[debops.slapd] Enable substring index for sudoUser

Without this, the hosts that read 'sudo' rules from LDAP can get
completely frozen with Ansible playbook executed via 'become' method due
to too much non-indexed queries to the LDAP directory.
drybjed committed Sep 4, 2019
1 parent 15c8963 commit 065bbf83d1f21fbd87451cc2f919787e0b73b7cb
:ref:`debops.slapd` role

- Enable substring index for the ``sudoUser`` attribute from the :ref:`sudo
LDAP schema <slapd__ref_sudo>`. Existing installations should be updated
manually via the LDAP client, by setting the value of the ``sudoUser`` index
to ``eq,sub``.

@@ -579,7 +579,7 @@ slapd__default_tasks:
- 'homeDirectory,loginShell eq'
- 'uidNumber,gidNumber eq'
- 'entryCSN,entryUUID eq'
- 'sudoUser eq'
- 'sudoUser eq,sub'

