| @@ -18,3 +18,37 @@ bindpw your-password | |||
| 18 | 18 | sudo systemctl restart nslcd | |
| 19 | 19 | sudo reboot | |
| 20 | 20 | ||
| 21 | + | ||
| 22 | + | # /etc/nslcd.conf | |
| 23 | + | # nslcd configuration file. See nslcd.conf(5) | |
| 24 | + | # for details. | |
| 25 | + | ||
| 26 | + | # The user and group nslcd should run as. | |
| 27 | + | uid nslcd | |
| 28 | + | gid nslcd | |
| 29 | + | ||
| 30 | + | # The location at which the LDAP server(s) should be reachable. | |
| 31 | + | uri ldap://10.3.12.13:3189 | |
| 32 | + | ||
| 33 | + | # The search base that will be used for all queries. | |
| 34 | + | base dc=rhodiumlab,dc=org | |
| 35 | + | ||
| 36 | + | # The LDAP protocol version to use. | |
| 37 | + | #ldap_version 3 | |
| 38 | + | ||
| 39 | + | # The DN to bind with for normal lookups. | |
| 40 | + | binddn cn=admin,dc=rhodiumlab,dc=org | |
| 41 | + | bindpw "password" | |
| 42 | + | ||
| 43 | + | # The DN used for password modifications by root. | |
| 44 | + | #rootpwmoddn cn=admin,dc=example,dc=com | |
| 45 | + | ||
| 46 | + | # SSL options | |
| 47 | + | #ssl off | |
| 48 | + | #tls_reqcert never | |
| 49 | + | tls_cacertfile /etc/ssl/certs/ca-certificates.crt | |
| 50 | + | ||
| 51 | + | # The search scope. | |
| 52 | + | #scope sub | |
| 53 | + | ||
| 54 | + | ||
admin / ldapconfig
Last active 1 month ago
admin revised this gist 1 month ago · bfda87a
1 file changed, 34 insertions
admin revised this gist 1 month ago · 71c4aac
1 file changed, 20 insertions
| @@ -0,0 +1,20 @@ | |||
| 1 | + | If it's plain OpenLDAP | |
| 2 | + | The libpam-ldapd route is the least painful because the installer prompts you interactively and auto-configures nsswitch.conf + PAM: | |
| 3 | + | ||
| 4 | + | sudo apt install libnss-ldapd libpam-ldapd | |
| 5 | + | ||
| 6 | + | When it prompts, just fill in: | |
| 7 | + | ||
| 8 | + | LDAP server URI: ldap://your-server:389 | |
| 9 | + | Search base: dc=example,dc=com | |
| 10 | + | Check passwd, group, shadow | |
| 11 | + | Then set the bind DN/password: | |
| 12 | + | ||
| 13 | + | sudo nano /etc/nslcd.conf | |
| 14 | + | ||
| 15 | + | binddn "cn=readonly,dc=example,dc=com" | |
| 16 | + | bindpw your-password | |
| 17 | + | ||
| 18 | + | sudo systemctl restart nslcd | |
| 19 | + | sudo reboot | |
| 20 | + | ||