ldap這種原始的服務器搭建起來比較復雜,同時它也是CE必考的(客戶端的搭建)。
1、安裝openldap-servers軟件包
data:image/s3,"s3://crabby-images/a6677/a6677654e25ea062c925622536d7cb8a4ae63899" alt=""
2、查看ldap模板文件的存放位置:
data:image/s3,"s3://crabby-images/75674/756745b15c389a65466ee83a32e849e73cfcc940" alt=""
3、拷貝ldap模板文件到配置文件目錄並修改文件名為slapd.conf。
data:image/s3,"s3://crabby-images/17f4a/17f4a70e30cb74c739bbf29db076e2006ef2a72e" alt=""
data:image/s3,"s3://crabby-images/ae461/ae46120f07487513ec258cbb1d5d91ba059610ad" alt=""
4、刪除/etc/openldap目錄下原有的文件,保留下這幾個文件,注意:以前學時是要刪除schema文件,直留下三個,但是我測試時如果刪除schema服務將失敗。
data:image/s3,"s3://crabby-images/8b9d0/8b9d0273908b9b6bfef0f5798bf4a7bceb8d6b89" alt=""
5、修改slapd.conf文件的權限:
data:image/s3,"s3://crabby-images/b39f8/b39f8d1eb84e77e0c3dba143a3178c63b04a83fe" alt=""
data:image/s3,"s3://crabby-images/fd68f/fd68f7e5224a6fe0a6ff1f7f157e858ca397bb74" alt=""
6、修改sldap.conf配置文件:如下:(主要配好紅色的就ok,沒有的都是被注釋掉的)
復制代碼代碼如下:
include /etc/openldap/schema/corba.schema
include /etc/openldap/schema/core.schema
include /etc/openldap/schema/cosine.schema
include /etc/openldap/schema/duaconf.schema
include /etc/openldap/schema/dyngroup.schema
include /etc/openldap/schema/inetorgperson.schema
include /etc/openldap/schema/java.schema
include /etc/openldap/schema/misc.schema
include /etc/openldap/schema/nis.schema
include /etc/openldap/schema/openldap.schema
include /etc/openldap/schema/ppolicy.schema
include /etc/openldap/schema/collective.schema
allow bind_v2
pidfile /var/run/openldap/slapd.pid argsfile /var/run/openldap/slapd.args
database bdb suffix "dc=example,dc=com" checkpoint 1024 15 rootdn
"cn=Manager,dc=example,dc=com"
rootpw redhat
directory /var/lib/ldap
index objectClass eq,pres
index ou,cn,mail,surname,givenname eq,pres,sub
index uidNumber,gidNumber,loginShell eq,pres
index uid,memberUid eq,pres,sub
database monitor
access to * by dn.exact="cn=Manager,dc=example,dc=com" read by * none
7、重啟動ldap服務器:
data:image/s3,"s3://crabby-images/89075/89075070fb2e0221903fa3e45717c423d0a36eca" alt=""
8、創建ldap用戶目錄:
data:image/s3,"s3://crabby-images/6c8ad/6c8ad6fe4639acc2d3151fc921705c86299ee88d" alt=""
9、編輯一個自動創建ldap用戶的腳本:
data:image/s3,"s3://crabby-images/7b2ea/7b2eacb057e146b0d92494b4814c7ae437aa6456" alt=""
10 、執行此腳本添加用戶:
data:image/s3,"s3://crabby-images/4e15c/4e15c104075ec1435c50521c29b9f72878334893" alt=""
11、把ldap用戶,組分別導出來,到一個文件中:(例子只做了組)用戶在、/etc/passwd下
data:image/s3,"s3://crabby-images/436cb/436cba4806fa6a114f159ae0f77c18b77ec8171b" alt=""
12、安裝軟件包:
data:image/s3,"s3://crabby-images/4c7b4/4c7b4b8dfe080c0bdee9200772b122aacc9e9402" alt=""
13、去它的目錄下編譯ldap用戶組文件:
data:image/s3,"s3://crabby-images/0373c/0373cd10c039f62d1c98d5f996173524af4ef5bc" alt=""
14、修改migrate_common.ph文件:
data:image/s3,"s3://crabby-images/aac6c/aac6c3fced2e165e4d48580ab0cc5bc0c5a2e7af" alt=""
15、執行./migrate_base.pl文件,並導出到一個目錄下邊,進行進行修改,只留下最基本的三個配置:
data:image/s3,"s3://crabby-images/2e88a/2e88aecced1c36e910f77e716e0d97aaa749b51b" alt=""
16,、分別使用./migrate_passwd.pl ./migrate_group.pl編譯我們已經導出的ldap用戶和組文件: /mnt/user /mnt/group分別是從/etc/passwd /etc/group 導出的ldap用戶和組文件
/date/user.ldif /date/group.ldif 是編譯後生成的文件要以ldif結尾
data:image/s3,"s3://crabby-images/a8a5f/a8a5f7285743d0fdb27f470c92395775bfde4507" alt=""
17、看下/date下我們編譯好的幾個文件:
data:image/s3,"s3://crabby-images/2f779/2f7798f083773215eec789cda421c447f112421f" alt=""
18、添加ldap用戶和組:
data:image/s3,"s3://crabby-images/f7e41/f7e41629467edd26148f501e95795e40d7dbfcf1" alt=""
首先提示輸入密碼,其次添加成功。
data:image/s3,"s3://crabby-images/08a59/08a5990269ebf2f48515435c379989514a5bd923" alt=""
還有個用戶,必須首先執行base.ldif文件,它是最基本的配置。
data:image/s3,"s3://crabby-images/5fa11/5fa115972258c2071b713e8cd4500405f4be9d7a" alt=""