LoginSudoGroups.sh 630 B

1234567891011121314151617
  1. #!/bin/bash
  2. # Load configuration file
  3. source config.sh
  4. # Deny login to all users
  5. sudo realm deny --all
  6. # Allow login to domain groups
  7. sudo realm permit -g "Domain Admins"
  8. sudo realm permit -g "Access - Admin - All Servers"
  9. sudo realm permit -g "Access - Admin - $NEW_HOSTNAME"
  10. # Set up sudoers file
  11. echo "%Domain\ Admins ALL=(ALL:ALL) ALL" | sudo tee /etc/sudoers.d/LocalAdmins > /dev/null
  12. echo "%Access\ -\ Admin\ -\ All\ Servers ALL=(ALL) ALL" | sudo tee -a /etc/sudoers.d/LocalAdmins > /dev/null
  13. echo "%Access\ -\ Admin\ -\ $NEW_HOSTNAME ALL=(ALL) ALL" | sudo tee -a /etc/sudoers.d/LocalAdmins > /dev/null