Note
This plugin is part of the fortinet.fortimanager collection (version 2.1.3).
You might already have this collection installed if you are using the ansible
package. It is not included in ansible-core
. To check whether it is installed, run ansible-galaxy collection list
.
To install it, use: ansible-galaxy collection install fortinet.fortimanager
.
To use it in a playbook, specify: fortinet.fortimanager.fmgr_user_fsso
.
New in version 2.10: of fortinet.fortimanager
Parameter | Choices/Defaults | Comments | |||
---|---|---|---|---|---|
adom string / required | the parameter (adom) in requested url | ||||
bypass_validation boolean |
| only set to True when module schema diffs with FortiManager API structure, module continues to execute without validating parameters | |||
enable_log boolean |
| Enable/Disable logging for task | |||
proposed_method string |
| The overridden method for the underlying Json RPC request | |||
rc_failed list / elements=string | the rc codes list with which the conditions to fail will be overriden | ||||
rc_succeeded list / elements=string | the rc codes list with which the conditions to succeed will be overriden | ||||
state string / required |
| the directive to create, update or delete an object | |||
user_fsso dictionary | the top level parameters set | ||||
_gui_meta string | no description | ||||
dynamic_mapping list / elements=string | no description | ||||
_gui_meta string | no description | ||||
_scope list / elements=string | no description | ||||
name string | no description | ||||
vdom string | no description | ||||
group-poll-interval integer | no description | ||||
interface string | no description | ||||
interface-select-method string |
| no description | |||
ldap-poll string |
| no description | |||
ldap-poll-filter string | no description | ||||
ldap-poll-interval integer | no description | ||||
ldap-server string | no description | ||||
password string | no description | ||||
password2 string | no description | ||||
password3 string | no description | ||||
password4 string | no description | ||||
password5 string | no description | ||||
port integer | no description | ||||
port2 integer | no description | ||||
port3 integer | no description | ||||
port4 integer | no description | ||||
port5 integer | no description | ||||
server string | no description | ||||
server2 string | no description | ||||
server3 string | no description | ||||
server4 string | no description | ||||
server5 string | no description | ||||
source-ip string | no description | ||||
source-ip6 string | no description | ||||
ssl string |
| no description | |||
ssl-trusted-cert string | no description | ||||
type string |
| no description | |||
user-info-server string | no description | ||||
group-poll-interval integer | Interval in minutes within to fetch groups from FSSO server, or unset to disable. | ||||
interface string | Specify outgoing interface to reach server. | ||||
interface-select-method string |
| Specify how to select outgoing interface to reach server. | |||
ldap-poll string |
| Enable/disable automatic fetching of groups from LDAP server. | |||
ldap-poll-filter string | Filter used to fetch groups. | ||||
ldap-poll-interval integer | Interval in minutes within to fetch groups from LDAP server. | ||||
ldap-server string | LDAP server to get group information. | ||||
name string | Name. | ||||
password string | no description | ||||
password2 string | no description | ||||
password3 string | no description | ||||
password4 string | no description | ||||
password5 string | no description | ||||
port integer | Port of the first FSSO collector agent. | ||||
port2 integer | Port of the second FSSO collector agent. | ||||
port3 integer | Port of the third FSSO collector agent. | ||||
port4 integer | Port of the fourth FSSO collector agent. | ||||
port5 integer | Port of the fifth FSSO collector agent. | ||||
server string | Domain name or IP address of the first FSSO collector agent. | ||||
server2 string | Domain name or IP address of the second FSSO collector agent. | ||||
server3 string | Domain name or IP address of the third FSSO collector agent. | ||||
server4 string | Domain name or IP address of the fourth FSSO collector agent. | ||||
server5 string | Domain name or IP address of the fifth FSSO collector agent. | ||||
source-ip string | Source IP for communications to FSSO agent. | ||||
source-ip6 string | IPv6 source for communications to FSSO agent. | ||||
ssl string |
| Enable/disable use of SSL. | |||
ssl-trusted-cert string | Trusted server certificate or CA certificate. | ||||
type string |
| Server type. | |||
user-info-server string | LDAP server to get user information. | ||||
workspace_locking_adom string | the adom to lock for FortiManager running in workspace mode, the value can be global and others including root | ||||
workspace_locking_timeout integer | Default: 300 | the maximum time in seconds to wait for other user to release the workspace lock |
Note
- hosts: fortimanager-inventory collections: - fortinet.fortimanager connection: httpapi vars: ansible_httpapi_use_ssl: True ansible_httpapi_validate_certs: False ansible_httpapi_port: 443 tasks: - name: Configure Fortinet Single Sign On fmgr_user_fsso: bypass_validation: False workspace_locking_adom: <value in [global, custom adom including root]> workspace_locking_timeout: 300 rc_succeeded: [0, -2, -3, ...] rc_failed: [-2, -3, ...] adom: <your own value> state: <value in [present, absent]> user_fsso: _gui_meta: <value of string> dynamic_mapping: - _gui_meta: <value of string> _scope: - name: <value of string> vdom: <value of string> ldap-server: <value of string> password: <value of string> password2: <value of string> password3: <value of string> password4: <value of string> password5: <value of string> port: <value of integer> port2: <value of integer> port3: <value of integer> port4: <value of integer> port5: <value of integer> server: <value of string> server2: <value of string> server3: <value of string> server4: <value of string> server5: <value of string> source-ip: <value of string> source-ip6: <value of string> ssl: <value in [disable, enable]> ssl-trusted-cert: <value of string> type: <value in [default, fortiems, fortinac, ...]> user-info-server: <value of string> ldap-poll: <value in [disable, enable]> ldap-poll-filter: <value of string> ldap-poll-interval: <value of integer> group-poll-interval: <value of integer> interface: <value of string> interface-select-method: <value in [auto, sdwan, specify]> ldap-server: <value of string> name: <value of string> password: <value of string> password2: <value of string> password3: <value of string> password4: <value of string> password5: <value of string> port: <value of integer> port2: <value of integer> port3: <value of integer> port4: <value of integer> port5: <value of integer> server: <value of string> server2: <value of string> server3: <value of string> server4: <value of string> server5: <value of string> source-ip: <value of string> source-ip6: <value of string> ldap-poll: <value in [disable, enable]> ldap-poll-filter: <value of string> ldap-poll-interval: <value of integer> ssl: <value in [disable, enable]> ssl-trusted-cert: <value of string> type: <value in [default, fortiems, fortinac, ...]> user-info-server: <value of string> group-poll-interval: <value of integer> interface: <value of string> interface-select-method: <value in [auto, sdwan, specify]>
Common return values are documented here, the following are the fields unique to this module:
Key | Returned | Description |
---|---|---|
request_url string | always | The full url requested Sample: /sys/login/user |
response_code integer | always | The status of api request |
response_message string | always | The descriptive message of the api response Sample: OK. |
© 2012–2018 Michael DeHaan
© 2018–2021 Red Hat, Inc.
Licensed under the GNU General Public License version 3.
https://docs.ansible.com/ansible/latest/collections/fortinet/fortimanager/fmgr_user_fsso_module.html