config { profiles: { CONTRACT: { servers: [ "dc-11.office.daily","dc-12.office.daily","dc-13.office.daily" ] baseDN: "ou=Users_External,OU=Dailymotion,DC=office,DC=daily", bindCn: "CN=VPN Service,OU=Services,OU=Dailymotion,DC=office,DC=daily", bindPw: "********************", searchFilter: "(&(sAMAccountName=%s))" primaryAttribute: "memberOf" secondaryAttribute: "mail" validGroups: [ "CN=SEC_VPN_Users_External,OU=Security,OU=Groups,OU=Dailymotion,DC=office,DC=daily", ] otp: "okta" cert: "ignore" ip_range: "192.168.207.1 - 192.168.207.254", routes: [ "10.189.10.9 255.255.255.255", "10.190.32.2 255.255.255.255", "10.190.32.20 255.255.255.255", "10.190.22.1 255.255.255.255", "10.190.22.2 255.255.255.255", "188.65.124.35 255.255.255.255", "195.8.215.129 255.255.255.255", "195.8.215.140 255.255.255.255", "10.190.52.100 255.255.255.255", "10.190.62.150 255.255.255.255", ] } CORP: { servers: [ "dc-11.office.daily","dc-12.office.daily","dc-13.office.daily" ] baseDN: "OU=Dailymotion,DC=office,DC=daily", bindCn: "CN=VPN Service,OU=Services,OU=Dailymotion,DC=office,DC=daily", bindPw: "********************", searchFilter: "(&(sAMAccountName=%s))" primaryAttribute: "memberOf" secondaryAttribute: "mail" validGroups: [ "CN=SEC_VPN,OU=Security,OU=Groups,OU=Dailymotion,DC=office,DC=daily", ] otp: "okta" cert: "optionnal" upgrade-to: "DEV" ip_range: "192.168.201.1 - 192.168.203.254" } DEV: { servers: [ "ldap-auth.vip.dailymotion.com" ] baseDN: "dc=dailymotion,dc=com" bindCn: "cn=readonly,dc=dailymotion,dc=com" bindPw: "**********" searchFilter: "(&(mail=%s))" primaryAttribute: "description" secondaryAttribute: "sshPublicKey" upgrade-from: "CORP" upgrade-to: "ADMINS" otp: "okta" cert: "optionnal" ip_range: "192.168.204.1 - 192.168.206.254" } ADMINS: { validGroups: [ "infra", "net", "datacenter", ] upgrade-from: "DEV" otp: [ "internal", "slack" ] cert: "mandatory" ip_range: "192.168.200.2 - 192.168.200.254" } } cacheDir: "/var/run/openvpn/" masterSecrets: [ "*******************************J" ] vpnLogUrl: "https://install.dm.gg/vpn-log.php" slackToken: "*************************************************************************" slackChannels: [ "#squad-it-office" ] configParser: "/etc/openvpn/roadwarrior_([a-zA-Z0-9]*).conf" mailRelay: "mailrelay.dailymotion.com:25" mailFrom: "engineering-infra@dailymotion.com" ccPwnPassword: "security-incident-report@dailymotion.com" pwnTemplate: "Mime-Version: 1.0;\nContent-Type: text/html; charset=\"ISO-8859-1\";\nContent-Transfer-Encoding: 7bit;\nFrom: {{.MailFrom}}\nSubject: [Dailymotion] Your current okta password is compromised\nTo: {{.Mail}}\nCc: {{.CcPwnPassword}}\n\n
Hello