.clamd
|
name: clamav
|
||||||
create: yes
|
groups: "{{ item.name }}"
|
||||||
|
append: yes
|
||||||
|
loop: "{{ samba_user }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.name }}"
|
||||||
|
when:
|
||||||
|
- inventory_hostname in groups['samba_server']
|
||||||
|
- samba_homes_virusfilter | default(false) | bool
|
||||||
|
- samba_user | length > 0
|
||||||
|
tags:
|
||||||
|
- samba-server
|
||||||
|
- samba-virusfilter
|
||||||
|
|
||||||
|
- name: (samba-config-server.yml) Get home directories of samba users via getent (homes virusfilter)
|
||||||
|
ansible.builtin.getent:
|
||||||
|
database: passwd
|
||||||
|
key: "{{ item.name }}"
|
||||||
|
loop: "{{ samba_user }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.name }}"
|
||||||
|
register: samba_user_getent
|
||||||
|
when:
|
||||||
|
- inventory_hostname in groups['samba_server']
|
||||||
|
- samba_homes_virusfilter | default(false) | bool
|
||||||
|
- samba_user | length > 0
|
||||||
|
tags:
|
||||||
|
- samba-server
|
||||||
|
- samba-virusfilter
|
||||||
|
|
||||||
|
- name: (samba-config-server.yml) Ensure home directories are group-traversable for clamd (homes virusfilter)
|
||||||
|
file:
|
||||||
|
path: "{{ item.ansible_facts.getent_passwd[item.item.name][4] }}"
|
||||||
|
mode: "0750"
|
||||||
|
state: directory
|
||||||
|
loop: "{{ samba_user_getent.results | default([]) }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.item.name }}"
|
||||||
|
when:
|
||||||
|
- inventory_hostname in groups['samba_server']
|
||||||
|
- samba_homes_virusfilter | default(false) | bool
|
||||||
|
- item.ansible_facts is defined
|
||||||
|
tags:
|
||||||
|
- samba-server
|
||||||
|
- samba-virusfilter
|
||||||
|
|
||||||
|
|
||||||
|
- name: (samba-config-server.yml) Configure AppArmor local profile for clamd (data paths)
|
||||||
|
template:
|
||||||
|
src: etc/apparmor.d/local/usr.sbin.clamd.j2
|
||||||
|
dest: /etc/apparmor.d/local/usr.sbin.clamd
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: "0644"
|
mode: "0644"
|
||||||
marker: "# {mark} ANSIBLE MANAGED - smba virusfilter paths"
|
|
||||||
block: |
|
|
||||||
/data/** r,
|
|
||||||
/data/samba/QUARANTINE/** rw,
|
|
||||||
notify: Reload AppArmor profile clamd
|
notify: Reload AppArmor profile clamd
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
@@ -146,7 +213,7 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
- name: (samba-install.yml) Ensure AllowAllMatchScan is enabled in clamd.conf
|
- name: (samba-config-server.yml) Ensure AllowAllMatchScan is enabled in clamd.conf
|
||||||
lineinfile:
|
lineinfile:
|
||||||
path: /etc/clamav/clamd.conf
|
path: /etc/clamav/clamd.conf
|
||||||
regexp: "^#?\\s*AllowAllMatchScan\\s"
|
regexp: "^#?\\s*AllowAllMatchScan\\s"
|
||||||
@@ -161,7 +228,6 @@
|
|||||||
- samba-server
|
- samba-server
|
||||||
- samba-virusfilter
|
- samba-virusfilter
|
||||||
|
|
||||||
|
|
||||||
# ---
|
# ---
|
||||||
# /etc/samba/smb.conf
|
# /etc/samba/smb.conf
|
||||||
# ---
|
# ---
|
||||||
@@ -241,7 +307,7 @@
|
|||||||
- name: (samba-config-server.yml) Check if cleaning up trash dirs is configured
|
- name: (samba-config-server.yml) Check if cleaning up trash dirs is configured
|
||||||
ansible.builtin.lineinfile:
|
ansible.builtin.lineinfile:
|
||||||
path: /root/bin/samba/conf/clean_samba_trash.conf
|
path: /root/bin/samba/conf/clean_samba_trash.conf
|
||||||
regexp: '^trash_dirs=*'
|
regexp: "^trash_dirs=*"
|
||||||
state: absent
|
state: absent
|
||||||
check_mode: true
|
check_mode: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
@@ -299,7 +365,5 @@
|
|||||||
job: "{{ samba_cronjob_permissions.job }}"
|
job: "{{ samba_cronjob_permissions.job }}"
|
||||||
when:
|
when:
|
||||||
- inventory_hostname in groups['samba_server']
|
- inventory_hostname in groups['samba_server']
|
||||||
- (clean_samba_trash_dirs.found | int) > 0 # << int -> bool
|
- (clean_samba_trash_dirs.found | int) > 0 # << int -> bool
|
||||||
tags: [samba-server, samba-cron]
|
tags: [samba-server, samba-cron]
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
# {{ ansible_managed }}
|
||||||
|
# see: roles/common/tasks/samba-config-server.yml
|
||||||
|
|
||||||
|
/data/** r,
|
||||||
|
/data/samba/QUARANTINE/** rw,
|
||||||
|
{% if samba_homes_virusfilter | default(false) | bool %}
|
||||||
|
{{ base_home }}/** r,
|
||||||
|
{% if base_home != '/home' %}
|
||||||
|
/home/** r,
|
||||||
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
@@ -305,6 +305,14 @@
|
|||||||
# next parameter to 'no' if you want to be able to write to them.
|
# next parameter to 'no' if you want to be able to write to them.
|
||||||
read only = no
|
read only = no
|
||||||
|
|
||||||
|
{% if samba_homes_virusfilter | default(false) | bool %}
|
||||||
|
# Virusfilter aktiv: Gruppe benötigt Leserecht, damit clamd (als Gruppenmitglied)
|
||||||
|
# Dateien und Verzeichnisse direkt öffnen kann (SCAN-Kommando an clamd).
|
||||||
|
create mask = 0640
|
||||||
|
force create mode = 0040
|
||||||
|
directory mask = 0750
|
||||||
|
force directory mode = 0050
|
||||||
|
{% else %}
|
||||||
# File creation mask is set to 0700 for security reasons. If you want to
|
# File creation mask is set to 0700 for security reasons. If you want to
|
||||||
# create files with group=rw permissions, set next parameter to 0775.
|
# create files with group=rw permissions, set next parameter to 0775.
|
||||||
create mask = 0700
|
create mask = 0700
|
||||||
@@ -312,6 +320,7 @@
|
|||||||
# Directory creation mask is set to 0700 for security reasons. If you want to
|
# Directory creation mask is set to 0700 for security reasons. If you want to
|
||||||
# create dirs. with group=rw permissions, set next parameter to 0775.
|
# create dirs. with group=rw permissions, set next parameter to 0775.
|
||||||
directory mask = 0700
|
directory mask = 0700
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
# By default, \\server\username shares can be connected to by anyone
|
# By default, \\server\username shares can be connected to by anyone
|
||||||
# with access to the samba server.
|
# with access to the samba server.
|
||||||
@@ -319,6 +328,35 @@
|
|||||||
# to \\server\username
|
# to \\server\username
|
||||||
# This might need tweaking when using external authentication schemes
|
# This might need tweaking when using external authentication schemes
|
||||||
valid users = %S
|
valid users = %S
|
||||||
|
{% if samba_homes_virusfilter | default(false) | bool %}
|
||||||
|
|
||||||
|
# --- Virusfilter-Einstellungen [homes] ---
|
||||||
|
|
||||||
|
vfs objects = virusfilter
|
||||||
|
|
||||||
|
virusfilter:scanner = clamav
|
||||||
|
virusfilter:socket path = /var/run/clamav/clamd.ctl
|
||||||
|
|
||||||
|
virusfilter:infected file action = delete
|
||||||
|
|
||||||
|
virusfilter:cache entry limit = 1000
|
||||||
|
virusfilter:cache time limit = 60
|
||||||
|
|
||||||
|
virusfilter:max file size = 26214400
|
||||||
|
virusfilter:min file size = 10
|
||||||
|
|
||||||
|
virusfilter:scan on open = yes
|
||||||
|
virusfilter:scan on close = yes
|
||||||
|
|
||||||
|
# Fehlercode bei infizierter Datei (beim Öffnen)
|
||||||
|
virusfilter:infected file errno on open = EACCES
|
||||||
|
|
||||||
|
# Fehlercode beim Schließen
|
||||||
|
virusfilter:infected file errno on close = EACCES
|
||||||
|
|
||||||
|
virusfilter:connect timeout = 30000
|
||||||
|
virusfilter:io timeout = 60000
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
# Un-comment the following and create the netlogon directory for Domain Logons
|
# Un-comment the following and create the netlogon directory for Domain Logons
|
||||||
# (you need to configure Samba to act as a domain controller too.)
|
# (you need to configure Samba to act as a domain controller too.)
|
||||||
@@ -489,7 +527,13 @@
|
|||||||
|
|
||||||
# Scan-Zeitpunkt: nur beim Öffnen, nicht beim Schließen
|
# Scan-Zeitpunkt: nur beim Öffnen, nicht beim Schließen
|
||||||
virusfilter:scan on open = yes
|
virusfilter:scan on open = yes
|
||||||
virusfilter:scan on close = no
|
virusfilter:scan on close = yes
|
||||||
|
|
||||||
|
# Fehlercode bei infizierter Datei (beim Öffnen)
|
||||||
|
virusfilter:infected file errno on open = EACCES
|
||||||
|
|
||||||
|
# Fehlercode beim Schließen
|
||||||
|
virusfilter:infected file errno on close = EACCES
|
||||||
|
|
||||||
# Timeouts (Millisekunden)
|
# Timeouts (Millisekunden)
|
||||||
virusfilter:connect timeout = 30000
|
virusfilter:connect timeout = 30000
|
||||||
|
|||||||
Reference in New Issue
Block a user