Skip to content
Snippets Groups Projects
Commit 7b2701b9 authored by Rafael Guterres Jeffman's avatar Rafael Guterres Jeffman
Browse files

ipapwpolicy: Updated module documentation.

Most of ipapwpolicy parameters can be set to an empty string ("") so
that the policy is not applied to pwpolicy. This was not refelected on
the documentation.

This change adds 'or ""' to all the fields that can be disabled by
setting it to an empty string. Also, `data types were reviewed and fixed.
parent 694c7178
No related branches found
No related tags found
No related merge requests found
...@@ -128,20 +128,20 @@ Variable | Description | Required ...@@ -128,20 +128,20 @@ Variable | Description | Required
`ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no `ipaapi_context` | The context in which the module will execute. Executing in a server context is preferred. If not provided context will be determined by the execution environment. Valid values are `server` and `client`. | no
`ipaapi_ldap_cache` | Use LDAP cache for IPA connection. The bool setting defaults to yes. (bool) | no `ipaapi_ldap_cache` | Use LDAP cache for IPA connection. The bool setting defaults to yes. (bool) | no
`name` \| `cn` | The list of pwpolicy name strings. If name is not given, `global_policy` will be used automatically. | no `name` \| `cn` | The list of pwpolicy name strings. If name is not given, `global_policy` will be used automatically. | no
`maxlife` \| `krbmaxpwdlife` | Maximum password lifetime in days. (int) | no `maxlife` \| `krbmaxpwdlife` | Maximum password lifetime in days. (int or "") | no
`minlife` \| `krbminpwdlife` | Minimum password lifetime in hours. (int) | no `minlife` \| `krbminpwdlife` | Minimum password lifetime in hours. (int or "") | no
`history` \| `krbpwdhistorylength` | Password history size. (int) | no `history` \| `krbpwdhistorylength` | Password history size. (int or "") | no
`minclasses` \| `krbpwdmindiffchars` | Minimum number of character classes. (int) | no `minclasses` \| `krbpwdmindiffchars` | Minimum number of character classes. (int or "") | no
`minlength` \| `krbpwdminlength` | Minimum length of password. (int) | no `minlength` \| `krbpwdminlength` | Minimum length of password. (int or "") | no
`priority` \| `cospriority` | Priority of the policy, higher number means lower priority. (int) | no `priority` \| `cospriority` | Priority of the policy, higher number means lower priority. (int or "") | no
`maxfail` \| `krbpwdmaxfailure` | Consecutive failures before lockout. (int) | no `maxfail` \| `krbpwdmaxfailure` | Consecutive failures before lockout. (int or "") | no
`failinterval` \| `krbpwdfailurecountinterval` | Period after which failure count will be reset in seconds. (int) | no `failinterval` \| `krbpwdfailurecountinterval` | Period after which failure count will be reset in seconds. (int or "") | no
`lockouttime` \| `krbpwdlockoutduration` | Period for which lockout is enforced in seconds. (int) | no `lockouttime` \| `krbpwdlockoutduration` | Period for which lockout is enforced in seconds. (int or "") | no
`maxrepeat` \| `ipapwdmaxrepeat` | Maximum number of same consecutive characters. Requires IPA 4.9+ (int) | no `maxrepeat` \| `ipapwdmaxrepeat` | Maximum number of same consecutive characters. Requires IPA 4.9+ (int or "") | no
`maxsequence` \| `ipapwdmaxsequence` | The maximum length of monotonic character sequences (abcd). Requires IPA 4.9+ (int) | no `maxsequence` \| `ipapwdmaxsequence` | The maximum length of monotonic character sequences (abcd). Requires IPA 4.9+ (int or "") | no
`dictcheck` \| `ipapwdictcheck` | Check if the password is a dictionary word. Requires IPA 4.9+ (int) | no `dictcheck` \| `ipapwdictcheck` | Check if the password is a dictionary word. Requires IPA 4.9+. (bool or "") | no
`usercheck` \| `ipapwdusercheck` | Check if the password contains the username. Requires IPA 4.9+ (int) | no `usercheck` \| `ipapwdusercheck` | Check if the password contains the username. Requires IPA 4.9+. (bool or "") | no
`gracelimit` \| `passwordgracelimit` | Number of LDAP authentications allowed after expiration. Requires IPA 4.9.10 (int) | no `gracelimit` \| `passwordgracelimit` | Number of LDAP authentications allowed after expiration. Requires IPA 4.9.10 (int or "") | no
`state` | The state to ensure. It can be one of `present` or `absent`, default: `present`. | yes `state` | The state to ensure. It can be one of `present` or `absent`, default: `present`. | yes
......
...@@ -45,82 +45,84 @@ options: ...@@ -45,82 +45,84 @@ options:
required: false required: false
aliases: ["cn"] aliases: ["cn"]
maxlife: maxlife:
description: Maximum password lifetime (in days) description: Maximum password lifetime (in days). (int or "")
type: str type: str
required: false required: false
aliases: ["krbmaxpwdlife"] aliases: ["krbmaxpwdlife"]
minlife: minlife:
description: Minimum password lifetime (in hours) description: Minimum password lifetime (in hours). (int or "")
type: str type: str
required: false required: false
aliases: ["krbminpwdlife"] aliases: ["krbminpwdlife"]
history: history:
description: Password history size description: Password history size. (int or "")
type: str type: str
required: false required: false
aliases: ["krbpwdhistorylength"] aliases: ["krbpwdhistorylength"]
minclasses: minclasses:
description: Minimum number of character classes description: Minimum number of character classes. (int or "")
type: str type: str
required: false required: false
aliases: ["krbpwdmindiffchars"] aliases: ["krbpwdmindiffchars"]
minlength: minlength:
description: Minimum length of password description: Minimum length of password. (int or "")
type: str type: str
required: false required: false
aliases: ["krbpwdminlength"] aliases: ["krbpwdminlength"]
priority: priority:
description: Priority of the policy (higher number means lower priority) description: >
Priority of the policy (higher number means lower priority). (int or "")
type: str type: str
required: false required: false
aliases: ["cospriority"] aliases: ["cospriority"]
maxfail: maxfail:
description: Consecutive failures before lockout description: Consecutive failures before lockout. (int or "")
type: str type: str
required: false required: false
aliases: ["krbpwdmaxfailure"] aliases: ["krbpwdmaxfailure"]
failinterval: failinterval:
description: Period after which failure count will be reset (seconds) description: >
Period after which failure count will be reset (seconds). (int or "")
type: str type: str
required: false required: false
aliases: ["krbpwdfailurecountinterval"] aliases: ["krbpwdfailurecountinterval"]
lockouttime: lockouttime:
description: Period for which lockout is enforced (seconds) description: Period for which lockout is enforced (seconds). (int or "")
type: str type: str
required: false required: false
aliases: ["krbpwdlockoutduration"] aliases: ["krbpwdlockoutduration"]
maxrepeat: maxrepeat:
description: > description: >
Maximum number of same consecutive characters. Maximum number of same consecutive characters.
Requires IPA 4.9+ Requires IPA 4.9+. (int or "")
type: str type: str
required: false required: false
aliases: ["ipapwdmaxrepeat"] aliases: ["ipapwdmaxrepeat"]
maxsequence: maxsequence:
description: > description: >
The maximum length of monotonic character sequences (abcd). The maximum length of monotonic character sequences (abcd).
Requires IPA 4.9+ Requires IPA 4.9+. (int or "")
type: str type: str
required: false required: false
aliases: ["ipapwdmaxsequence"] aliases: ["ipapwdmaxsequence"]
dictcheck: dictcheck:
description: > description: >
Check if the password is a dictionary word. Check if the password is a dictionary word.
Requires IPA 4.9+ Requires IPA 4.9+. (bool or "")
type: str type: str
required: false required: false
aliases: ["ipapwdictcheck"] aliases: ["ipapwdictcheck"]
usercheck: usercheck:
description: > description: >
Check if the password contains the username. Check if the password contains the username.
Requires IPA 4.9+ Requires IPA 4.9+. (bool or "")
type: str type: str
required: false required: false
aliases: ["ipapwdusercheck"] aliases: ["ipapwdusercheck"]
gracelimit: gracelimit:
description: > description: >
Number of LDAP authentications allowed after expiration. Number of LDAP authentications allowed after expiration.
Requires IPA 4.10.1+ Requires IPA 4.10.1+. (int or "")
type: str type: str
required: false required: false
aliases: ["passwordgracelimit"] aliases: ["passwordgracelimit"]
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment