[debops.nsswitch] Don't show 'shadow' LDAP data

The 'shadow' database LDAP information shouldn't be needed on the hosts.
Showing LDAP entries via the 'getent shadow' command can be confusing on
unprivileged accounts, therefore the database will not be included in
NSS switch table by default.
......@@ -89,7 +89,7 @@ nsswitch__combined_services: '{{ lookup("flattened", (nsswitch__default_services
'passwd': [ 'compat', 'mymachines', 'systemd', 'sss', 'ldap', 'winbind' ]
'group': [ 'compat', 'mymachines', 'systemd', 'sss', 'ldap', 'winbind' ]
'shadow': [ 'compat', 'sss', 'ldap' ]
'shadow': [ 'compat', 'sss' ]
'gshadow': [ 'files' ]
'initgroups': []
