config { profiles: { CONTRACT: { servers: [ "dc-11.office.daily","dc-12.office.daily","dc-13.office.daily" ] baseDN: "ou=Users_External,OU=Dailymotion,DC=office,DC=daily", bindCn: "CN=VPN Service,OU=Services,OU=Dailymotion,DC=office,DC=daily", bindPw: "********************", searchFilter: "(&(sAMAccountName=%s))" primaryAttribute: "memberOf" secondaryAttribute: "mail" validGroups: [ "CN=SEC_VPN_Users_External,OU=Security,OU=Groups,OU=Dailymotion,DC=office,DC=daily", ] mfa: "okta" cert: "ignore" IPRange: "192.168.207.1 - 192.168.207.254", routes: [ "10.189.10.9 255.255.255.255", "10.190.32.2 255.255.255.255", "10.190.32.20 255.255.255.255", "10.190.22.1 255.255.255.255", "10.190.22.2 255.255.255.255", "188.65.124.35 255.255.255.255", "195.8.215.129 255.255.255.255", "195.8.215.140 255.255.255.255", "10.190.52.100 255.255.255.255", "10.190.62.150 255.255.255.255", ] } CORP: { servers: [ "dc-11.office.daily","dc-12.office.daily","dc-13.office.daily" ] baseDN: "OU=Dailymotion,DC=office,DC=daily", bindCn: "CN=VPN Service,OU=Services,OU=Dailymotion,DC=office,DC=daily", bindPw: "********************", searchFilter: "(&(sAMAccountName=%s))" primaryAttribute: "memberOf" secondaryAttribute: "mail" validGroups: [ "CN=SEC_VPN,OU=Security,OU=Groups,OU=Dailymotion,DC=office,DC=daily", ] mfa: "okta" cert: "optionnal" IPRange: "192.168.201.1-192.168.203.254" } DEV: { servers: [ "ldap-auth.vip.dailymotion.com" ] baseDN: "dc=dailymotion,dc=com" bindCn: "cn=readonly,dc=dailymotion,dc=com" bindPw: "**********" searchFilter: "(&(mail=%s))" primaryAttribute: "description" secondaryAttribute: "sshPublicKey" upgradeFrom: "CORP" mfa: "" cert: "optionnal" IPRange: "192.168.204.1-192.168.206.254" routes: [ "10.190.32.51 255.255.255.255", ] } ADMINS: { validGroups: [ "infra2", "net", "datacenter", ] upgradeFrom: "DEV" mfa: "internal" cert: "mandatory" IPRange: "192.168.200.2-192.168.200.254" } } openvpnPort: "127.0.0.1:4000" httpPort: ":8443" httpCa: "/usr/local/share/ca-certificates/Dailymotion.crt" httpKey: "/etc/ssl/private/server-key.pem" httpCert: "/etc/ssl/certs/server-bundle.pem" cacheDir: "/var/run/openvpn/" authCa: "/usr/local/share/ca-certificates/Dailymotion.crt" masterSecrets: [ "********************************"] vpnLogUrl: "https://install.dm.gg/vpn-log.php" mailRelay: "mailrelay.dailymotion.com:25" mailFrom: "engineering-infra@dailymotion.com" ccPwnPassword: "security-incident-report@dailymotion.com" pwnTemplate: "Mime-Version: 1.0;\nContent-Type: text/html; charset=\"ISO-8859-1\";\nContent-Transfer-Encoding: 7bit;\nFrom: {{.MailFrom}}\nSubject: [Dailymotion] Your current okta password is compromised\nTo: {{.Mail}}\nCc: {{.CcPwnPassword}}\n\n
Hello