Rootmanual:ldap: Skillnad mellan sidversioner
Baafen (diskussion | bidrag) (Skapade sidan med 'Place holder for LDAP') |
Net4all (diskussion | bidrag) Ingen redigeringssammanfattning |
||
Rad 1: | Rad 1: | ||
= Useful documentation = |
|||
Place holder for LDAP |
|||
https://wiki.debian.org/LDAP/OpenLDAPSetup |
|||
http://www.openldap.org/doc/admin22/index.html |
|||
http://www.zytrax.com/books/ldap/ch6/slapd-config.html |
|||
= Bootstrap slapd = |
|||
First install debian, configure the network and run puppet. |
|||
Please see ldap-server in the lysator puppet git repo. |
|||
Now, slapd needs to be reconfigured (mainly to set ldap admin password). |
|||
Run this: |
|||
dpkg-reconfigure -plow slapd |
|||
Example answers, note the password <ldap-admin>. |
|||
Omit OpenLDAP server configuration? no |
|||
DNS nomain name: lysator.liu.se |
|||
Organization name: lysator.liu.se |
|||
Administrator password: <ldap-admin> |
|||
Database backend to use: MDB |
|||
Remove database when slapd is purged: no |
|||
Move old database: yes |
|||
Allow ldapv2 protocol: no |
|||
Last, make sure slapd is running: |
|||
service slapd start |
|||
You should see this in /var/log/syslog: |
|||
<date> ldap slapd[XXX]: slapd starting |
|||
<data> ldap slapd[XXX]: Starting OpenLDAP: slapd. |
|||
= Configure slapd = |
|||
The OpenLDAP server (slapd) is configured by making changes to a database call |
|||
ed "cn=config". |
|||
We need to make a number of changes before we are ready to initialize the normal database with user data. |
|||
We make the changes by writing so called ldif files and applying them to the database with the ldapmodify tool. |
|||
ldapmodify -Y EXTERNAL -H ldapi:/// -f diff.ldif |
|||
For viewing changes we use the following: |
|||
ldapsearch -Y EXTERNAL -H ldapi:/// -b "cn=config" |
|||
== Configure more extensive indexing == |
|||
Configure slapd to use more indexing to improve performance. |
|||
Put this into indexing.ldif |
|||
dn: olcDatabase={1}hdb,cn=config |
|||
changetype: modify |
|||
add: olcDbIndex |
|||
olcDbIndex: cn pres,sub,eq |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: sn pres,sub,eq |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: uid pres,sub,eq |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: displayName pres,sub,eq |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: default sub |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: uidNumber eq |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: gidNumber eq |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: mail,givenName eq,subinitial |
|||
- |
|||
add: olcDbIndex |
|||
olcDbIndex: dc eq |
|||
Run this: |
|||
ldapmodify -Y EXTERNAL -H ldapi:/// -f indexing.ldif |
|||
== Configure SASL/SSL == |
|||
== Import POSIX User schema ? == |
|||
== Import AUTOFS schema == |
|||
= Importing data from NIS = |
|||
* Import from nis scripts. |
|||
* Autofs conversion. |
|||
* Character conversion. |
Versionen från 11 december 2015 kl. 20.00
Useful documentation
https://wiki.debian.org/LDAP/OpenLDAPSetup
http://www.openldap.org/doc/admin22/index.html
http://www.zytrax.com/books/ldap/ch6/slapd-config.html
Bootstrap slapd
First install debian, configure the network and run puppet. Please see ldap-server in the lysator puppet git repo.
Now, slapd needs to be reconfigured (mainly to set ldap admin password). Run this:
dpkg-reconfigure -plow slapd
Example answers, note the password <ldap-admin>.
Omit OpenLDAP server configuration? no DNS nomain name: lysator.liu.se Organization name: lysator.liu.se Administrator password: <ldap-admin> Database backend to use: MDB Remove database when slapd is purged: no Move old database: yes Allow ldapv2 protocol: no
Last, make sure slapd is running:
service slapd start
You should see this in /var/log/syslog:
<date> ldap slapd[XXX]: slapd starting ldap slapd[XXX]: Starting OpenLDAP: slapd.
Configure slapd
The OpenLDAP server (slapd) is configured by making changes to a database call ed "cn=config".
We need to make a number of changes before we are ready to initialize the normal database with user data.
We make the changes by writing so called ldif files and applying them to the database with the ldapmodify tool.
ldapmodify -Y EXTERNAL -H ldapi:/// -f diff.ldif
For viewing changes we use the following:
ldapsearch -Y EXTERNAL -H ldapi:/// -b "cn=config"
Configure more extensive indexing
Configure slapd to use more indexing to improve performance. Put this into indexing.ldif
dn: olcDatabase={1}hdb,cn=config changetype: modify add: olcDbIndex olcDbIndex: cn pres,sub,eq - add: olcDbIndex olcDbIndex: sn pres,sub,eq - add: olcDbIndex olcDbIndex: uid pres,sub,eq - add: olcDbIndex olcDbIndex: displayName pres,sub,eq - add: olcDbIndex olcDbIndex: default sub - add: olcDbIndex olcDbIndex: uidNumber eq - add: olcDbIndex olcDbIndex: gidNumber eq - add: olcDbIndex olcDbIndex: mail,givenName eq,subinitial - add: olcDbIndex olcDbIndex: dc eq
Run this:
ldapmodify -Y EXTERNAL -H ldapi:/// -f indexing.ldif
Configure SASL/SSL
Import POSIX User schema ?
Import AUTOFS schema
Importing data from NIS
- Import from nis scripts.
- Autofs conversion.
- Character conversion.