1. 安裝openldap及ldap認證module
yum install openldap-servers openldap-devel openldap openldap-clients nss_ldap2. 複製範本至/etc/openldap內
cp /usr/share/openldap-servers/slapd.conf.obsolete slapd.conf3. 創建要存放ldap的目錄
mkdir /var/lib/ldap/niu4. 複製DB_CONFIG
cp /usr/share/openldap-servers/DB_CONFIG.example /var/lib/ldap/niu/DB_CONFIG5. 編輯slapd.conf設定檔
vim /etc/openldap/slapd.conf去除mark標誌(看是裝哪個版本的os)
x32: # modulepath /usr/lib/openldap => modulepath /usr/lib/openldap
x64: # modulepath /usr/lib64/openldap => modulepath /usr/lib64/openldap去除ppolicy.la的mark標誌 (用於密碼更改原則)
# moduleload ppolicy.la => moduleload ppolicy.la去除syncprov.la的mark標誌 (用於同步)
#moduleload syncprov.la => moduleload syncprov.la新增TLS連線設定
TLSCipherSuite HIGH:MEDIUM:+SSLv2:+SSLv3:RSA
TLSCACertificateFile /etc/openldap/cacerts/server.pem
TLSCertificateFile /etc/openldap/cacerts/server.pem
TLSCertificateKeyFile /etc/openldap/cacerts/server.pem
TLSVerifyClient allow新增ACL規則
access to attrs=userPassword
by self write
by anonymous auth
by dn.base="cn=Manager,ou=admin,dc=niu,dc=edu,dc=tw" write
by * noneaccess to *
by * read
by dn.base="cn=Manager,ou=admin,dc=niu,dc=edu,dc=tw" write修改DB設定
database bdb
suffix "dc=niu,dc=edu,dc=tw"
checkpoint 1024 15
rootdn "cn=Manager,ou=admin,dc=niu,dc=edu,dc=tw"修改root密碼
rootpw (使用slappasswd產生,rootpw後按一個tab即可)修改DB存放目錄
directory /var/lib/ldap/niu新增log設定 (loglevel說明)
loglevel 256新增ppolicy設定
overlay ppolicy
ppolicy_default "cn=NoExpirePassword,ou=Policies,dc=niu,dc=edu,dc=tw"
ppolicy_use_lockout
ppolicy_hash_cleartext新增同步設定
主:
serverID 1syncrepl rid=001
provider=ldap://client ldap server
bindmethod=simple
binddn="cn=Manager,ou=admin,dc=niu,dc=edu,dc=tw"
credentials=pw
searchbase="dc=niu,dc=edu,dc=tw"
schemachecking=on
type=refreshAndPersist
retry="60 +"mirrormode onoverlay syncprov
syncprov-checkpoint 100 10
syncprov-sessionlog 100副:
serverID 2syncrepl rid=001
provider=ldap://master ldap server
bindmethod=simple
binddn="cn=Manager,ou=admin,dc=niu,dc=edu,dc=tw"
credentials=pw
searchbase="dc=niu,dc=edu,dc=tw"
schemachecking=on
type=refreshAndPersist
retry="60 +"mirrormode onoverlay syncprov
syncprov-checkpoint 100 10
syncprov-sessionlog 1006. 編輯 /etc/sysconfig/iptables,允許ldap協定通過
-A INPUT -m state --state NEW -m tcp -p tcp --dport 389 -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 636 -j ACCEPT7. 重新啟動iptables
service iptables restart8. 重新產生openldap設定檔
slaptest -f /etc/openldap/slapd.conf -F /etc/openldap/slapd.dPS: 如果跳出沒有此DB則先匯入DB
slapadd -l ldif檔案 -f /etc/openldap/slapd.confchown -R ldap.ldap /var/lib/ldap/niu9. 設定log
vim /etc/rsyslog.conf加入
# save OpenLDAP log #### edited by cowman 2012-02-21
local4.* /var/log/ldap/ldap.log重新啟動rsyslog服務
service rsyslog restart10. 重新啟動openldap
service slapd restart
0 意見:
張貼留言